Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Security practice (contest)

2456789

Comments

  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    found some things, but server is down now?


  • Closed Accounts Posts: 891 ✭✭✭conceited


    Ok it's been up a few hours now and nobody was able to do anything.
    There was plenty of port scanning and such but nothing came of it.
    I'll make it easier if you want? But to be honest, this was fairly easy.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    im able to execute commands on the server, i know of the weakness in the system


    Directory of c:\

    07/05/2008 08:35p <DIR> Inetpub
    07/05/2008 11:11p <DIR> WINNT
    07/05/2008 08:22p <DIR> Program Files
    07/05/2008 08:47p <DIR> WEB_ROOT
    07/05/2008 08:27p <DIR> Documents and Settings
    07/05/2008 09:39p 5,255,168 lol.txt
    1 File(s) 5,255,168 bytes
    5 Dir(s) 1,315,172,352 bytes free


  • Closed Accounts Posts: 891 ✭✭✭conceited


    I got a few dr watsons alright was looking through the logs :pac: haha
    Ah i see you must be using the ././././.././././././././.
    ?
    Any idea of os etc and network?


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    i didnt use that, i did a quick sniff with nessus.


  • Advertisement
  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    i was hoping to compile src and get a reverse shell as 8080 seems to be the only port going through your router, opening a local port seemed pointless.


  • Closed Accounts Posts: 891 ✭✭✭conceited


    Ya i seen a few attemps with that.
    I have other machines on the network so i didn't wanted to bridge it ,but your scans are allowed through.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    welll os is win2k


  • Closed Accounts Posts: 891 ✭✭✭conceited


    Thats right.
    Any idea of sp ?


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    I dont recall seeing any SP but i should have checked the splash of cmd.exe


  • Advertisement
  • Closed Accounts Posts: 891 ✭✭✭conceited


    Well if you like i can put her back up?


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    is there many people at it?


  • Closed Accounts Posts: 891 ✭✭✭conceited


    I'd say you changed ip 2 times and i seen 2 others thats about it so 3 or 4.
    You gathered the most info without a doubt.


  • Registered Users, Registered Users 2 Posts: 469 ✭✭knuth


    Down :|


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    my ip shouldnt have changed so i guess there is more at it


  • Registered Users, Registered Users 2 Posts: 469 ✭✭knuth


    8080 is closed, vnc is open. Desktop / http.


  • Closed Accounts Posts: 891 ✭✭✭conceited


    The scans looked similar ,guess you were using the same tools.


  • Closed Accounts Posts: 891 ✭✭✭conceited


    lordlame are yo drunk sir? :D


  • Registered Users, Registered Users 2 Posts: 469 ✭✭knuth


    yup :)


  • Registered Users, Registered Users 2 Posts: 469 ✭✭knuth


    HAH, scanned 84 instead of 86. Damnit!


  • Advertisement
  • Closed Accounts Posts: 891 ✭✭✭conceited


    i'll put it up again tomorrow for yee .


  • Closed Accounts Posts: 891 ✭✭✭conceited


    my network.

    Router:Netopia
    Model: 3347NWG


    My router had a nat rule setup,
    allow traffic on tcp port 8080 to target host.

    The routers firewall was turned off.
    Not recommended. This setting disables all levels of protection for your network, and exposes your network to significant security risks by allowing all traffic to and from the Internet through your Router. This setting should be used for testing only, or if you are using another type of firewall in conjunction with your Netopia Router.


    Anyway you said you were hoping to compile src and get a reverse shell as 8080 seems to be the only port going through the router, and opening a local port seemed pointless.

    What did your port scans show only port 8080?
    Should i put my router in bridge mode?

    Have another think about what you said above and have a look at this .

    Server will be up at 6pm
    Any questions you can pm me on windows live.

    lolsm6.jpg
    my.php?image=lolsm6.jpg


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    I only seen 8080 responding to requests but I didnt scan too much, just when I seen the weakness, I went from there.


  • Closed Accounts Posts: 891 ✭✭✭conceited


    Ok just 8080.
    Have you tried using hping or any advanced scanning to guess the host behind the nat?
    So what do you think shall i make it easier?


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    conceited wrote: »
    my network.

    Router:Netopia
    Model: 3347NWG


    Anyway you said you were hoping to compile src and get a reverse shell as 8080 seems to be the only port going through the router, and opening a local port seemed pointless.

    you see I could open an alternate port on your server via exploit but your router would not forward this port to your win2k machine, so instead you use an exploit to make your win2k machine connect back to me, reversing a shell at the same time.


    What do I have to do if i get in?
    Put my name on the webpage been served?


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    conceited wrote: »
    Ok just 8080.
    Have you tried using hping or any advanced scanning to guess the host behind the nat?
    So what do you think shall i make it easier?


    Nah its grand the way it is.


  • Closed Accounts Posts: 891 ✭✭✭conceited


    you see I could open an alternate port on your server via exploit but your router would not forward this port to your win2k machine, so instead you use an exploit to make your win2k machine connect back to me, reversing a shell at the same time.
    Are you sure about that?
    What do I have to do if i get in?
    Put my name on the webpage been served?
    Yes thats it.
    Nah its grand the way it is.
    Fair enough.
    Goodluck :)


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    conceited wrote: »
    Are you sure about that?

    yes as that port would then need to be setup in the NAT table on your router togo to the win2k machine.


  • Closed Accounts Posts: 891 ✭✭✭conceited


    If you say so:pac:


  • Advertisement
  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    unless you setup a static NAT to the win2k machine?


Advertisement