⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 ntsec.html

📁 黑客培训教程
💻 HTML
📖 第 1 页 / 共 5 页
字号:
  <b>&lt;Rockin_lad&gt;</b> yeah exactly<br>

  <b>&lt;Cypher&gt;</b> DF, what is?<br>

  <b>&lt;DigitalFallout&gt;</b> SE the admin<br>

  <b>&lt;Cypher&gt;</b> oh, that... well, u'll be surprised (especially on large networks/companies)<br>

  <b>&lt;Rockin_lad&gt;</b> so , you've got this ISP runing by NT so how can you log

  in , or in another word break in , or cant you ?<br>

  <b>&lt;DigitalFallout&gt;</b> True<br>

  <b>&lt;Cypher&gt;</b> u can take a tour to the offices<br>

  <b>&lt;DigitalFallout&gt;</b> it has happened<br>

  <b>&lt;DigitalFallout&gt;</b> However it is easier to talk to IE, an intern<br>

  <b>&lt;Cypher&gt;</b> stand in the middle and yell &quot;hey! i forgot the system password

  again, what is it?&quot;<br>

  <b>&lt;Rockin_lad&gt;</b> lol<br>

  <b>&lt;Cypher&gt;</b> and u can hear a &quot;the_password&quot; response some times<br>

  <b>&lt;Cypher&gt;</b> :)<br>

  <b>&lt;snider&gt;</b> i know, im the guy that yells<br>

  <b>&lt;Cypher&gt;</b> hehehe<br>

  <b>&lt;DigitalFallout&gt;</b> Good one<br>

  <b>&lt;Rockin_lad&gt;</b> Cypher , what gopher ?<br>

  <b>&lt;Cypher&gt;</b> so, first thing - gather information! its more then 60% of the

  deal<br>

  <b>&lt;Cypher&gt;</b> gother?<br>

  <b>&lt;Cypher&gt;</b> gather maybe?<br>

  <b>&lt;snider&gt;</b> gopher is a 10 year old service<br>

  <b>&lt;Rockin_lad&gt;</b> no Gopher<br>

  <b>&lt;m0ded&gt;</b> yeah,,<br>

  <b>&lt;snider&gt;</b> like a really old BBS<br>

  <b>&lt;m0ded&gt;</b> poor gopher..<br>

  <b>&lt;Rockin_lad&gt;</b> what does it do ?<br>

  <b>&lt;Cypher&gt;</b> of, the Gopher service :)<br>

  <b>&lt;Cypher&gt;</b> snider told already<br>

  <b>&lt;Cypher&gt;</b> i don't believe anyone uses it anymore, though<br>

  <b>&lt;Cypher&gt;</b> wait, i'll look up a formal definition :)<br>

  <b>&lt;snider&gt;</b> me neither, poor thing<br>

  <b>&lt;Rockin_lad&gt;</b> oh<br>

  <font color="#ff0000">*** rek has joined #bsrf</font><br>

  <b>&lt;rek&gt;</b> hey<br>

  <b>&lt;Cypher&gt;</b> hi rek<br>

  <b>&lt;_quato_&gt;</b> hey<br>

  <b>&lt;TTT&gt;</b> hi, Rekaerf!<br>

  <b>&lt;TTT&gt;</b> long time not seen!<br>

  <b>&lt;_quato_&gt;</b> Cypher whats network latency<br>

  <b>&lt;Rockin_lad&gt;</b> its when your analog dialup is fuck up <br>

  <b>&lt;Rockin_lad&gt;</b> fucked up<br>

  <b>&lt;Cypher&gt;</b> :)<br>

  <b>&lt;Rockin_lad&gt;</b> like mine <br>

  <b>&lt;Noon_Ghunna&gt;</b> Cypher! where are the nt passwd hashes are stored! if they

  are in sam file, where can i find it in NT.<br>

  <b>&lt;Cypher&gt;</b> its when the network is terribly late :)<br>

  <b>&lt;Rockin_lad&gt;</b> regisrty<br>

  <b>&lt;Cypher&gt;</b> Noon_Ghunna, in the SAM, in the registry, BUT<br>

  <b>&lt;Cypher&gt;</b> u cannot access it cause NT locks it (atleast one smart thing

  :))<br>

  <b>&lt;Cypher&gt;</b> BUT (again)<br>

  <b>&lt;Rockin_lad&gt;</b> check SECURITY while you're there too<br>

  <font color="#ff0000">*** ZipIt has quit IRC (Ping timeout)</font><br>

  <b>&lt;Cypher&gt;</b> u can access the SAM_ file, which is the backup file (made by

  the admin, especially for you)<br>

  <b>&lt;Cypher&gt;</b> it is not locked<br>

  <b>&lt;Noon_Ghunna&gt;</b> hey is SAM a file or its some information in registery<br>

  <b>&lt;Cypher&gt;</b> and located in the repair dir in winnt<br>

  <b>&lt;Cypher&gt;</b> Noon_Ghunna, registry is a file<br>

  <b>&lt;Cypher&gt;</b> of some sort<br>

  <b>&lt;Cypher&gt;</b> anyhow, it is stored on the disk<br>

  <b>&lt;Noon_Ghunna&gt;</b> never found the registry file in win98<br>

  <b>&lt;Cypher&gt;</b> in the system32\config directory<br>

  <b>&lt;m0ded&gt;</b> what SAM stands for?<br>

  <b>&lt;Cypher&gt;</b> cause win98 sucZ :)<br>

  <b>&lt;dr3x&gt;</b> Security Access Manager<br>

  <b>&lt;DigitalFallout&gt;</b> run-&gt;REGEDIT<br>

  <b>&lt;TTT&gt;</b> it is not a file<br>

  <b>&lt;QX-Mat&gt;</b> ooh<br>

  <b>&lt;Rockin_lad&gt;</b> Hive <br>

  <b>&lt;Cypher&gt;</b> Security_A_M..... ;-) forgot<br>

  <b>&lt;m0ded&gt;</b> <b>&lt;dr3x&gt;</b> Security Access Manager<br>

  <b>&lt;QX-Mat&gt;</b> umm, can I say something NT user related?<br>

  <font color="#ff0000">*** sanke has left #bsrf</font><br>

  <b>&lt;TTT&gt;</b> the registry is based on many files<br>

  <b>&lt;Cypher&gt;</b> right<br>

  <b>&lt;Noon_Ghunna&gt;</b> i know regedit but isn't thee a file on which the registry

  stores its backup! if there is one where in NT<br>

  <b>&lt;Cypher&gt;</b> TTT, of course, but we were talking about the SAM (a part of

  it)<br>

  <b>&lt;TTT&gt;</b> oh, alright<br>

  <b>&lt;Rockin_lad&gt;</b> USER.DAT SYSTEM.DAT mybee ?<br>

  <b>&lt;QX-Mat&gt;</b> umm, can I say something NT user related?<br>

  <b>&lt;Cypher&gt;</b> yes<br>

  <b>&lt;Cypher&gt;</b> i thing<br>

  <b>&lt;Cypher&gt;</b> QX-Mat, i think.....<br>

  <b>&lt;QX-Mat&gt;</b> I've put a couple of NT CGI's up for you too gander at. None

  of them are complete. But they demo remote user admin via perl.... http://www.q-m.net/outofsite/cgis/list.cgi<br>

  <b>&lt;Cypher&gt;</b> Just Do It :)<br>

  <b>&lt;Cypher&gt;</b> kewl<br>

  <b>&lt;Cypher&gt;</b> so, if there are no more questions, i guess we can call it a

  day/lecture :-)<br>

  <b>&lt;DigitalFallout&gt;</b> Ummmm let me think<br>

  <b>&lt;DigitalFallout&gt;</b> Did you go over print access?<br>

  <b>&lt;m0ded&gt;</b> time for NT exploits and IIS?<br>

  <b>&lt;Cypher&gt;</b> m0ded, right!<br>

  <b>&lt;Noon_Ghunna&gt;</b> who will send me the log :|<br>

  <b>&lt;m0ded&gt;</b> cool]<br>

  <b>&lt;Rockin_lad&gt;</b> yes eys yeas<br>

  <b>&lt;Slayer&gt;</b> yeah<br>

  <b>&lt;Rockin_lad&gt;</b> ecploit<br>

  <b>&lt;Cypher&gt;</b> DF, no :) (and not scanner access also :))<br>

  <b>&lt;Rockin_lad&gt;</b> exploit rules <br>

  <b>&lt;Cypher&gt;</b> i think its time for a brake<br>

  <b>&lt;DigitalFallout&gt;</b> you might want to cover how to secire printers<br>

  <b>&lt;Slayer&gt;</b> exploits and IIS<br>

  <b>&lt;Cypher&gt;</b> Have a Brake have a KitKat :)<br>

  <b>&lt;m0ded&gt;</b> hehe<br>

  <b>&lt;Rockin_lad&gt;</b> okay <br>

  <b>&lt;Slayer&gt;</b> pls<br>

  <b>&lt;dr3x&gt;</b> when the next lecture?<br>

  <b>&lt;Rockin_lad&gt;</b> let the man rest</p>

<p><b>&lt;Cypher&gt;</b> ========== 15 minutes brake ========= oki?</p>

<p><b>&lt;Cypher&gt;</b> shall we continue?<br>

  <b>&lt;m0ded&gt;</b> yeah<br>

  <b>&lt;aragorn&gt;</b> yes!<br>

  <b>&lt;m0ded&gt;</b> END OF BREAK<br>

  <b>&lt;m0ded&gt;</b> p;<br>

  <b>&lt;m0ded&gt;</b> ;p<br>

  <b>&lt;DigitalFallout&gt;</b> YOur call<br>

  <b>&lt;Slayer&gt;</b> yes lets get toexploits and IIS pls<br>

  <b>&lt;aragorn&gt;</b> right<br>

  <b>&lt;m0ded&gt;</b> IIS the best part<br>

  <b>&lt;The_Duke247&gt;</b> hmm<br>

  <b>&lt;The_Duke247&gt;</b> is that the time already ?<br>

  <b>&lt;m0ded&gt;</b> i was waiting for it<br>

  <b>&lt;QX-Mat&gt;</b> It said it was avalible twice on signup, but then on the confirmation

  email, it turned around! Kill BT!<br>

  <b>&lt;Noon_Ghunna&gt;</b> Cypher! is ntfaq worth to download?<br>

  <b>&lt;snider&gt;</b> duke: NT security lecure if you didnt know<br>

  <b>&lt;The_Duke247&gt;</b> oh really ?<br>

  <b>&lt;The_Duke247&gt;</b> errr ok then<br>

  <b>&lt;The_Duke247&gt;</b> *shuts up*<br>

  <b>&lt;Cypher&gt;</b> NTfaq? sure, y not<br>

  <b>&lt;snider&gt;</b> hehe<br>

  <b>&lt;DigitalFallout&gt;</b> Well unfortunatly I must depart. I'l have a gander at

  the logs later<br>

  <b>&lt;The_Duke247&gt;</b> can i comment on it or not ?<br>

  <b>&lt;Cypher&gt;</b> later DF<br>

  <b>&lt;DigitalFallout&gt;</b> Cya<br>

  <b>&lt;QX-Mat&gt;</b> Oh, and if any of you didn't know, I survied my hostpital Op!<br>

  <font color="#ff0000">*** DigitalFallout has left #bsrf</font><br>

  <b>&lt;The_Duke247&gt;</b> cos i know quite a bit on NT, and proxy server hence...

  ISAPI filters etc..<br>

  <b>&lt;Cypher&gt;</b> QX-Mat, that's interesting, especially cause we're talking to

  u<br>

  <b>&lt;The_Duke247&gt;</b> so whos lecturing anyway ?<br>

  <b>&lt;Cypher&gt;</b> The_Duke247, u can comment?<br>

  <b>&lt;Cypher&gt;</b> we don't know...<br>

  <font color="#ff0000">*** _quato_ has left #bsrf</font><br>

  <font color="#ff0000">*** Cypher sets mode: +v The_Duke247</font><br>

  <b>&lt;QX-Mat&gt;</b> The ISAPI is a little... ahem.... muddled.<br>

  <b>&lt;m0ded&gt;</b> shut up<br>

  <b>&lt;m0ded&gt;</b> Cypher start<br>

  <b>&lt;aragorn&gt;</b> lets go<br>

  <b>&lt;Cypher&gt;</b> that was: <b>[Cypher]</b> The_Duke247, u can comment!<br>

  <b>&lt;The_Duke247&gt;</b> lol<br>

  <b>&lt;Cypher&gt;</b> lets<br>

  <font color="#ff0000">*** Rockin_lad has quit IRC (Ping timeout)</font><br>

  <b>&lt;Cypher&gt;</b> so IIS, what is it, actually?<br>

  <b>&lt;The_Duke247&gt;</b> don't have a mic my friend, thanks for privs anyway<br>

  <b>&lt;m0ded&gt;</b> a webserver<br>

  <b>&lt;The_Duke247&gt;</b> IIS ?<br>

  <b>&lt;The_Duke247&gt;</b> Internet Information Server<br>

  <b>&lt;m0ded&gt;</b> good boy<br>

  <b>&lt;The_Duke247&gt;</b> packaged as part of Windows 2000<br>

  <b>&lt;Cypher&gt;</b> good, i was waiting for someone to type that<br>

  <b>&lt;The_Duke247&gt;</b> or the back office set<br>

  <b>&lt;Cypher&gt;</b> :)<br>

  <b>&lt;The_Duke247&gt;</b> IIS 4.0 with win2k<br>

  <b>&lt;The_Duke247&gt;</b> IIS 5.0 released<br>

  <b>&lt;m0ded&gt;</b> ok ok<br>

  <b>&lt;The_Duke247&gt;</b> with various holes already found<br>

  <b>&lt;Cypher&gt;</b> its the Microsoft Server pack<br>

  <b>&lt;The_Duke247&gt;</b> :)<br>

  <b>&lt;QX-Mat&gt;</b> TOTP is on....<br>

  <b>&lt;The_Duke247&gt;</b> yep<br>

  <b>&lt;Cypher&gt;</b> The_Duke247, we got it :)<br>

  <b>&lt;snider&gt;</b> duke : you can comment, not just satrt talking on and on and

  on and on<br>

  <b>&lt;The_Duke247&gt;</b> lol<br>

  <b>&lt;The_Duke247&gt;</b> ok then<br>

  <b>&lt;snider&gt;</b> heh<br>

  <b>&lt;Cypher&gt;</b> and as all microsoft products<br>

  <b>&lt;m0ded&gt;</b> snider right<br>

  <b>&lt;Cypher&gt;</b> IIS has bugs<br>

  <b>&lt;QX-Mat&gt;</b> !!!!!!<br>

  <b>&lt;m0ded&gt;</b> especially 4.0<br>

  <b>&lt;Cypher&gt;</b> and bugs and bugs and bugs and bugs and bugs and bugs and bugs

  and bugs<br>

  <font color="#ff0000">*** syfilis84 has joined #bsrf<br>

  <b>&lt;Cypher&gt;</b> and holes and holes and holes and holes</font><br>

  <b>&lt;Cypher&gt;</b> well, u got the picture :)<br>

  <font color="#ff0000">*** syfilis84 has left #bsrf</font><br>

  <b>&lt;The_Duke247&gt;</b> *sticks hand in the air saying&quot; me me me me me me&quot;*<br>

  <b>&lt;QX-Mat&gt;</b> :&gt;<br>

  <b>&lt;Slayer&gt;</b> so how do u exploit them:9<br>

  <b>&lt;Noon_Ghunna&gt;</b> ISS know for aspz!<br>

  <b>&lt;Slayer&gt;</b> )<br>

  <b>&lt;Cypher&gt;</b> Slayer, nah, we just look at them :)<br>

  <b>&lt;blindman`s_vision&gt;</b> can someone tell me what this is?<br>

  <b>&lt;blindman`s_vision&gt;</b> Apache/1.2.0 PHP/FI-2.0b11 on BSD/OS<br>

  <b>&lt;Cypher&gt;</b> The_Duke247, what is it?<br>

  <b>&lt;Slayer&gt;</b> arhh<br>

  <b>&lt;m0ded&gt;</b> blindman we're in a lecture<br>

  <b>&lt;The_Duke247&gt;</b> header from web server<br>

  <font color="#ff0000">*** Cypher sets mode: +m</font><br>

  <b>&lt;The_Duke247&gt;</b> HTTP 1.1<br>

  <b>&lt;Cypher&gt;</b> sorry :)<br>

  <b>&lt;The_Duke247&gt;</b> no cigar huh?<br>

  <font color="#ff0000">*** Rockin_lad has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> i'll -m it at the question part<br>

  <b>&lt;m0ded&gt;</b> Cypher devoice The_Duke!<br>

  <font color="#ff0000">#BSRF Cannot send to channel (channel is moderated, you do not have a voice)</font><br>

  <b>&lt;Cypher&gt;</b> so, IIS is fuuulll of probs and bugs<br>

  <b>&lt;Cypher&gt;</b> just waiting to be exploited<br>

  <b>&lt;Cypher&gt;</b> by.... well... various ppl<br>

  <b>&lt;The_Duke247&gt;</b> yep<br>

  <b>&lt;Cypher&gt;</b> the 4.0 version had plenty of them (5.0 less)<br>

  <b>&lt;Cypher&gt;</b> or better to say, not yet discovered ;-)<br>

  <b>&lt;The_Duke247&gt;</b> because it hasn't been around as long you could say<br>

  <b>&lt;The_Duke247&gt;</b> lol exactly<br>

  <b>&lt;Cypher&gt;</b> many of the holes were in the /scripts directory<br>

  <b>&lt;Cypher&gt;</b> it would give u to execute stuff<br>

  <font color="#ff0000">*** rattle_and_hum has joined #bsrf</font><br>

  <b>&lt;Cypher&gt;</b> for example<br>

  <b>&lt;Cypher&gt;</b> the *.bat is assosiated with the cmd.exe application<br>

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -