Re: password cracker for PCAnywhere and VNC (RFB 003.008)



Good point! Definately the first thing you want to do is compile a
list of *commonly* used usernames/passwords and also grab *real ones*
from employees' email addresses.

I recommend using an email harvester tool (just like the ones used by
spammers). Most of the times usernames which are valid on the client's
web interfaces can be extracted from email addresses. Also remember
getting email addresses not just from the web but *also* from whois
queries against the client's IP addresses and domain names.

Do *not* forget to try passwords equal to usernames. I've seen this
work several times on real pentests, and of course null (empty)
passwords.

On 3/6/06, Christine Kronberg <Christine_Kronberg@xxxxxxxx> wrote:
On Thu, 2 Mar 2006, 3 shool wrote:

Thank you all for your emails.

Just to elaborate more on my earlier email, what I'm looking for is a
Remote Password Cracker. Cain & Able I think will not help me in this
case, as I can't sniff also. These servers are on Internet.

I'll try hydra although it has its own limitations. I tried Brutus but
it doesn't do VNC or PCAnywhere password cracking.

Does anyone know of good username/password lists for dictionary attack?

Be careful. Do some calculating first. I've done a similar attack for
a customer a short while back. My initial username/password files turned
out to be too comprehensive (the whole attack would have run about 4
years). Instead I used google to search for persons working for the
customer to get a list of possible usernames. Then I stripped down
my password dictionary to meet my and the customers requirements (the
attack must not run 4 years - 5 hours are enough).
It was a shot in the dark. I agree with the other posting: try to
get information about the username/password policy of the customer.
That will help more than the poking I did.

Cheers,


Christine Kronberg.

------------------------------------------------------------------------------
This List Sponsored by: Lancope

"Discover the Security Benefits of Cisco NetFlow"
Learn how Cisco NetFlow enables cost-effective security across distributed
enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA)
and Response solution, leverages Cisco NetFlow to provide scalable,
internal network security.
Download FREE Whitepaper "Role of Network Behavior Analysis (NBA) and Response
Systems in the Enterprise."

http://www.lancope.com/resource/
------------------------------------------------------------------------------




--
pagvac (Adrian Pastor)
www.ikwt.com - In Knowledge We Trust

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
As attacks through web applications continue to rise, you need to proactively
protect your applications from hackers. Cenzic has the most comprehensive
solutions to meet your application security penetration testing and
vulnerability management needs. You have an option to go with a managed
service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm).
Download FREE whitepaper on how a managed service can help you:
http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@xxxxxxxxxx
------------------------------------------------------------------------------



Relevant Pages

  • [NT] DCE RPC Vulnerabilities New Attack Vectors Analysis
    ... Get your security news from a reliable source. ... These new attack methods were found while researching exploitation ... They might also apply to other vulnerabilities such as the DCE RPC DCOM ...
    (Securiteam)
  • << Small Biz Server news this week - June 18, 2004 >>>
    ... The monthly Executive Circle Security Webcast with Mike Nash, ... IP phones can create network security risk ... The biggest of the headaches was Tuesday's attack ... Akamai now says it was targeted by DDoS attack ...
    (microsoft.public.backoffice.smallbiz)
  • << Small Biz Server news this week - June 18, 2004 >>>
    ... The monthly Executive Circle Security Webcast with Mike Nash, ... IP phones can create network security risk ... The biggest of the headaches was Tuesday's attack ... Akamai now says it was targeted by DDoS attack ...
    (microsoft.public.backoffice.smallbiz2000)
  • << Small Biz Server news this week - June 18, 2004 >>>
    ... The monthly Executive Circle Security Webcast with Mike Nash, ... IP phones can create network security risk ... The biggest of the headaches was Tuesday's attack ... Akamai now says it was targeted by DDoS attack ...
    (microsoft.public.windows.server.sbs)
  • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
    ... As others have pointed out, your attack only works if security in depth has been blatantly, intentionally ignored. ... We educate users not to open .exe files but RDP ... updating to the 6.0 client anyway. ...
    (Full-Disclosure)