⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 ntsec.html

📁 黑客培训教程
💻 HTML
📖 第 1 页 / 共 5 页
字号:
  of letters, symbols, and numbers<br>

  <b>&lt;tcg&gt;</b> again, I love your stylw<br>

  <b>&lt;tcg&gt;</b> style, rather<br>

  <b>&lt;Samcon&gt;</b> :)<br>

  <b>&lt;tcg&gt;</b> man<br>

  <b>&lt;tcg&gt;</b> noone guess passwords today<br>

  <b>&lt;Cypher&gt;</b> that's it for passwords<br>

  <b>&lt;TTT&gt;</b> There is a simple way to get a good password:<br>

  <b>&lt;Cypher&gt;</b> questions? (elad?)<br>

  <b>&lt;TTT&gt;</b> Take a phrase you remember always<br>

  <b>&lt;TTT&gt;</b> e.g.<br>

  <b>&lt;elad&gt;</b> yeah<br>

  <font color="#ff0000">*** Rockin_lad has joined #bsrf</font><br>

  <b>&lt;TTT&gt;</b> The Matrix is a great Movie<br>

  <font color="#ff0000">*** _zach- has quit IRC (Quit: yyhythythtnnt)</font><br>

  <b>&lt;elad&gt;</b> who is the real slim shady?<br>

  <b>&lt;TTT&gt;</b> then take every first letter<br>

  <b>&lt;TTT&gt;</b> and put it together<br>

  <b>&lt;Cypher&gt;</b> elad, u?! ;)<br>

  <b>&lt;TTT&gt;</b> so you got a good &quot;base&quot; for a password<br>

  <b>&lt;TTT&gt;</b> and you remember it always<br>

  <b>&lt;elad&gt;</b> tmiagm is a bad password<br>

  <b>&lt;Samcon&gt;</b> this has a real connection to the lecture<br>

  <b>&lt;TTT&gt;</b> as I said, it is a base<br>

  <b>&lt;m0ded&gt;</b> aaa is worse<br>

  <b>&lt;Rockin_lad&gt;</b> Hello room <br>

  <b>&lt;Rockin_lad&gt;</b> am I late ?<br>

  <b>&lt;Sub&gt;</b> yes<br>

  <b>&lt;m0ded&gt;</b> yeah u are<br>

  <b>&lt;Cypher&gt;</b> anyhow, if there are no more questions, lets continue<br>

  <b>&lt;Cypher&gt;</b> hey rockin_lad, a bit, yes<br>

  <b>&lt;Rockin_lad&gt;</b> oh shit <br>

  <b>&lt;QX-Mat&gt;</b> I have a question<br>

  <b>&lt;Slayer[reading_eating]&gt;</b> me too<br>

  <b>&lt;Rockin_lad&gt;</b> damn analog dialups<br>

  <b>&lt;Cypher&gt;</b> shoot, QX-Mat, Slayer<br>

  <b>&lt;QX-Mat&gt;</b> When calculating user ages under NT, what is the age set from

  (enum_xxxx_xxxx etc)<br>

  <b>&lt;elad&gt;</b> ok i'm out<br>

  <b>&lt;tcg&gt;</b> ;\<br>

  <font color="#ff0000">*** _sniper- has joined #bsrf</font><br>

  <font color="#ff0000">*** _sniper- is now known as sniper</font><br>

  <b>&lt;Slayer[reading_eating]&gt;</b> the only way to crack the share pass is brute

  force?<br>

  <b>&lt;Cypher&gt;</b> QX-Mat, user age? i'm not following....<br>

  <font color="#ff0000">*** SpiderMan has joined #bsrf</font><br>

  <b>&lt;Sub&gt;</b> i gotta go<br>

  <b>&lt;TTT&gt;</b> Hi, spider!<br>

  <b>&lt;QX-Mat&gt;</b> Never mind<br>

  <b>&lt;SpiderMan&gt;</b> hi<br>

  <b>&lt;Sub&gt;</b> cya all<br>

  <b>&lt;Cypher&gt;</b> Slayer, no, u could also try a dictionary attack<br>

  <font color="#ff0000">*** Sub has quit IRC (Quit: gone)</font><br>

  <b>&lt;QX-Mat&gt;</b> I say later with more info<br>

  <b>&lt;SpiderMan&gt;</b> wow there are a lot of people here, is there a lecture?<br>

  <b>&lt;m0ded&gt;</b> yeah god damniut<br>

  <b>&lt;TTT&gt;</b> jep, spider<br>

  <b>&lt;Samcon&gt;</b> yep<br>

  <b>&lt;m0ded&gt;</b> shut up<br>

  <b>&lt;Cypher&gt;</b> lets continue<br>

  <b>&lt;TTT&gt;</b> NT-Security<br>

  <b>&lt;Slayer[reading_eating]&gt;</b> yeah i now is there any other way then guess

  attacks<br>

  <b>&lt;Cypher&gt;</b> next issue - Permissions<br>

  <b>&lt;Rockin_lad&gt;</b> bye<br>

  <b>&lt;Cypher&gt;</b> organize them! there is no purpose of giving everyone access

  to all directories...<br>

  <font color="#ff0000">*** Olaf has quit IRC (Ping timeout)</font><br>

  <b>&lt;Cypher&gt;</b> keep users to their home dirs, and don't let them browse away<br>

  <b>&lt;m0ded&gt;</b> Read-Only<br>

  <b>&lt;Rockin_lad&gt;</b> registry maybe ?!<br>

  <b>&lt;Rockin_lad&gt;</b> take the encryped password and decrypt it , would that work

  ?<br>

  <b>&lt;Slayer[reading_eating]&gt;</b> i guess no<br>

  <b>&lt;Cypher&gt;</b> Rockin_lad, u cannot decrypt passwords<br>

  <b>&lt;Cypher&gt;</b> they use assimetric functions - one-way<br>

  <b>&lt;tcg&gt;</b> 1 way encryption<br>

  <b>&lt;tcg&gt;</b> ;\<br>

  <b>&lt;tcg&gt;</b> bbl<br>

  <b>&lt;Cypher&gt;</b> next - The Administrator account<br>

  <b>&lt;Rockin_lad&gt;</b> no , I just guessd , I think they have programs for that<br>

  <b>&lt;Cypher&gt;</b> Rockin_lad, they do something else<br>

  <b>&lt;Cypher&gt;</b> not decryption<br>

  <b>&lt;Cypher&gt;</b> which is, sadly, a built-in NT account u have no way of deleting.

  but u can rename it.....<br>

  <b>&lt;Cypher&gt;</b> now, what good will a rename do?<br>

  <b>&lt;tcg&gt;</b> people wont guess it ;\<br>

  <b>&lt;Cypher&gt;</b> and the default password is &lt;blank&gt;, btw....<br>

  <b>&lt;dr3x&gt;</b> evil script kiddies wont know what account to h4x0r<br>

  <b>&lt;Cypher&gt;</b> right :) although this sound to simple, most ppl first try

  the Administrator:&lt;blank&gt; and Guest:Guest combinations<br>

  <font color="#ff0000">*** Slayer[reading_eating] is now known as Slayer</font><br>

  <font color="#ff0000">*** sanke has joined #bsrf</font><br>

  <b>&lt;dr3x&gt;</b> I know i do!<br>

  <b>&lt;Cypher&gt;</b> so that rename will stop most script kiddies<br>

  <b>&lt;dr3x&gt;</b> (oops)<br>

  <b>&lt;Cypher&gt;</b> hehe :)<br>

  <b>&lt;sanke&gt;</b> Hey Qx<br>

  <b>&lt;Cypher&gt;</b> which just seek the net for &quot;test-my-kEwL-haX0r-skilZ&quot;

  purposes and have no intention for your system, specifically<br>

  <font color="#ff0000">*** snider has joined #bsrf</font><br>

  <font color="#ff0000">*** sniper has quit IRC (Ping timeout)</font><br>

  <b>&lt;snider&gt;</b> [19:37] [snider PING reply]: 41secs ............shit<br>

  <b>&lt;Cypher&gt;</b> so a fair solution is to rename that account and password it.<br>

  <b>&lt;Cypher&gt;</b> then create another account, named Administrator, but with absolutely

  NO permittions<br>

  <b>&lt;dr3x&gt;</b> honey pot?<br>

  <b>&lt;Cypher&gt;</b> that's another anti-script-kiddie countermeasure<br>

  <b>&lt;TTT&gt;</b> dr3x, no<br>

  <b>&lt;Cypher&gt;</b> dr3x, kinda yeah :)<br>

  <b>&lt;dr3x&gt;</b> cant you set the Administrator account to set off all sorts of

  alarms?<br>

  <b>&lt;TTT&gt;</b> A honeypot would act more aggressive, does it?<br>

  <b>&lt;Rockin_lad&gt;</b> correct me if I'm wrong , but aint the pass file supposed

  to somewhere under HKWEY_LOCAL_MACHINE/SAM OR SOMETHING ?<br>

  <b>&lt;dr3x&gt;</b> thatd make sense<br>

  <b>&lt;Cypher&gt;</b> besides, u could audit and see when someone tryes to access that

  account.... and KILL KILL KILL :)<br>

  <b>&lt;dr3x&gt;</b> yeah,<br>

  <b>&lt;Cypher&gt;</b> dr3x, u can write on-logon scripts<br>

  <b>&lt;Cypher&gt;</b> rockin_lad, yes<br>

  <b>&lt;Cypher&gt;</b> we'll get to that<br>

  <b>&lt;Rockin_lad&gt;</b> k<br>

  <font color="#ff0000">*** _zach- has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> of and btw, u also should set a real good password: something

  like - &quot;try_and_hax0r_me_u_dumbas&quot; ;-) so he won't have it easy<br>

  <b>&lt;Cypher&gt;</b> getting your &quot;zero permittions&quot; account also :)<br>

  <b>&lt;dr3x&gt;</b> hehehe<br>

  <b>&lt;Cypher&gt;</b> question time<br>

  <b>&lt;QX-Mat&gt;</b> me<br>

  <font color="#ff0000">*** tcg has quit IRC (Quit: ircII EPIC4-0.9.1 -- Accept no limitations)</font><br>

  <b>&lt;QX-Mat&gt;</b> Back with that thing earlier<br>

  <b>&lt;QX-Mat&gt;</b> For example: <br>

  <b>&lt;QX-Mat&gt;</b> # Win32-NT :)<br>

  <b>&lt;QX-Mat&gt;</b> use Win32::NetAdmin;<br>

  <b>&lt;QX-Mat&gt;</b> UserGetAttributes(&quot;&quot;, $_, $password, $passwordAge,

  $privilege, $homeDir, $comment, $flags, $scriptPath)<br>

  <b>&lt;QX-Mat&gt;</b> <br>

  <b>&lt;QX-Mat&gt;</b> The user/password age is a number, but this number is not the

  seconds since the passwords was<br>

  <b>&lt;QX-Mat&gt;</b> activated, but the seconds (or days/minuets?) from 1980 sometime

  untill the password was created<br>

  <b>&lt;QX-Mat&gt;</b> plus the actual age.<br>

  <b>&lt;QX-Mat&gt;</b> Ex: 1980 to today is 20 years + say 1 since the user made their

  password, then you do<br>

  <b>&lt;QX-Mat&gt;</b> (((((21*365)+5)*24)*60)*60), but I'm<br>

  <b>&lt;QX-Mat&gt;</b> not sure of the exact date in 1980?<br>

  <font color="#ff0000">*** ZipIt has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> are u asking what password age is measured in? days i believe....<br>

  <b>&lt;QX-Mat&gt;</b> yes, but from?<br>

  <b>&lt;Cypher&gt;</b> its the time since the password was set<br>

  <b>&lt;Cypher&gt;</b> or changed, of course<br>

  <b>&lt;QX-Mat&gt;</b> That's not how it works out of.... and I did read it was set

  from a data in the 80's<br>

  <font color="#ff0000">*** wallk has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> perhaps in nt3.51? or did u read about nt4/5?<br>

  <b>&lt;QX-Mat&gt;</b> same, user attributes are the same...<br>

  <font color="#ff0000">*** ZipIt has quit IRC (Killed (NickServ (GHOST command used by wallk)))</font><br>

  <font color="#ff0000">*** wallk is now known as zipit</font><br>

  <b>&lt;QX-Mat&gt;</b> it was because of Nt 3.51 though<br>

  <font color="#ff0000">*** zipit is now known as ZipIt</font><br>

  <b>&lt;Cypher&gt;</b> i'll check that out, can't give u a full answer now<br>

  <b>&lt;QX-Mat&gt;</b> ok<br>

  <b>&lt;Cypher&gt;</b> its a novice lecture, after all :)<br>

  <b>&lt;ZipIt&gt;</b> Hello all#<br>

  <b>&lt;Cypher&gt;</b> lets continue then<br>

  <b>&lt;Cypher&gt;</b> hey ZipIt<br>

  <b>&lt;Cypher&gt;</b> next issue of the day is - Lockout and Audit policies<br>

  <b>&lt;Rockin_lad&gt;</b> will be covering , Microfosf Exchange ?<br>

  <b>&lt;Cypher&gt;</b> if there is a thing users hate is complex passwords and lockouts<br>

  <b>&lt;Cypher&gt;</b> no<br>

  <b>&lt;Rockin_lad&gt;</b> oh , okay then <br>

  <b>&lt;Cypher&gt;</b> but as an admin, u _must_ set a complex passwords and a lockout

  policy<br>

  <b>&lt;Rockin_lad&gt;</b> lockout ?!<br>

  <b>&lt;Cypher&gt;</b> (therefor being hated by the users) :)<br>

  <b>&lt;Rockin_lad&gt;</b> he he<br>

  <b>&lt;Cypher&gt;</b> Lockout means that the system locks up after a certain number<br>

  <b>&lt;ZipIt&gt;</b> But what a user wants is not always the best thing...<br>

  <b>&lt;Cypher&gt;</b> of invalid login attempts<br>

  <font color="#ff0000">*** sanke has quit IRC (Ping timeout)</font><br>

  <b>&lt;Rockin_lad&gt;</b> oh I see , <br>

  <b>&lt;Samcon&gt;</b> screw the users<br>

  <b>&lt;Cypher&gt;</b> ZipIt, absolutelly correct!<br>

  <font color="#ff0000">*** Olaf has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> i recommend setting the invalid attemps to 3 or 5, and the lockout

  time to about 10 minutes (or more, if u desire)<br>

  <b>&lt;Cypher&gt;</b> that's actually the time in which the user cannot try any logins<br>

  <b>&lt;Cypher&gt;</b> (also an anti-script-kiddie countermeasure)<br>

  <font color="#ff0000">*** _quato_ has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> if he tryes 3 or even 5 attemps and then looses connection he'll

  just (usually) backaway<br>

  <b>&lt;_quato_&gt;</b> greetings<br>

  <b>&lt;ZipIt&gt;</b> Cypher - What about Auditing failed attemps<br>

  <b>&lt;ZipIt&gt;</b> ?<br>

  <b>&lt;Cypher&gt;</b> getting to it now :)<br>

  <b>&lt;ZipIt&gt;</b> soz<br>

  <b>&lt;Cypher&gt;</b> Auditing is another _very_ important issue in sec.<br>

  <b>&lt;_caps&gt;</b> was just reading the logs.., about setting a &quot;lifetime&quot;

  for passwords, that isn't a real good idea if you are running a big network

  that has to be dynamic<br>

  <b>&lt;Cypher&gt;</b> its help u see all those invalid logins or ever successfull ones<br>

  <b>&lt;_caps&gt;</b> users can't always check for new passwords<br>

  <b>&lt;Cypher&gt;</b> _caps, but imagine someone gets one &quot;unlimited&quot; password.....<br>

  <b>&lt;QX-Mat&gt;</b> my neighbors on BBC2<br>

  <b>&lt;Cypher&gt;</b> save that to the questions time (soon to be) plz<br>

  <font color="#ff0000">*** Sub has joined #bsrf</font><br>

  <b>&lt;ZipIt&gt;</b> But if there's 1 thing Admin's hate... and thats &quot;wading&quot;

  through MB's of Audit logs<br>

  <b>&lt;Cypher&gt;</b> Auditing lets u monitor all sorts of security related activity

  on your machine/network<br>

  <b>&lt;_quato_&gt;</b> greetings Samcon<br>

  <b>&lt;_caps&gt;</b> okay :) was just reading logs and thought i'll note on that.<br>

  <b>&lt;Cypher&gt;</b> ZipIt, normal admins, just hate logs :)<br>

  <b>&lt;ZipIt&gt;</b> lol<br>

  <b>&lt;Cypher&gt;</b> but they use and read them, anyhow :)<br>

  <b>&lt;_zach-&gt</b>; some..<br>

  <b>&lt;_zach-&gt</b>; :)<br>

  <b>&lt;Cypher&gt;</b> so the conclusion is - read your logs!!! don't underestimate

  the great power of the written word! ;-)<br>

  <b>&lt;Samcon&gt;</b> ?<br>

  <b>&lt;Cypher&gt;</b> now - before i move to NTFS - questions<br>

  <font color="#ff0000">*** sniper has joined #bsrf</font><br>

  <font color="#ff0000">*** sniper has quit IRC (Quit: plec la mama acasa !!! :))))</font><br>

  <font color="#ff0000">*** snider has quit IRC (Ping timeout)</font><br>

  <b>&lt;Cypher&gt;</b> anyone?<br>

  <b>&lt;QX-Mat&gt;</b> With Win32::EventLog, you can make perl cypher though to check

  for &quot;naughty&quot; things<br>

  <font color="#ff0000">*** DigitalFallout has joined #bsrf</font><br>

  <font color="#ff0000">*** Samcon has quit IRC (Quit: Women, You can't dig them and you can't dig them

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -