Thứ Ba, 29 tháng 4, 2014

System Hacking - p.14

Lab 13

Password Recovery Using CHNTPW.ISO

CHNTPWISO is apassiwrd recovery too! 1hat mis on WindonsServer2003, WindonsSener 2008, and Windons 7 Virtual-Machine.

Lab Scenario
Nowadays, attacking the password is one o f die most straightforward hacking attacks. Passwords are the most common access control method used by system administers to manage the usage of network resources and applications. There are numerous feasible methods to crack passwords. To be an expert etliical hacker and penetration tester, you must have sound knowledge of footprinting, scanning, and enumeration. Tins process requires an active connection to the machine being attacked. A hacker enumerates applications and banners in addition to identifying user accounts and shared resources. in this lab, we show you how to erase or recover an admin password using CHNTPW.ISO.

Lab Objectives

Tlie objective of tins lab is to help students learn:
■ Recovering the Password of Windows Server 2008

Lab Environment

To earn* out die lab, you need:
■ CHNTPW.ISO located at D:\CEH-Tools\CEHv8 Module 05 System Hacking\Password Recovery Tools\CHNTPW.ISO\cd110511
■ CHNTPW.ISO is tool to recover/erase the administrator passwords for Windows Server 2008
■ A computer running with Windows Server 2008 as Virtual Machine

Lab Duration

Time: 15 Minutes

Overview of CHNTPW.ISO

ONTPWJSOis an offline NT password and registry editor, boot disk/CD.

Lab Task

1. Start Hyper-V Manager by selecting Start ^ Hyper-V Manager.
2. Before starting diis lab make sure diat Windows Server 2008 Virtual Machine is shut down.
3. Now select Windows Server 2008 Yiitual Machine and click Settings in the  right pane of Hyper-V..Hyper


FIGURE 13.1: CHNTPW.ISO Windows Server 2008 settings

4. Select DVD drive from IDE controller in die left pane of Settings tor Windows Server 2008.
5. Check the Image file option and browse for die location of CHNTPW.ISO, and select Apply->OK.

FIGURE 13.2: CHNTPW.ISO Windows Server 2008 settings
6. Now go to Hyper-V Manager and right-click Windows Server 2008. and select Connect to start Windows Server 2008 Virtual Maclune

FIGURE 13.3: CHNTPW.ISO Connecting to Windows Server 2008
7. Click the Start ^ button; Windows Server 2008 will start.

FIGURE 13.4: starting windows server 2008 O /S
8. After booting, Window will prompt you with: Step one: Select disk where the Windows installation is
9. Press Enter.
FIGURE 13.5: CHNTPW.ISO Step One

10. Now you will see: Step TWO: Select PATH and registry files; press Enter.
FIGURE 13.6: CHNTPW.ISO Step Two

11. Select which part of the registry to load, use predefined choices, or list the files with space as delimiter, and then press Enter.

FIGURE 13.7: CHNTPW.ISO loading registry request
12. When you see: Step THREE: Password or registry edit, type yes (y), and press Enter.

FIGURE 13.8: CHNTPW.I SO Step Three
13. Loaded hives: <SAM><system><SECURITY>
1 — Edit user ckta and passwords
9 — Registry editor, now with hill write support!
Q — Quit (you will be asked if there is something to save)
in What to do? the default selected option will be [1]. Press Enter.
FIGURE 13.9: CHNTPW.ISO loading hives
14. in chntpw Edit User Info & Passwords, press Enter to enter the user name to change
FIGURE 13.10: CHNTPW.ISO chntpw Edit User Info & Passwords
15. 111 the User Edit Menu:
1 — Clear (blank) user password
2 — Edit (set new) user password (careful with diis on XP or Vista)
3 — Promote user (make user an administrator)
4 — Unlock and enable user account [seems unlocked already]
q — Quit editing user, back to user select
The default option, Quit [q], is selected. Type 1 and press Enter.
FIGURE 13.11: CHNTPWJSO User Edit Menu

16. Type ! after clearing die password of die user account, and press Enter.

FIGURE 13.12: CHNTPWISO Password Cleared
17. Load hives: <SAM><system><SECURTTY>
1 - Edit user data and passwords
9 - Registry editor, now with full write support!
Q — Quit (you will be asked if diere is somediiiig to save) in What to do?, the default selected option will be [1]. Type quit (q), and press Enter.

FIGURE 13.13: CHNTPWJSO loading hives Quit option
18. In Step FOUR: Writing back Changes, About to write file(s) back! Do it?,
here die default option will be [n]. Type yes [y] and press Enter.
FIGURE 13.14: CHNTPW.ISO Step Four

19. Tlie edit is completed.
FIGURE 13.15: CHNTPWJSO Edit Completed
20. Now turn off die Windows Server 2008 Virtual Machine.
21. Open Hyper-V Manager settings of Windows Server 2008 and change die DVD drive option to None from IDE Controller 1 and then select click Apply ״>OK.

FIGURE 13.16: CHN1PW.ISO Windows Sender 2008 Setri!1gs
22. Go to Windows Server 2008 Virtual Maclune, and click the Start button

22. Go to Windows Server 2008 Virtual Maclune, and click the Start button
23. Windows server 2008 boots without requiring any password

FIGURE 13.18: Windows Server 2008 Window
Lab Analysis
Analyze and document die results related to the lab exercise.

Questions
1. How do y o u configure CHNTPW.ISO in Windows Server 2008 Virtual Machine Settings?









































































































System Hacking - p.13

Lab 12

Viewing, Enabling, and Clearing the Audit Policies Using Auditpol

Ajidffpolis a con/n/andin Windons Server2012, Windons Server2008, and Windoirs Server 200J and is leqnhedfor querying orconfgningan a!iditpolicy at the snbcafespy level

Lab Scenario

To be an expert ethical hacker and penetration tester, you must have sound
knowledge of footprinting, scanning, and enumeration. Tins process requires an
active connection to the machine being attacked. A hacker enumerates applications
and banners in addition to identifying user accounts and shared resources.
You should also have knowledge on gaining access, escalating privileges, executing
applications, luduig tiles, and covering tracks.

Lab Objectives

The objective of tins lab is to help students learn:
■ How to set audit policies

Lab Environment

To earn־ out the lab, you need:
■ Auditpol is a built-in command in Windows Server 2012
■ You can see the more audit commands from the following link:
http:/ / technet.microsott.com/enus

/library /cc731451 %28v=ws. 100/029.aspx for Windows Server 2012
■Run diis on Windows Server 2012

Lab Duration

Time: 10 Minutes
Overview of Auditpol
Aucftpd displays information on performance and functions to man^xiate audit policies.

Lab Task

1. Select Start Command Prompt.
2. Administrator: A command prompt will appears as shown in the following
figure.
FIGURE 12.1: Administrator Command Prompt in windows server 2012
3. To view all die audit policies, type die following command in thecommand prompt: auditpol /get /category:*
4. Press Enter
FIGURE 12.2: Auditpol viewing die policies

5. To enable die audit policies, type die following command in the command prompt:
auditpol /set /category:"system",'"account logon" /success:enable /failureienable
6. Press Enter.

FIGURE 12.3: Auditpol Local Security Policies in Windows Server 2012
7. To check if audit policies are enabled, type die following command in the command prompt auditpol /get /category:*
8. Press Enter.

FIGURE 12.4: Auditpol enabling system and account logon policies
9. To clear die audit policies, type die following command in the command prompt: auditpol /clear /y
10. Press Enter.

FIGURE 12.5: Auditpol clearing die policies

11. To check if the audit policies are cleared, type the following command in the  command prompt: auditpol I get /category:*
12. Press Enter.
FIGURE 12.6: Auditpol clearing die audit policies
Lab Analysis
Analyze and document the results related to the lab exercise.


Questions

1. How do you configure global resource SACLs using Auditpol?
2. Evaluate a report or backup an audit policy to a comma separated value (CSV) text file.



















































System Hacking - p.12

Lab 11

Hiding Data Using Snow Steganog raphy


Lab Scenario

Network steganography describes all the methods used tor transmitting data over a network without it being detected. Several methods for liiduig data ina network have been proposed, but the main drawback of most of them is that they do not offer a secondary layer of protection. If steganography is detected, the data is in plaintext. To be an expert ethical hacker and penetration tester, you must have sound knowledge of footprinting, scanning, and enumeration. Tins process requires an active connection to the machine being attacked.

Lab Objectives

The objective of this lab is to help students learn:
■ Using Snow steganography to hide tiles and data
■ Hiding tiles using spaces and tabs

Lab Environment

To earn־ out die lab, you need:

■Snow located at D:\CEH-Tools\CEHv8 Module 05 System Hacking\Steganography\Whitespace Steganography\SNOW
■Run tins tool on Windows Server 2012
■ You can also download the latest version of Snow from the link http :/Avww.darks1de.com.au/snow/
■ If you decide to download the latest version, then screenshots shown in the lab might ditter

Lab Duration

Tune: 10 Minutes

Overview of Snow

Snow exploits die steganograplnc nature of whitespace. Locating trailing whitespace in text is like tinduig a polar bear 111 a snowstorm. It uses die ICE encryption algoridun, so the name is diemadcally consistent.

Lab Task

1. Open a command prompt and navigate to D:\CEH-Tool\CEHv8 module 05 system hacking\steganography\white space steganography\snow
2. Open Notepad and type Hello World! and dien press enter and press die Hyphen key to draw a line below it.
3. Save die die as readme.txt.

FIGURE 11.1: Contents of readme.txt
4. Type diis command 111 the command sheU: readme2.txt. It is die name of anodier diat will be created automatically.
snow -C -m "My sw iss bank account number is 45656684512263”
p "magic" readme.txt readme2.txt(magic is the password, you can
type your desired password also)


FIGURE 11.2: Hiding Contents of readme, txt and die text in the readme2.txt file

5. Now die data (‘ My Swiss bank account number is 45656684512263 ”) is hidden inside die readme2.txt hie with die contents of readme.txt.
6. The contents ol readme2.txt are readme.txt + My Swiss bank account number is 45656684512263.
7. Now type snow -C -p "magic" Readme2.txt: diis will show die contents of readme.txt.(magic is die password which was entered while luding die data).


FIGURE 11.3: Revealing the hidden data of readme2.txt
8. To check die tile in a G U I, open die readme2.txt in Notepad and select Edit־^ Select all. You will see die hidden data inside readme2.txt inthe form of spaces and tabs.

FIGURE11.4: Contents of readme2.txt revealed with select all option
Lab Analysis
Analyze and document die results related to die lab exercise.


Lab Questions
1. How would you lude die data of tiles widi secret data in other tiles?
2. Which encryption is used 111 Snow?










































































































































































System Hacking - p.11

Lab 10

System Monitoring Using RemoteExec

System hacking is the science of testing computers and networks for vulnerabilities andplugging.

Lab Scenario

To be an expert ethical hacker and penetration tester, you must have sound knowledge of footprinting, scanning, and enumeration. Tliis process requires an active connection to the machine being attacked. A hacker enumerates applications and banners in addition to identifying user accounts and shared resources. You should also have knowledge of gaining access, escalating privileges, executing applications, liiduig tiles, and covering tracks.

Lab Objectives

The objective of tins lab is to help students to learn how to:
■Modify Add / Delete registry keys and or values
■ Install service packs, patches, and hottixes
■ Copy folders and tiles
■ Run programs, scripts, and applications
■ Deploy Windows Installer packages in silent mode

Lab Environment

To earn־ out die lab, you need:
■ Remote Exec Tool located at D:\CEH-Tools\CEHv8 Module 05 System Hacking\Executing Applications Tools\RemoteExec
■ Windows Server 2008 running on the Yutual machine
■ Follow die Wizard Driven Installation steps

■ You can also download die latest version of RemoteExec from the link
http://www.isdecisions.com/en
■ If you decide to download die latest version, dien screenshots shown in the lab might differ
■ Administrative pnvileges to run tools

Lab Duration

Tune: 10 Minutes

Overview of RemoteExec

RemoteExec, die universal deployer for Microsoft Windows systems, allows network administrators to run tasks remotely.

Lab Task

1. Install and  launch RemoteExec.

FIGURE 10.1: RemoteExec main window
2. To configure executing a file, double-click Remote jobs.

FIGURE 10.2: RemoteExec configuring Remote jobs
3. To execute a New Remote job, double-click die New Remote job option diat configures and executes a new remote job

FIGURE 10.3: RemoteExec configuring New Remote job

4. in a New Remote job configuration you can view different categories to work remotely.
5. Here as an example: we are executing die file execution option. To execute double-click File Execution.
FIGURE 10.4: RemoteExec configuring File Execution
6. In the File execution settings, browse die executable file, select Interactive from drop-down list of Context, and check the Auto option

FIGURE 10.5: RemoteExec File execution settings
7. Configuring die Filter Section:
a. For the OS version, select = from die drop-down menu and specify die operating system.
b. For the OS level, select = from die drop-down menu and select Workstation.
c. For the IE version, select >= from die drop-down menu and specify the IE version.
d. For the Service Pack, select = from die drop-down menu and specify die service pack version

FIGURE 10.6: RemoteExec Filter tab
8, Selecting a Target Computer: Enter die target computer name manually by selecting Name from the drop-down list and clicking OK.

FIGURE 10.7: RemoteExec Add/Edit a computer
9. To execute the defined action on die remote computer, click the Launch
option in the nglit pane of die window.

FIGURE 10.8: RemoteExec executing the defined action
Lab Analysis

Analyze and document die results related to die lab exercise.





































































































































































System Hacking - p.10

Lab 10

Password Cracking Using Ophcrack

Ophcrnck is a free open source (GPL licensed) pmgram that cracks Windows passn ׳ords by using LM hashes through rain bon ׳ tables.

Lab Scenario

in a security system that allows people to choose their own passwords, those people
tend to choose passwords that can be easily guessed. Tins weakness exists 111
practically all widely used systems instead of forcing users to choose well-chosen
secrets that are likely to be difficult to remember. The basic idea is to ensure that
data available to the attacker is sufficiently unpredictable to prevent an off-line
verification of whether a guess is successful or not; we examine common forms of
guessing attacks, password cracking utilities to develop examples of cryptographic
protocols that are immune to such attacks. Pooiiy chosen passwords are vulnerable
to attacks based upon copying information. 111 order to be an expert ethical hacker
and penetration tester, you must understand how to crack the weak administrator or
system user account password using password cracking tools. 111 tins lab we show
you how to crack system user accounts using Ophcrack.
Lab Objectives

The objective of this lab is to help students learn:

■ Use the OphCrack tool
■ Crack administrator passwords

Lab Environment

To earn־ out die lab, you need:

" OphCrack tool located at D:\CEH-Tools\CEHv8 Module 05 System Hacking\Password Cracking Tools\Ophcrack

■ Run this tool on Windows Server 2012 (Host Machine)
■ You can also download the latest version of LOphtCrack from the link http:/ / ophcrack.sourceforge.net/


■ Administrative privileges to run tools
■ Follow the wizard-driven installation instructions

Lab Duration

Time: 15 Minutes

Overview of OphCrack

Rainbow tables for LM hashes of alphanumeric passwords are provided for free by developers. By default, OphCrack is bundled with tables diat allow it to crack passwords no longer than 14 characters using only alphanumeric characters.

Lab Task

1. Launch the Start menu by hovering the mouse cursor on the lower-left corner of the desktop.

FIGURE 9.1: Windows Server 2012 - Desktop view
2. Click the OphCrack app to open the OphCrack window

FIGURE 9.2: Windows Server 2012—Apps

3. Tlie OphCrack main window appears

FIGURE 9.3: OphCrack Main window
4. Click Load, and then click PWDUMP file
Fig 9.4: Selecting PWDUMP file

5. Browse die PWDUMP file diat is already generated by using P\\T)UMP7 111 die previous lab 110:5 (located at c :\hashes.txt).
6. Click Open

FIGURE 9.5 import the hashes from PWDUMP file
7. Loaded hashes are shown 111 the following figure

FIGURE 9.6 Hashes are added
8. Click Table. The Table Selection window will appear as shown in the following figure.

FIGURE 9.7: selecting die Rainbow table
Note: You can download die free XP Rainbow Table, Vista Rainbow Tables from http:// ophcrack.sourcelorge.net/tables.php

9. Select Vista free, and click Install.

FIGURE 9.8: Installing vista free rainbow table

10. The Browse For Folder window appears; select the the table_vista_free folder (which is already download and kept at D:\CEH-Tools\CEHv8 Module 05 System Hacking\Password Cracking Tools\Ophcrack)

11. Click OK.



12. The selected table vista free is installed,; it shows a green color ball which means it is enabled. Click OK.

FIGURE 9.9: vista free rainbow table installed successfully
13. Click Crack: it will crack die password as shown 111 die following figure

FIGURE 9.10: passwords ate cracked
Lab Analysis

Analyze and document the results related to the lab exercise


Questions
1. What are the alternatives to cracking administrator passwords?