RE: Hacking to Xp box

From: Josh perrymon (perrymonj@networkarmor.com)
Date: Fri Sep 02 2005 - 10:05:15 EDT


If you scanned it with Nessus what vulnerabilities does it have other
that TCP Stack issues? I think you will find with desktops your limited
on real services to attack other than a few RPC / NetBIOS
vulnerabilities.. sometimes the ASN.1 may be vulnerable.. But if it's
patched then you will have a harder time..

You may be able to use some of the IE exploits to control his machine..
Or if you compromise the domain then you can use admin credential to get
into it... just be creative.. think how you could get it with actual
credentials then go after them..

Some ideas....

Joshua Perrymon
Sr. Security Consultant
Network Armor
A Division of Integrated Computer Solutions
perrymonj@networkarmor.com
Cell. 850.345.9186
Office: 850.205.7501 x1104

-----Original Message-----
From: phugo@highspeedweb.net [mailto:phugo@highspeedweb.net]
Sent: Thursday, September 01, 2005 7:07 PM
To: pen-test@securityfocus.com
Subject: RE: Hacking to Xp box

Hi,
Shouldn't you try to penetrate something more important than the CEO box
?
Aren't there any more important servers than CEO box ?
In what aspect do you need better security ? Having a "good" antivirus
protection, all patches, and firewalls enabled at desktops, doesn't look
that bad security.
Regards,
Pedro

-----Original Message-----
From: Juan B [mailto:juanbabi@yahoo.com]
Sent: quinta-feira, 1 de Setembro de 2005 6:46
To: pen-test@securityfocus.com
Subject: Hacking to Xp box

Hi Guys

Please give me a hend here.

Im trying to penetrate the CEO box to show him why we need better
security
in our company, he told me to show me how it can be done. he has xp pro
sp 2
with all the pathches installed and FW enbled but I cant ! I tried to
use
metasploit with the ms rpc dcom exploit but it didnt worked. nessus
found
port 135 139 2000 and ntp are opened and also he can read some smb
shares
and also outputed that this host doesnt disgard SYN packets that have
the
FIN flag set. and port 2000 (callback is open).
what I can try more to break this box? any ideas? I know I allways can
try
to arp poison his arp table and pass all the machines traffic throw my
laptop to capture some passwords but this is enough. or send him a
trojan but we have a good anti virus protection .
            
                            
Does some of you have Ideas ?

Thanks a lot !

Juan

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

------------------------------------------------------------------------

----
--
Audit your website security with Acunetix Web Vulnerability Scanner: 
Hackers are concentrating their efforts on attacking applications on
your
website. Up to 75% of cyber attacks are launched on shopping carts,
forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers
are
futile against web application hacking. Check your website for
vulnerabilities to SQL injection, Cross site scripting and other web
attacks
before hackers do! 
Download Trial at:
http://www.securityfocus.com/sponsor/pen-test_050831
------------------------------------------------------------------------
----
---
------------------------------------------------------------------------
------
Audit your website security with Acunetix Web Vulnerability Scanner: 
Hackers are concentrating their efforts on attacking applications on
your 
website. Up to 75% of cyber attacks are launched on shopping carts,
forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers
are 
futile against web application hacking. Check your website for
vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before
hackers do! 
Download Trial at:
http://www.securityfocus.com/sponsor/pen-test_050831
------------------------------------------------------------------------
-------
------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 
Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:
http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:54:48 EDT