Friday, August 17, 2007

Password Cracking and Security: Part 2

Introduction:
This will show you how to break the encryption on a zip file, word document, and excel document. The tools and methods shown here are just some of the many ways to get a password. There are things called exploits which could allow an attacker to get in even faster... but for now lets take a look at Brute Force and Dictionary attacks. NOTE: This tutorial doesn't recommend you crack passwords that don't belong to you. It is meant be used for password recovery and password strength testing.

Tools needed:
Excel_crackers_setup.exe (mirror)
Zip Password Finder (mirror)
abc.doc (word doc I made with password... see if you can get access)


These programs have been tested and they work with not only the older versions of office, but also newer ones...

  1. Microsoft Word / Microsoft Excel
    This method will work on either a word or excel file, it doesn't matter which you choose.
    First create(or open) a password protected Microsoft Word or Excel document; type some information into it so that you will be able verify you have unlocked the document.
    To enable password click tools--> options --> security, and enter password, click ok and save the document. (Visual here)


  2. Next download and install excel_cracker_setup.exe
  3. You should get a
    window that looks like:
  4. In the name box type or click the icon and browse, to enter the password protected word/excel file you created.
  5. You have 2 options: Brute Force attack! and Dictionary attack (see Password cracking part 1 for more info). If you do a dictionary attack you must select a word file... and it has to be text. For this demonstration select only Brute Force attack

  6. Further options include:
    - All printable (meaning all characters able to be typed)
    - Latin small symbols [ a...z] (lowercase letter)
    - Latin capital symbols [A...Z] (UPPERCASE letters)
    - Digits [0...9] (numbers)
    - Special symbols [1@#$...] (can you guess this one?)
    - Space [ ] (its like outer space...)

  7. You can set the Minimum Length and Maximum Length of the passwords you want try. But here is where things get a little sticky. See chart below to see what I mean. (click to see it larger)


    A ten character password with both symbols and letters (no caps) will take over 960000 years to crack.
ZIP Archives
In order to crack zip archives it is very similar but here are the step by step instructions.
  1. Download: Zip Password Finder
  2. Once you have opened the program (it installs to the start menu),
  3. Click "Open File" and select the zip file you wish to crack.
  4. Next, pick the "charType Property" which will be the character set that is used for the Brute Force. (you should understand from the other demonstrations, so I don't have to re-list the distinctions.)
  5. You may also want to select "Max password Length:"
  6. Go get a drink and find something productive to do while you wait :-)

    END NOTES:
    The best thing that you can use this for is to test how fast someone could crack your password or if you have forgotten the password to a word, excel, or zip file. Once you have cracked (or failed to crack) your password, you can make an assessment as to whether or not you need to change it. (If your password is over 10 charters, I expect you know better than to wait 100+ years to find out it is safe :-P )

MORE TOOLS:
IBIOS (http://www.11a.nu/)....... BIOS cracking
Cain and Able................................ OS PWD cracker /Net spoofer
007PeepPassword..........................view password under asterisks
Archpr.................................... rar, zip, pkzip, ARJ/ACE + more
http://www.password-crackers.com.... good resource for free and paid tools.

Thursday, July 26, 2007

PDF Yesterday... Ecards today

I have found that this weeks Email spam Scam is E-cards...
the following "loving" ECards from my "friends" can be seen below:



It appears that this round of Spam is very Dangerous as can be seen in detail from a report by
SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc

They said that it has been labeled "Storm worm"
and houses a collection of
-botnet malware
(allows virus master to control 100 or 1000s of machines at a time)
-a rootkit
(hides programs from antivirus and spyware detection software so no detection is even possible)
-NEW: Virtual Machine Detection
(harder to use a sandbox windows environment to test and understand the virus)
-Worming virus like activity
(allows program to hop from machine to machine uninvited)
-hiding behind a P2P style network
(uses its own network to spread)

This mix allows it to deal a perfected blow to any PC it is allowed to infect. What has changed the game for this virus/malware is the fact that when researches put it inside their Virtual Machines (the place they test the virus safely) nothing happened. The Virus didn't deploy and only rebooted the Virtual Machine.

Now I haven't personally tried these attachments, like I did with the PDF ones (see earlier post)
But I did notice that there are more attachments with these Emails and there volume is increased and not every Email has a attachment, it may have a link to a file to download.

Thats it for now... check back again to stay informed on more everyday security problems and to follow my security series.

Sunday, July 15, 2007

Password Cracking and Security: Part 1

Introduction:
Many times the only thing stopping a hacker from accesses your data is a username and/or password. A strong password will insure that nothing gets leaked. A password's strength can broken down into: numbers, letters(lower and UPPERCASE), symbols, and length.

Most hackers will try the default passwords first. (and I have to say I have recovered many a password by having that list handy) Examples include, but aren't limited to: admin, root, password, pass, password1, default, and.... so on and so forth. View larger sample (router default passwords)

Definitions:
If he can't get in with the default passwords he may step up the attack to a dictionary attack or brute force attack.

  • A Dictionary Attack -- which is where he takes a list of words from the dictionary and other sources(like acronyms, foreign words etc) and trys each one to see if it is the password. He may also add numbers such as a 1 or a 2 to the end for a quick check. If your password is a single word or a phrase, such as "hardcrack" or "notime" then the attacker will be inside your account(s) in a matter of hours or days.
  • Brute Force Attack -- this is where the attacker attempts every combination in the book, and out of the book. Normally he selects the category and length he wishes to try. The script he has made will then try an alphabetical/numeric/symbolic attempt 1 by 1. e.g aa, ab, ac... ax, ay, az, a1, a2, a3, ... a7, a8, a9, a0, a!, a@, a#..... Oh yeah, I can't forget to mention that he also has to try Uppercase and lower case letters. This can end up taking forever since time to try the passwords compounds itself.
    (Check back for Password Cracking and Security: Part 2 Word, Excel, and Zip brute force demonstration)
THE Protection TIPS:
The more combinations you use in your password the harder it will be to crack. The most secure passwords contain a mix of the items noted above. Now you may be thinking how in the world am I going to remember such a complicated password? Here are some tips:

  1. - Develop an algorithm for your passwords. The password to your "mail" could be MaIl6245 and the password for your computer could be cOmPuTeR26678837. With the algorithm being: Subject name, alternating upper and lower case, and then the corresponding numbers from a phone keypad.

  2. - Use geometric shapes to remember your password:






    Each button would be pressed and make up passwords that look hard, but really when you sit down to type are easy to remember. (Picture shows passwords: "e3dcft654" and "8ik./lo9")
  3. - Another way to remember your password is to write it down...
    BUT don't just leave the paper lying around for someone to find. Put it in your wallet, or other safe place (and that doesn't include your monitor) Plus, hide it in such a way as not to make it obvious. e.g. if your password was MaIl6245 mix it up --- put "MaIl" on one line and 6245 on another line on the index card.


  4. Don't type your password in straight. What I mean is type your password in backwards, out of sequence, and add extra keys to confuse the keyloggers. When you are on a computer there are programs called keyloggers that will log every stroke you make. It doesn't matter how strong your password is, if the computer has a keylogger, then the keylogger's master can get it easily.
    Also, use the mouse, not the arrow keys to move around in the password field. Most keyloggers that I have tested can't pick up mouse movements.
    For Example lets say you have a password of abc123 (though not especially safe, it is alphanumeric). If typed :Then it will show in the keylogger: 123xabnc
    And unless the keylogger can log backspace/left/right arrows then whoever looks at it will be confused, and hopefully pass you by.

    If you want to try out a keylogger I recommend:
    FREE:
    Tiny KL - http://home.rochester.rr.com/artcfox/TinyKL/ OR
    Actual Keylogger - http://www.download.com/3001-2092_4-10541792.html
    Or you can try out my all time favorite:
    $19.99
    Winspy - http://www.win-spy.com/ (feature list is amazing)

  5. - You may even want to use a password storage program. Firefox has a built in password manager which I recommend using --- so long as you add a master password (Tools--> Options, Security Tab, Check "use master password" and click "change"/"setup password"). You can also use Roboform which works well to remember Internet Explorer and Firefox passwords. Most of the time a password gets added by you typing it in and selecting you want Roboform or Firefox to remember it.

    What I did for a while with my passwords was I kept them in Firefox's list (practically all of my vital passwords were for websites) . Then I created a master password using symbols and letters and stored a hard copy of that in my wallet. For passwords that were not in the browser(like the screensaver) I just picked 1 tricky alpha/numeric/symbol password and used it over and over till I had memorized it --- that is one thing I have found true to remembering passwords, if you have to type it every time you start windows(however infrequent that may be :-P) you will tend to remember the password better.

    If you have passwords outside the browser (like to get into Windows) it is best to keep them in a protected password manger program or password protected Word or Excel document with auto recovery turned off (so no cache copies remain on disk) which is located on a keydisk(which can be hidden under your bed, the place every robber looks ;-P).

    Note: I personally don't trust any password manger program, and just use a combo of MS word, MS excel, and zip files to keep my passwords manged and safe.


    Now there are some people that argue that you need to have better Encryption for your passwords. Two good applications for that are Blowfish and TrueCrypt . If you need any help with them feel free to leave a comment, but for now I don't have room in this post to go into details about encryption. (both are free)


    Another problem with passwords that I have found is that people make a great secure password only to have a very simple password recovery question. Like their birthday. Chances are if they have a myspace or something else online where a birth date or father's name, age, favorite place to vacation is posted, etc. then they might as well have no password at all. A hacker can get your password just from those backdoors...

    This is why many companies and individuals have selected to use a security disk instead of passwords. Security disks(USB or Floppy) hold a password generated from the make up of a file or a longer password. The only way to log on to the computer is with that keydisk or the longer password thereby eliminating the need to type the password in each time. This allows you to select a password that you wouldn't ever think of using before. (e.g. you could make a password out of the 255 first characters of the definition of A in the Dictionary) TrueCrypt has some of these features.
End Notes: As you probably can tell, security is an ongoing, never ending
"black art". You are never completely secure. Hackers find exploits, create newer tools, and trick you with their looks and charms :-P. But what you have to do is take steps to be more secure; increase your security to the point that you are so hard to reach, you become not worth the time. Be creative. There is a saying "to prevent a robber you must think like a robber." The same goes for Hackers.

Stay informed, be alert, and if you think security has been compromised, You better pick a new PWD FAST. Trust no-one, not even your yourself.


EDIT INCLUDES MINOR GRAMmATICAL/SPELLING CHANGES.

Friday, July 13, 2007

PDF Viruses on Yahoo? nah-uh

During the last few weeks I have received about 3 PDF Containing Emails from people
I didn't know on my yahoo Email account. Then today while I was working at a customer's I was alerted to the fact that she had opened one of the PDF files, mistaking it for a legit attachment, so I knew I needed to find out whether it was dangerous or not.

I began searching for the answer to whether it was a virus or just spam. According to various sites and Antivirus software, this round is just a spamming ploy to make money.

I opened the PDF on my Windows XP PC and scanned it with AVG, and Norton (via yahoo's scanner.)
No virus was found, and the contents of the PDF showed:



The name of this particular file was "check_50290cba35810.pdf" but I have seen many other names.

I tried a simple Google search on SZSN, It appears that this Chinese company may be paying spammers in order to get to get the word out about there new seed and products. Header information could not verify the location of the spammer (no surprise). I can't help wondering if something was really happening with a virus this Morning and has yet to turn up.

But I can only guess the spammer is working out of China which ranks in the top 10 nations for illegal piracy and activity. The disguise of the PDF and the crooked print attempt to make it look more legitimate... to the spam blocker software.

This is something that has become more and more of a problem, spammers get paid to spam. These people have created a new profession which has a paycheck in the thousands or even millions.


Resources:
http://chris.pirillo.com/media/2007/07/02/pdf-viruses/

Thursday, July 5, 2007

Antivirus Test and Results in

After testing several Antivirus and spyware protection programs against over 174,770 viruses and malware, Virus.GR a list has been compiled on how well different security applications have held up:


Testing was done on an up to date Windows XP Professional SP2 on a P4 3000 Mhz, 1024MB DDRAM. Each program was customized to maximize its ability to detect and remove the nasties.

This test does not include DOS scanners and scanned file types:
SH, ELF, COM, EXE, PL, BAT, PRC, DOC, XLS, BIN, MDB, IMG, PPT, VBS, MSG, VBA, OLE, HTM, INI, SMM, TD0, REG, CLASS, HTA, JS, VI_, URL, PHP, WMF, HLP, XML, SCR, PIF, SHS, WBT, CSC, MAC, DAT, CLS, STI, INF, HQX, XMI, SIT.


And just for the record: Anyone trying to use Norton or Macafee and protect them self from viruses/malware is going to get infected soon or later (most likely sooner rather than later) ... which is why I am posting this list.

(list provided by virus.gr, partial information www.techdo.com)

1. Kaspersky version 7.0.0.43 beta - 99.23%
2.
Kaspersky version 6.0.2.614 - 99.13%
3.
Active Virus Shield by AOL version 6.0.0.308 - 99.13%
4.
ZoneAlarm with KAV Antivirus version 7.0.337.000 - 99.13%
5.
F-Secure 2007 version 7.01.128 - 98.56%
6.
BitDefender Professional version 10 - 97.70%
7.
BullGuard version 7.0.0.23 - 96.59%
8.
Ashampoo version 1.30 - 95.80%
9.
eScan version 8.0.671.1 - 94.43%
10.
Nod32 version 2.70.32 - 94.00%
11.
CyberScrub version 1.0 - 93.27%
12.
Avast Professional version 4.7.986 - 92.82%
13.
AVG Anti-Malware version 7.5.465 - 92.14%
14.
F-Prot version 6.0.6.4 - 91.35%
15.
McAfee Enterprise version 8.5.0i+AntiSpyware module - 90.65%
16.
Panda 2007 version 2.01.00 - 90.06%
17.
Norman version 5.90.37 - 88.47%
18.
ArcaVir 2007 - 88.24%
19.
McAfee version 11.0.213 - 86.13%
20.
Norton Professional 2007 - 86.08%

Then the following applications trailing behind:
21. Rising AV version 19.19.42 - 85.46%
22. Dr. Web version 4.33.2 - 85.09%
23. PC-Cillin 2007 version 15.00.1450 - 84.96%
24. Iolo version 1.1.8 - 83.35%
25. Virus Chaser version 5.0a - 79.51%
26. VBA32 version 3.11.4 - 77.66%
27. Sophos Sweep version 6.5.1 - 69.79%
28. ViRobot Expert version 5.0 - 69.53%
29. Antiy Ghostbusters version 5.2.1 - 65.95%
30. Zondex Guard version 5.4.2 - 63.79%
31. Vexira 2006 version 5.002.62 - 60.07%
32. V3 Internet Security version 2007.04.21.00 - 55.09%
33. Comodo version 2.0.12.47 beta - 53.94%
34. Comodo version 1.1.0.3 - 53.39%
35. A-Squared Anti-Malware version 2.1 - 52.69%
36. Ikarus version 5.19 - 50.56%
37. Digital Patrol version 5.00.37 - 49.80%
38. ClamWin version 0.90.1 - 47.95%
39. Quick Heal version 9.00 - 38.64%
40. Solo version 5.1 build 5.7.3 - 34.52%
41. Protector Plus version 8.0.A02 - 33.13%
42. PcClear version 1.0.4.3 - 27.14%
43. AntiTrojan Shield version 2.1.0.14 - 20.25%
44. PC Door Guard version 4.2.0.35- 19.95%
45. Trojan Hunter version 4.6.930 - 19.20%
46. VirIT version 6.1.75 - 18.78%
47. E-Trust PestPatrol version 8.0.0.6 - 11.80%
48. Trojan Remover version 6.6.0 - 10.44%
49. The Cleaner version 4.2.4319 - 7.26%
50. True Sword version 4.2 - 2.20%
51. Hacker Eliminator version 1.2 - 1.43%
52. Abacre version 1.4 - 0.00%

Saturday, June 9, 2007

Hacking Defined

This is a essay that I did a while a back and I though I would post since it defines the various types of hackers and dismisses some common misconceptions about this group of people. As with the my other posts, you may use this for your educational use with out question --- provided you give me credit. If you would like to use my work for profit you can make a request here. Enjoy ;-)

Hackers: Protectors of Computers

“What is a hacker?” seems like it has an obvious answer, but it does not. Right now I bet you are thinking about some kind of evil crook that tries to break into a company’s, or individual’s, computer in order to steal private information. Though this may be true, a hacker is just someone “who is proficient at using or programming a computer” (“Hacker”). There are two types of hackers. Black hat hackers give hacking a bad name; they break into computers to destroy them or to steal data. White hat hackers look for vulnerabilities in a computer system to make the owner and data safer. Script kiddies, amateurs, and elite hackers, the three skill levels of hacking, can be either black hats or white hats.

In the book, Hack Proofing, Jeff Forristal explains the differences between white hats (also called ethical hackers) and black hats (or malicious hackers). The term “ethical hacking occurs anytime you are ‘testing the limits’” concerning a piece of software or hardware you, or your affiliates, have created (10). Those hacking as black hats can be labeled as “malicious hackers … [who] exploit a weakness … lead to theft, a DDoS attack [denial of service], or defacing of a website” (10). There is also the question that some people may ask: when “is it … okay for someone to … poke around in some manner in search of an exploitable weakness?” (11).

There are many companies that hire white hat hackers in order to prevent black hats from taking over. In Jeff Forristal’s book, which tells businesses how to protect their websites, he recommends, “the best possible way to focus on security … is to begin to think like a hacker” (32). Another suggestion is to “invite a hacker into your code. Think security from every level” (527). He is basically saying in order to protect your system and data, you must know the way they think and try to observe the methods they use to hack into your system.

The most novice hackers, script kiddies, do not know what they are doing or what the rules of hacking are. They think it is “kool” to hack government or company computer systems and, therefore, they can create much damage and be traced easily. Christopher J. Coyne from the Department of Economics at Hampden-SydneyCollege stated, “inferior programming skills prevent them from creating effective hacking programs” (17). Most of the time, they are just trying to “gain notoriety for the damage they cause using the programs and information created by more elite hackers” (17); this is why they are called “script” kiddies.

Amateur hackers are between script kiddies and elite hackers. They have good knowledge of hacking rules and how to get what they want. They many times can’t be traced easily. They may use a backdoor, a way of running an undetectable code on a host’s system that requires no login or confirmation (Forristal, 196). These people hack for enjoyment, although some could still be using it as a way to show off.

Elite hackers are the most proficient; their success and recognition among their peers makes them “the cream of the underground” (Coyne, 21). They could be thought of as hacker’s heroes, or leaders, since they “are the most innovative in the underground and are responsible for making hacking programs publicly available” (21). Some start out as “individuals who used to hack illegally” and, on their own or by being caught, ended up as ethical hackers and/or hired as security analyzers (21). This “‘hiring a hacker’” has great advantages because the new “security professional is familiar with the methods used by hackers” (Forristal 11). They still may hack for fun, but a lot of the time, these “hackers sell their skills at finding security weaknesses in computer systems.” (Coyne, 21).

Governments, computer businesses, and individuals pay in order to have hackers test their security by inviting them to hack into their computer systems. It takes hours, weeks, and even months to move from script kiddie to amateur; and many years to obtain the well deserved “rank” of elite hacker.


Coyne, Christopher J. and Peter T. Leeson. “The Economics of Computer Hacking.” Journal of Law, Economics, and Policy 1 (2006): 511-532.

Forristal, Jeff. Hack Proofing: Your Web Applications. Ed. Julie Traxler. Massachusetts: Syngress Publishing, 2001.

“Hacker.” The AmericanHeritageCollege Dictionary. 4th ed. 2004


Monday, June 4, 2007

Netbios hacking, art/crime of

Netbios hacking is the art( or crime) or attacking a Window's Machine using the underlying file transfer protocol setup by Microsoft for file sharing. Almost every Microsoft Windows computer connected to a network, whether it be fiber optics, cable, DSL, Home or Business Network or even dialup has the opportunity to be invaded by a Netbios attack. Many newer PCs have this feature turned off but a lot of times people share certain folders/files with others on the network, not using secure passwords or being careful about what they share.


Scroll to the bottom to get the simple quick attack.

Basics:
IP addresses defined:

First to understand how a netbios attack is done you must understand how a network works. Every network that has a computer or device(e.g. Palm Pad) on it has provides an individual number called an Internet Protocol (IP) address to each device in the form of X.X.X.X (e.g. 192.168.1.1) This can be compared to a house address in the real world. The first 2 Numbers are the "Street address" and are specific to the network/ISP that the device uses. (e.g. 192.168.X.X = a local address, and 64.12.X.X would be a AOL network) and the last 2 numbers are for the individual computer or "House".

Ports defined:
For each IP address, their are ports that open so that applications can talk to the various other parts of the web. port 80 is for web browsing, port 21 is for File Transfer Protocol. You can think of each port as the "name" of a person at a particular house.

THE HOW TO:

  1. For netbios attack to work all you need is the ip address of your target. You can find this by going to command prompt (Start --> Run, type CMD) Then at the black screen type "ipconfig" look for some numbers in the form of "IP address . . . . . . :X.X.X.X"
    That is your IP address.
  2. The computer can either be on a WAN(Wide area network) or a LAN (Local Area Network). A WAN IP address is the IP that shows up on the Internet and allows computers from around the world to contact your PC. Note: A router on a LAN will have it's own WAN IP address that it shares with other PCs. A LAN is a Home or business network that only computers at the same location (hence the name Local) can access. Normally if you are on a LAN you connect to the internet through a router, and all requests to talk to your PC go through that.

  3. The way to tell what you have is to look at the first numbers of your IP address from "ipconfig". If the first 2 #s are "192.168.X.X", "10.10.X.X", or "172.16.X.X" then you have a LAN. Any other first 2 #s mean you are directly connected to the WAN without any router protection.

  4. For a LAN if you want to get into your PC from the internet you have to go through a router. You have to know the WAN of the router and set it up correctly. To find the WAN ip address, go to http://www.nwtools.com from any PC connected to the router with internet access(copy the numbers in the box-- middle screen. That is the IP address.). Your router also has to be setup to allow your PC to connect directly to the Net, via port forwarding or DMZ pass through. --- Check your router's manual for more information.

  5. For a WAN without a Router, simply use ipconfig and copy the IP address you see.

  6. Intruders can get your IP address just by sending you to their site, having you look/send them and Email, installing software on your PC, by network wide port scan(will talk about this later), or by various other means. If they only get your router you are fairly safe, but if they catch you without a router (e.g. a hotel, hotspot or other LAN) they can get inside more easily.
  7. For testing purposes I recommending setting up a network with at least 2 computers on it. (you could also use a virtual machine on a single PC, you will need a Windows setup disk handy)
  8. Once you have the IP address, it is time to do something called a port scan. This will tell you what programs are running and communicating with the outside world using that IP address. Netbios use ports 135, 137-139, and 445 .(Full list of ports: here) There are many port scanners that can be used:

    Angry IP Scanner: http://www.snapfiles.com/get/angryip.html
    (easiest and fastest, though not always the most anonymous)

    Nmap
    :http://download.insecure.org/nmap/dist/nmap-4.20-setup.exe (requires WinCap and isn't as easy to install, but has a whole score of options)

  9. I will show how to do this with Angry IP Scanner since that is the easiest/ Try Nmap if you want more options and are comfortable with command prompt:
    a. Open Angry IP scanner (the file called "ipscan.exe")

    b.
    Put Ip range as X.X.X.X to X.X.X.X. (e.g. 192.168.1.1 to 192.168.1.1)

    c.
    You could have more than 1 IP address: X.X.X.X to X.X.X.Z (e.g. 192.168.1.1 to 192.168.1.3) This would be if you where hacking more than 1 PC.

    d.
    Click Options --> Select Ports…

    e.
    Fill in port field with “135, 137-139, 445” all the ports used by netbios

    f.
    Click “OK”, and then “Start”

    g.
    It will then pop up with a window showing alive hosts, note the number. Click Ok and Scroll through the list till you see the host with ping column = X ms

  10. Now if you see alive host = 1 on the end message it means you can go further, but if it says 1 dead host then it most likely has a firewall and it can't be netbios hacked.
  11. The next thing to do is find out what is open via those ports... so open command prompt (Start--> Run Type "Cmd") type in nbtstat -a X.X.X.X this will give a list of what is open via NetBios.
  12. Now look for a <20> next to the computers name i should look like:









    <20> is the code for netbios.
  13. Now we need to use winfingerprint ( www.winfingerprint.com) so that we can get a little more info about what Netbios shares that are open. A "share" is a folder or Drive (Hard drive, CD rom drive, etc) that is open to other Computers on the network. If this share has a weak password or no password then anybody can easily get in and access whatever is in that folder or drive.
  14. Once winfingerprint is installed select the check boxes "single host","Win32 Os Version", "null IPC$ sessions","NetBIOS shares, "users", "disks", "groups","RPC bindings", "Patch Level", "MAC address", "Sessions" and "Event log" This will give you a huge array of information to work with. (don't worry I will tell you what to do with your little "gold mine" lol )
  15. Type the ip address of the victim PC in the box below "single Host" and Click Scan.


















  16. When it finishes(it could take a min or 2) scroll down the list till you see "NetBios Shares"
    copy these down or leave the window open you will need them later. Also copy the name of the users under "Users:" -- Provided their are any.

  17. Open a command prompt again and type net use {insert share name here} "" /u:"" for the share name you may want to try \\X.X.X.X\IPC$ first. This is a default share that comes up on most machines, though it may not be on the target you are testing.
  18. Next type: net use * "\\X.X.X.X\C$" * /u:adminstrator
    If "administrator" doesn't work try some of the other usernames that you got from Winfingerprint. You will need to guess the password, good ones to try are:
    (blank), password, password1, pass, admin, administrator, whatever you can think of.
    Repeat for each share that showed up in winfingerprint.

  19. If you get "Error 5 access ... access is denied." or Other errors:http://www.chicagotech.net/systemerrors.htm
    You can hunt for more shares by typing "net view X.X.X.X" for the shares you see substitute "C$" for the share (e.g. if the share was "Drive 2" you would type "net use "\\X.X.X.X\Drive 2" " note: put quotes around ip and share.)
    (if you can guess the password skip to #17, otherwise continue with #16)

    NOTE: I will talk more about password cracking in a future post.

  20. Download NAT (http://www.cotse.com/tools/sw/nat10bin.zip) to begin trying multi combination passwords. Extract all the files in to 1 folder. Then go into command prompt and type " C:\Foldername\nat.exe -u userlist.txt -p password.txt X.X.X.X "

  21. If you still have no cookie, try downloading another list of passwords off of google by searching "filetype:txt passlist.txt". Download the file and put it in the folder with NAT overwriting the file "passlist.txt". Type " C:\Foldername\nat.exe -u userlist.txt -p password.txt X.X.X.X " in command prompt again.

  22. You now have done everything you can do to get Netbios access. If you can't get in now, then most likely the computer is secure from a Netbios hack.

  23. If you get the password and have seen "command completed successfully"(after doing net use * "\\X.X.X.X\C$" * /u:USER) . Open windows explorer. You will see a new drive (it may have a different icon too) . This drive is the drive of the other PC.

  24. You have hacked in. With this power you can put in backdoors, programs that allow you to get in even if the computer's netbios is turned off and passwords are changed. This is why it is not a good idea to go online with a brand new PC and now Protection.


Quick check:

You can test simply if their are any open shared folders/drives on your network by running Angry IP scanner and putting in the IP address for all PCs on the network. (e.g. if 192.168. is the first 2 numbers: 192.168.1.1 to 192.168.1.255) This will test all PCs on your network and let you know which ones have open shares, you then can right click on the computer and select explorer to see what is open for viewing. THIS IS FAST, BUT NOT DOESN'T TEST EVERY ACCESS OPTION... fyi



END NOTES:
You now have the basic idea of how someone could/will enter your system. Even if you weren't able to get access you have a better understanding of the importance of having a firewall. The firewalls I recommend are:

Free Zone Alarm(Works well with all Windows systems, and is more protective/customizable).
Windows Firewall(only good in Vista and XP)


They seem to do the best job with less hassle (Pick only 1 though, or you might have problems). Mcafee and Norton Internet Security 2007 are good and will protect you well, I just feel that over the years these programs have been blown up and take advantage of too many system resources --- Slowing the computer down.

Another thing that you can do to protect yourself is to turn off file sharing. For Win2000, XP:

  1. Start --> control panel --> network connections.
  2. Look for the connection(s) you use to connect to the internet.
  3. Right click and select Properties.
  4. Uncheck “File and printer sharing for Microsoft windows”

(to my knowledge Vista doesn’t allow file sharing by default)

WARNING: Don’t do these steps if you are using a school, work, or other pc that you don’t have permission to change settings on, or if you do printing/file sharing over your network.

Finally it is a good idea to have a router to route your internet through, it proves what is called a hardware firewall.

Hopefully with what you now know, you will be able to avoid becoming a victim of NetBios hacking. :-)

DOWNLOADS & Sites:

Angry IP Scanner: http://www.snapfiles.com/get/angryip.html | mirror 1 |


Nmap: http://download.insecure.org/nmap/dist/nmap-4.20-setup.exe | mirror 1 |

WinCap: http://www.winpcap.org/install/bin/WinPcap_4_0.exe | mirror 1 |

Winfingerprint: http://sourceforge.net/project/showfiles.php?group_id=15870&amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;package_id=15574&release_id=328573 | mirror 1 |

Net Command Error List: http://www.chicagotech.net/systemerrors.htm

NAT: http://www.cotse.com/tools/sw/nat10bin.zip | mirror 1 |

Password list: http://amsterdam1.plunder.com/2798/passlist.txt

Free Zone Alarm 7.0: http://www.download.com/ZoneAlarm/3000-10435_4-10653297.html?tag=lst-0-1 | mirror 1(ver. 6.5) |

Windows firewall instructions: http://support.microsoft.com/kb/283673