Tuesday, September 29, 2009

Forgot that Windows password?

So there are many ways to retrieve that lost Windows password. I just wanted to share this for those that might run into some problems that I have seen.

So you might run into a situation where you need to reset the local administrator password on a Windows box. You might reboot into something like NT PASSWORD. Now comes the problem. You boot into this and it doesn't want to mount your drives or doesn't seem to want to find the SAM file. I did notice this happens more often when the system has been shut down improperly. To fix that issue, just reboot into safe mode. This will normally let you shut down properly. You might have to do this more than once. If that still doesn't work, have no fear:

Boot into Backtrack. After your booted up, check your mounts with the mount command. If you see your Windows system partition, your set if not you should try to mount it with the following:

ntfs-3g /dev/sda2 /mnt/sda2 -o force

That should mount your drive, it does expect that your drive is sda2. If it is not, put your value here. If you don't know check your logs and dmesg to see what it might be.

After it is mounted cd into the /pentest/password/chntpw directory.

Run the following:

chntpw -l /mnt/sda2/WINDOWS/system32/config/SAM

This should list the users that exist in the SAM file on the local system.

To change the password do the following:

chntpw -u Administrator /mnt/sda2/WINDOWS/system32/config/SAM

*Note: If your username happens to contain a space put it in quotes*

This will present you with some options as to what to change. Choose to blank out the password. You can also set it, but I have found this way to be the easiest. You can set it to what you want it to once you get the box back up.

After you modify the password, write your changes. This may ask for you to run a disk check after you reboot. Skip this on the first boot. Change your password after it comes back up then you can reboot and let it do what it wants.

This isn't an exact step by step. It is taking into account that you have Linux experience and some familiarity with password reset procedures. I just wanted to share this because I have seen admins feel like they are out of luck after NT Password does not work. Have no fear! You do have another option.

Monday, September 14, 2009

WEP Y?

Wow! It is truely amazing just how many people still use WEP. I'm not going to go on a huge rant about this but if you are using it STOP! People often say, well it's better than nothing. I say not really. The reason I say this is because it gives you a sense of security that is false. Others say "but I don't have anything anyone would want". I say there are millions of identities stolen from home computers. Most wireless access points have WPA, use this. If it has WPA2 then that is even better. In the "it's better than nothing" category, I would say WPA is here with WPA2 being the best at this time for home use.

With that in mind, I thought I would show how easy it is to crack WEP in a few simple commands and the right, freely available, tools.

*Disclaimer: Please remember not to use this for nefarious purposes. This is informational only. Do it on your own access point as a proof of concept or make sure it is in your rules of engagement for a penetration test for a client.*

I will not be held liable for any misuse of this information!

Cracking WEP

1. Download the tools:

Backtrack 4

2. Boot into the Disk

3. Find a good target by running the following command:

airodump-ng wlan0 (just run airodump-ng by itself to find your interface name, mine happens to be wlan0)

4. Write down the BSSID, ESSID, and channel of the AP with the strongest signal (this one is normally near the top of the list)

5. Lock onto the target with the following command in a new terminal window:

airodump-ng -w wep -c 11 --bssid 00:00:00:00:00:00 wlan0 (here WEP is the encryption type, -c is the channel, in this example it is 11 but enter the value you saved in step 4, the bssid will not be all zeros either, enter the BSSID you wrote down in step 4 in the style I wrote the zeros)

6. Attempt association to the AP with the following command in another terminal window:

aireplay-ng -1 0 -a 00:00:00:00:00:00 wlan0 (here again the bssid should not be zeros but the value you have from step 4)

7. Hopefully your card supports packet re-injection. This basically means when it finds some interesting traffic that it can recognize, it will replay that packet back into the network and make this process much faster. Do this step by typing the following in yet another terminal window:

aireplay-ng -3 -b 00:00:00:00:00:00 wlan0 (Remember not zeros but the step 4 BSSID here)

8. Once you see the "data" section get to somewhere between 20K and 30K you should be good to go. do an ls -la to capture the file name that was created. It is the file with the .cap extension.

9. Armed with that information run the following command to crack the WEP key

aircrack-ng filename (remember it should look like wep02.cap or something else with the .cap extension)

This final step is the quickest. Depending on if your wireless card supports packet re-injection, it could take a while to capture the needed traffic to get the pieces you need to crack WEP. If your card is fully supported with re-injection, this will probably take no more than 15 minutes as an average. You can run the crack command at random intervals during the capture process to see if you got it yet, though I recommend just waiting until you get 20-30K data numbers. I haven't seen it really work with less than that. Not saying it doesn't, I just haven't seen it.

So there you have it. Scary huh? It is. Please remember not to use this for nefarious purposes. This is informational only. Do it on your own access point as a proof of concept or make sure it is in your rules of engagement for a penetration test for a client. I didn't give you this so you can go cracking your neighbor's wireless connection :)

Monday, August 24, 2009

Personal Identification Disclosure

So I have been looking to rent a new place as I moved back to the DC metro area. What I have found is an exuberant amount of people that are asking for a ridiculous amount of personal information. They are asking for SSN, checks which would obviously include account and routing information, and I even had one person asking to set up the ability for them to auto charge my account for the monthly rent and yet another asking for a photocopy of 2 picture IDs and my SSN card!

I have probably found myself looking for this stuff more and more lately but I find this outrageous. My general question is; Am I being over paranoid or is it correct of me to deny them these things? It’s bad enough that I need to keep thieves from gaining access to this via my personal space, but now I need to put reliance on these people, which most are arguably ignorant about computer and general security, from getting hacked and exposing my information.

What ways are there to get around this? Obviously I see their side of wanting this information, but they should understand this side as well. Explaining this to them is quite difficult though unless they have been a victim of such a crime. I thought about running the credit checks myself and scrubbing the information and just denying the existence of a personal checking account. Any other suggestions?

Tuesday, August 18, 2009

SANS 560 anyone?

I was extended an invitation to become a SANS mentor. This means I will be running some classes real soon. I will be starting with offering the 560. This is the class you would take to obtain your GPEN certification. Time and place to be announced soon. If you are interested, drop me a line and let me know. I'll get you on the list. Here is the link of the course and what is included:

SANS 560

I Can't hear you now! :(

You read that correctly. I was unable to get a good test with the bluetooth hacking this weekend. The reason? It appears that when you pass your bluetooth through to a virtual machine on your Mac, you loose a lot of the needed functionality. Yes, yes I know. You are thinking why didn't you just get carwhisperer to work on the Mac or try the Windows route, or boot your Dell into Backtrack?

The truth is that I wanted to see it work this way. I really like the idea of having one laptop that can do everything I need to do with the use of VMWare. Alas, this is not the case yet; at least not without getting external wifi and bluetooth dongles. I will attempt again this weekend with the Dell and Backtrack.

I did find something else interesting though....the PS3 has bluetooth. My goal may be to see what kind of cool stuff I can do there as well.

Friday, August 14, 2009

Can you hear me now?

OK, OK my posting has been a bit spotty. I'm trying :) So anyway why I am posting today.... Can you hear me now? Reminds you of a Verizon commercial. Well, this post has to do with...well cell phones, and bluetooth headsets. You may have all been reading how vulnerable bluetooth is. Do you know just have vulnerable? Check out the following video by Josh Wright:

I Can I hear you now!

So how scary is that? Bet you will think twice about wearing one of those bad boys now :). That got me thinking, those of you that know me you know how that goes! If we can eavesdrop/inject on bluetooth headsets then I bet we can eavesdrop/inject on car bluetooth systems. Well...I hope to test this tomorrow and see. I'm traveling back from PA in the AM and will have a few hours at my disposal. If by some reason I am too tired, it will be done this weekend and I will post my results here. This can have a very scary outcome. Lets hope more thought was put into the car bluetooth setup though...yeah right!

Monday, July 20, 2009

Passed the GPEN!

Just wanted to share that I passed the GPEN exam! Got a 90%. It was one of those exams that showed you your progress. This was a blessing and curse. It was nice to know I passed after getting 105 questions correct, but since I knew I passed at that time, it was easy to slack off toward the end and I missed a number of questions because of it.

I put in my application for my GPEN gold. The paper title is: "Identifying Load Balancers in Penetration Testing". The application was approved. I will begin work on the paper starting around the 10th of next month. It is a 6 month process so more to come on that. I have a lot of work ahead of me.

In the mean time, still being on track with my certification goals, I began studying for the CISSP yesterday. I hope to have it done before the years end. (If anyone else is studying for this one as well and would like to get together online or in person to study, let me know) That was the goal I set forth. Then in the beginning of next year I will be finishing my GPEN gold paper and starting to get ready for the GSEC towards my GSE.