Week 5: System Hacking • Administrator Password Guessing 1
Week 5: System Hacking • Performing Automated Password Guessing • Legion • NTInfo. Scan 2
Week 5: System Hacking • • Defending Against Password Guessing Monitoring Event Viewer Logs Visual. Last Eavesdropping on Network Password Exchange 3
Week 5: System Hacking • Hacking Tool: L 0 pht. Crack • Hacking Tool: Kerb. Crack http: //ntsecurity. nu/toolbox/kerbcrack/ 4
Week 5: System Hacking • Privilege Escalation • Hacking Tool: Get. Admin • Hacking Tool: hk www. nmrc. org 5
Week 5: System Hacking • Manual Password Cracking Algorithm • Automatic Password Cracking Algorithm • Password Types 6
Week 5: System Hacking • • Types of Password Attacks Dictionary Attack Brute Force Attack Distributed Brute Force Attack 7
Week 5: System Hacking • Password Change Interval • Hybrid Attack • Cracking Windows 2000 Passwords 8
Week 5: System Hacking • Retrieving the SAM file • Redirecting SMB Logon to the Attacker • SMB Redirection 9
Week 5: System Hacking • Hacking Tool: SMBRelay 2 10
Week 5: System Hacking • SMBRelay Man-in-the-Middle (MITM) • SMBRelay MITM Countermeasures 11
Week 5: System Hacking • Hacking Tool: SMBGrinder • Hacking Tool: SMBDie • Hacking Tool: NBTDeputy 12
Week 5: System Hacking • Net. BIOS Do. S Attack • Hacking Tool: nbname • Hacking Tool: John the Ripper 13
Week 5: System Hacking • Lan. Manager Hash • Password Cracking Countermeasures 14
Week 5: System Hacking • Keystroke Logger • Hacking Tool: Spector http: //www. spectorsoft. com/ • Anti. Spector http: //www. antikeyloggers. com/ 15
Week 5: System Hacking • Hacking Tool: e. Blaster • Hacking Tool: Spy. Anywhere • Hacking Tool: IKS Software Logger 16
Week 5: System Hacking • Hardware Tool: Hardware Key Logger • Hacking Tool: Rootkit • Planting Rootkit on Windows 2000 Machine 17
Week 5: System Hacking • _rootkit_ embedded TCP/IP Stack • Rootkit Countermeasures 18
Week 5: System Hacking • MD 5 Checksum utility • Tripwire www. tripwire. com www. tripwire. org 19
Week 5: System Hacking • • Covering Tracks Disabling Auditpol Clearing the Event Log 20
Week 5: System Hacking • Hacking Tool: Elsave • Hacking Tool: Winzapper • Hacking Tool: Evidence Eliminator 21
Week 5: System Hacking • • Hiding Files NTFS File Streaming Hacking Tool: makestrm NTFS Streams Countermeasures: LADS, sfind can detect ADS (alternative data streams) • LNS 22
Week 5: System Hacking • • • Steganography (covered writing) Hacking Tool: Image. Hide Hacking Tool: MP 3 Stego Hacking Tool: Snow Hacking Tool: Camera/Shy 23
Week 5: System Hacking • • • Steganography Detection Steg. Detect Encrypted File System Hacking Tool: dskprobe Hacking Tool: EFSView 24
Week 5: System Hacking • • Buffer Overflows Creating Buffer Overflow Exploit Outlook Buffer Overflow Hacking Tool: Outoutlook 25
Week 5: System Hacking • Summary 26