Critical Security.NET: Tough Xp Scenario..... - Critical Security.NET

Jump to content

Rules

I want to remind people that this is not tech support, from now, it is a punishable offence to post tech support questions here.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Tough Xp Scenario..... XP security in limited accounts

#1 User is offline   pgorman98 Icon

  • Newbie
  • Pip
  • Group: Validating
  • Posts: 1
  • Joined: 09-February 10

Posted 07 February 2010 - 08:08 PM

First of all, this is not a post in which a new00b kid wants to know the tricks of cracking a XP admin password.

Aim: to get admin password on limited account of xp.

here is the scenario...
computer science lab of a college connected through lan and has internet access.

Operating System windows XP sp2

attacker has only limited account. Even a flashdrive cannot be installed. no programs can be installed.

There is no cd-rom in any computer so ophrack or linuxlive or bartpe cds will not work.

c:\windows\system32\config cannot be accessed. if sam could be copied then it could have been mailed and cracked on other systems

system cannot be booted from a flashdrive.

no hardware access. otherwise removing the battery could have reset the bios.

what may lead to possible solution..

a unrestricted internet connection is there. so anything can b downloaded and sent out of the system to internet.

if there is a program which need not to be installed and either could give full file system access or crack the hashes could have done the job.

on special request some files are transfered from one system to main system so that students can get those files on pendrive. this whole process is done under supervision of a person. so sam file cannot be taken from the main system also.

please post ur replies...
and tell wht u think. whether this system is penetrable or not.
thanks in advance

#2 User is offline   DamegedSpy Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 37
  • Joined: 05-February 10

Posted 08 February 2010 - 03:46 PM

Well there are many local vulnerabilities.
I have rooted my PC just by typing in CMD: at [next h:m] /interactive cmd.exe (A new Command Prompt should open with root access)

You should check milworm and Exploit for all those magic local vulnerabilities/exploits ;)
0

#3 User is offline   baph0m3t Icon

  • Turd
  • PipPipPipPipPipPipPipPipPip
  • Group: Oldies
  • Posts: 5,987
  • Joined: 13-June 06
  • Gender:Male

Posted 08 February 2010 - 04:42 PM

The interactive schedule trick won't work unless you have admin rights in which case you don't need it. I'd love to hear exactly how you rooted your box with it...

But you are right about local vulns - you could probably just run cain over it and dump the passwords - have they blocked executables?

E:

Quote

First of all, this is not a post in which a new00b kid wants to know the tricks of cracking a XP admin password.

Aim: to get admin password on limited account of xp.


Sorry, that did make me smile.

This post has been edited by baph0m3t: 08 February 2010 - 04:44 PM

0

#4 User is offline   talwoasc Icon

  • Posting Prodigy
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 657
  • Joined: 06-August 07
  • Gender:Male
  • Location:Yorkshire (Puddings!)

Posted 08 February 2010 - 05:19 PM

View PostDamegedSpy, on 08 February 2010 - 03:46 PM, said:

Well there are many local vulnerabilities.
I have rooted my PC just by typing in CMD: at [next h:m] /interactive cmd.exe (A new Command Prompt should open with root access)

You should check milworm and Exploit for all those magic local vulnerabilities/exploits Posted Image


That used to be as handy as hell until XP SP1 came out and ruined our fun as it worked on limited accounts aswell as admins then.
0

#5 User is offline   fuzzybunny Icon

  • Regular Member
  • PipPipPip
  • Group: Members
  • Posts: 99
  • Joined: 19-January 08
  • Gender:Male
  • Location:40.337, -74.042

Posted 09 February 2010 - 02:08 AM

I believe Metasploit includes the option to create malware pdf's. Since you have internet access, you can pretty easily construct a pdf to connect to a remote host (your computer) and spawn a shell. Once you have the shell, copy the sam file and start crackin :-) The only obstacle I can see is that you need the admin to open the pdf if you want root access, so you might need a bit of SE. Also, the correct version of adobe pdf reader needs to be installed. Hope that helps
0

#6 User is offline   Anonymous User Icon

  • Posting Prodigy
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 842
  • Joined: 15-March 08
  • Gender:Male
  • Location:░▒▓108▓▒░
  • Interests:Computer security, Programing, Music, Playing Guitar, Martial Arts, Movies, Games

Posted 10 February 2010 - 05:44 PM

If you can't "install" a flash drive that probably doesn't mean you can't boot from one as it is a security policy inside windows that is stoping you from doing this. What if you restarted the computer with a bootable USB plugged in and jamed on F12 until you got a boot prompt. You could boot into backtrack USB and have your SAM file decrypted in minutes. If you don't get a boot prompt it's because it's disabled in the bios. Restart again and jam on F2 or del until you get into the bios.


Quote

First of all, this is not a post in which a new00b kid wants to know the tricks of cracking a XP admin password.


Could have fooled me.


EDIT:
I swear that bit about not being able to boot from USB wasn't there when I first scanned the post. Still, it doesn't say your post was modified so I guess it's my bad here. nvm...

This post has been edited by Anonymous User: 11 February 2010 - 06:21 PM

0

#7 User is offline   DamegedSpy Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 37
  • Joined: 05-February 10

Posted 10 February 2010 - 07:18 PM

View Posttalwoasc, on 08 February 2010 - 05:19 PM, said:

View PostDamegedSpy, on 08 February 2010 - 03:46 PM, said:

Well there are many local vulnerabilities.
I have rooted my PC just by typing in CMD: at [next h:m] /interactive cmd.exe (A new Command Prompt should open with root access)

You should check milworm and Exploit for all those magic local vulnerabilities/exploits Posted Image


That used to be as handy as hell until XP SP1 came out and ruined our fun as it worked on limited accounts as well as admins then.

You are wrong on that. It also worked with Guest Accounts and if you run into a computer that had been off all this time is easy as hell ;)
0

#8 User is offline   baph0m3t Icon

  • Turd
  • PipPipPipPipPipPipPipPipPip
  • Group: Oldies
  • Posts: 5,987
  • Joined: 13-June 06
  • Gender:Male

Posted 10 February 2010 - 07:45 PM

Good plan.

And, of course, shorting J6 blanks any password protection of the CMOS. Means going in with a screwdriver, but hey.
0

#9 User is offline   nebriv Icon

  • Posting Superpower
  • PipPipPipPipPipPipPip
  • Group: Members
  • Posts: 1,247
  • Joined: 01-March 07
  • Gender:Male
  • Location:USA
  • Interests:Information Security
    Computer Forensics
    Photography
    Website design
    Environmental Science

Posted 10 February 2010 - 07:56 PM

View Postbaph0m3t, on 10 February 2010 - 07:45 PM, said:

And, of course, shorting J6 blanks any password protection of the CMOS. Means going in with a screwdriver, but hey.


Or any other metallic object for that matter!
0

#10 User is offline   baph0m3t Icon

  • Turd
  • PipPipPipPipPipPipPipPipPip
  • Group: Oldies
  • Posts: 5,987
  • Joined: 13-June 06
  • Gender:Male

Posted 10 February 2010 - 11:02 PM

Well if you are unscrewing the pc panels, you might as well use what's in your hand ;)

But yeah, you're right.
0

#11 User is offline   Obfuscater Icon

  • Legend
  • PipPipPipPipPip
  • Group: Oldies
  • Posts: 498
  • Joined: 18-January 08
  • Gender:Male

Posted 11 February 2010 - 11:42 AM

Sorry to rain on the BIOS-reset parade, but the scenario here has 'no hardware access' so you're going to have to be more creative, I'm afraid.
0

#12 User is offline   baph0m3t Icon

  • Turd
  • PipPipPipPipPipPipPipPipPip
  • Group: Oldies
  • Posts: 5,987
  • Joined: 13-June 06
  • Gender:Male

Posted 11 February 2010 - 11:59 AM

Shite, you're right. Right there in black and white.

Poetry. I'll stop.
0

#13 User is offline   Anonymous User Icon

  • Posting Prodigy
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 842
  • Joined: 15-March 08
  • Gender:Male
  • Location:░▒▓108▓▒░
  • Interests:Computer security, Programing, Music, Playing Guitar, Martial Arts, Movies, Games

Posted 11 February 2010 - 11:55 PM

I think fuzzy makes an excellent point. I don't see a way to achieve this without using SE to gain some kind of increased access to the target machine.
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users