But I had an idea: This can be a pretty good small research for fun.
- Only publicly available tools can be used for this hack, so no tool development. This is a CTF for script bunniez, and we can't haz code!
- Only hacks without user interaction are allowed (IE based sploits are out of scope).
- I need instant remote code execution. For example, if I can drop a malware to the c: drive, and change autoexec.bat, I'm still not done, because no one will reboot the CTF machine in a real CTF for me. If I can reboot the machine, that's OK.
- I don't have physical access.
PORT STATE SERVICE VERSION 139/tcp open netbios-ssn 137/udp open|filtered netbios-ns 138/udp open|filtered netbios-dgm Running: Microsoft Windows 3.X|95 OS details: Microsoft Windows for Workgroups 3.11 or Windows 95 TCP Sequence Prediction: Difficulty=25 (Good luck!) IP ID Sequence Generation: Broken little-endian incremental
- CIFS NULL Session Permitted
- Weak LAN Manager hashing permitted
- SMB signing not required
- Windows 95/98/ME Share Level Password Bypass
- TCP Sequence Number Approximation Vulnerability
- ICMP netmask response
- CIFS Share Readable By Everyone
- Weak LAN Manager hashing permitted - without user interaction or services looking at the network, useless (I might be wrong here, will check this later)
- TCP Sequence Number Approximation Vulnerability - not interesting
- ICMP netmask response - not interesting
- CIFS Share Readable By Everyone - unless there is a password in a text file, useless
- CIFS NULL Session Permitted - this could be interesting, I will check this later ...
- Windows 95/98/ME Share Level Password Bypass - BINGO!
I believe all characters between ALT+033 and ALT+255 can be used in the share password in Windows 95, but as it is case insensitive, we have 196 characters to use, and a maximum length of 8 characters. In worst case this means that we can guess the full password in 1568 requests. The funny thing is that the share password is not connected to (by default) any username/account, and it cannot be locked via brute force.
- Tools For Hacker
- Hacking Tools Pc
- Hackers Toolbox
- Hak5 Tools
- How To Hack
- Termux Hacking Tools 2019
- Hack Apps
- Pentest Tools
- Hacking Tools Name
- Hak5 Tools
- Hacking Tools Usb
- Hacker Tools Software
- Hacking Tools For Windows
- Hack Tools For Windows
- Hacker Tools Software
- Best Hacking Tools 2020
- Hacking Tools Mac
- Hacking Tools Windows 10
- Hack Tools Mac
- Hack Tools Github
- Hacking Tools For Games
- Pentest Reporting Tools
- Hack App
- Hack Tools For Games
- Hacker Tools List
- Hacker Security Tools
- Hacks And Tools
- Growth Hacker Tools
- Bluetooth Hacking Tools Kali
- Pentest Box Tools Download
- Pentest Tools Website Vulnerability
- Pentest Tools Apk
- Tools Used For Hacking
- Underground Hacker Sites
- Hacker Tools Github
- Underground Hacker Sites
- Hack App
- Hack Rom Tools
- Best Hacking Tools 2020
- New Hacker Tools
- Pentest Tools Github
- Hacking Tools 2019
- Tools Used For Hacking
- Hack Tools For Pc
- Hacker Hardware Tools
- Usb Pentest Tools
- Underground Hacker Sites
- Pentest Tools Bluekeep
- Hacker Tools Free
- Termux Hacking Tools 2019
- World No 1 Hacker Software
- Hack Tools For Ubuntu
- Pentest Tools Apk
- Hack Tool Apk
- Hacking Tools Mac
- Termux Hacking Tools 2019
- Hacker Security Tools
- Hacker Tools Free Download
- Pentest Tools Github
- Hacker Tool Kit
- Pentest Tools Android
- Hacking Tools For Windows
- Hack Website Online Tool
- Hacking Tools Online
- Easy Hack Tools
- Pentest Recon Tools
- Bluetooth Hacking Tools Kali
- Hacker Tools Mac
- Pentest Tools For Mac
- Hacker Security Tools
- Nsa Hack Tools
- Pentest Tools
- Hacker Security Tools
- Tools 4 Hack
- Hacking Tools For Pc
- Pentest Tools Tcp Port Scanner
- Hacking Tools For Windows Free Download
- Easy Hack Tools
- Nsa Hacker Tools
- Tools Used For Hacking
- Hack Tool Apk
- Hack And Tools
- Hacking Tools Usb
- Kik Hack Tools
- Nsa Hack Tools Download
- Hackers Toolbox
- Nsa Hack Tools
- Hacker
- World No 1 Hacker Software
- Pentest Tools Kali Linux
- Pentest Tools Android
- Hack App
- Hacker Tools 2019
- Hacker
- Easy Hack Tools
- Hacker Tools Software
- Beginner Hacker Tools
- Pentest Tools Download
- Pentest Tools Alternative
- Growth Hacker Tools
- Easy Hack Tools
- New Hack Tools
- Hack Tools Mac
- Hack Tools Mac
- Hack Apps
- Install Pentest Tools Ubuntu
- Pentest Tools List
- Hacking Tools For Windows 7
- Hacker Tools Online
- Pentest Tools Online
- Hacking Tools For Windows 7
- Pentest Tools Open Source
- Easy Hack Tools
- New Hack Tools
- Hacking Tools And Software
- Hacker Tools List
- Hacking Tools And Software
- Best Pentesting Tools 2018
- Hacker Tools Free
- Hacks And Tools
- Hacker Tools Software
- Pentest Tools For Windows
- Hack Tools Github
- Hacking Tools For Games
- Hack Tools For Pc
- Hacker Tools 2020
- Best Hacking Tools 2020
- Pentest Tools Android
- Hacking Tools Download
- Hacking Tools
- Hacking Tools For Pc
- Hacker Tools Mac
- Hacker Tools 2019
- Pentest Tools Tcp Port Scanner
- Pentest Tools Nmap
- Hacker Tools For Ios
- Pentest Tools Free
- Ethical Hacker Tools
- Free Pentest Tools For Windows
- Hacking Tools Software
- Pentest Tools Android
- Hacking Tools Windows 10
- Tools 4 Hack
- Hacker Tools Hardware
- Hack Tools
- Hacker Tools Hardware
- Hacking Tools
- Hacking Tools Windows 10
- Best Hacking Tools 2019
- Game Hacking
- Hacker Hardware Tools
- Pentest Tools Review
- World No 1 Hacker Software
- Hacking Apps
- Install Pentest Tools Ubuntu
- Pentest Tools List
- Best Hacking Tools 2019
- Hacking Tools Name
- Hacker Tool Kit
- Hack Tools For Mac
No comments:
Post a Comment