Remote Exploit Forums

Go Back   Remote Exploit Forums > Specialist Topics > Pentesting


Pentesting Specific topics related to legal penetration testing

   

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-23-2008, 04:34 AM
alienstargate's Avatar
Junior Member
 
Join Date: Jul 2007
Posts: 15
Default Hacking RealVNC

Ok ppl have a question,

i'm doing a pentest on a gov instance and founs some intresting stuff...

For now i'm focusing on VNC, i was able to runs the vnc 4.1 bypass exploit so am able to get the login screen of a 2k3 server.

My question is: is there a way to use some other exploit on the vnc or trough the vnc or inject something in there so i can get acces to the machine? think of a command shell or add users etc.

pls advice!
__________________
__________________________________

http://home.hccnet.nl/ea.abbink/imag...al_400x150.gif

·[a588d91aa2377044a8dad5d29360ff2d724d7f8a91078fde24 a8e55f01713194]·
__________________________________________________ ______________________________
Reply With Quote
  #2 (permalink)  
Old 05-23-2008, 07:53 AM
wyze's Avatar
Jenkem Addict
 
Join Date: Jul 2007
Location: chmod 400
Posts: 1,596
Default

Quote:
Originally Posted by alienstargate View Post
Ok ppl have a question,

i'm doing a pentest on a gov instance and founs some intresting stuff...

For now i'm focusing on VNC, i was able to runs the vnc 4.1 bypass exploit so am able to get the login screen of a 2k3 server.

My question is: is there a way to use some other exploit on the vnc or trough the vnc or inject something in there so i can get acces to the machine? think of a command shell or add users etc.

pls advice!
You're hacking the government?
__________________
dd if=/dev/swc666 of=/dev/wyze
Reply With Quote
  #3 (permalink)  
Old 05-23-2008, 08:35 AM
alienstargate's Avatar
Junior Member
 
Join Date: Jul 2007
Posts: 15
Default

YES!!!!

it's a project i've scored so i'm allowed to test their security (externaly)
anyway any advice?
__________________
__________________________________

http://home.hccnet.nl/ea.abbink/imag...al_400x150.gif

·[a588d91aa2377044a8dad5d29360ff2d724d7f8a91078fde24 a8e55f01713194]·
__________________________________________________ ______________________________
Reply With Quote
  #4 (permalink)  
Old 05-23-2008, 09:11 AM
archangel.amael's Avatar
Moderator
 
Join Date: Nov 2007
Location: I changed it for you.
Posts: 4,192
Default

Of what country ?
Is it possible you could slip me a pm with the name of the company you work for so maybe I could apply for a job there too?
__________________
Please visit the new forums for any and all help with Back Track 4 Final.
BackTrack-Linux is the new home.
Reply With Quote
  #5 (permalink)  
Old 05-23-2008, 09:39 AM
Thorn's Avatar
Senior Member
 
Join Date: Jul 2007
Location: The Village, of course
Posts: 1,398
Default

Quote:
Originally Posted by archangel.amael View Post
Of what country ?
China, testing the US DOD.



And it is just me, or are picture signatures one of the most annoying things people can do on a forum?
__________________
Thorn

“Never try to teach a pig to sing; it wastes your time and it annoys the pig.”
- Robert Heinlein

Last edited by Thorn; 05-23-2008 at 09:41 AM.
Reply With Quote
  #6 (permalink)  
Old 05-23-2008, 09:51 AM
williamc's Avatar
Senior Member
 
Join Date: May 2007
Posts: 280
Default

Code:
net use \\ipaddress /u:user password
Code:
regread.exe \\ipaddress software\orl\winvnc3\default Password | grep -v [g-zG-Z] | tr -d [:blank:]
This will get you the encrypted password. Then use vncpwdump.exe to decrypt it.

William
Reply With Quote
  #7 (permalink)  
Old 05-23-2008, 09:54 AM
theprez98's Avatar
Super Moderator
 
Join Date: Apr 2007
Location: Maryland
Posts: 2,556
Default

Quote:
Originally Posted by Thorn View Post
And it is just me, or are picture signatures one of the most annoying things people can do on a forum?
Sorry, it's just you.

I'd ban them if I could.
__________________
theprez98
"I want peace on earth and goodwill toward men."
"We are the United States Government. We don't do that sort of thing!"
Reply With Quote
  #8 (permalink)  
Old 05-23-2008, 10:03 AM
archangel.amael's Avatar
Moderator
 
Join Date: Nov 2007
Location: I changed it for you.
Posts: 4,192
Default

Quote:
Originally Posted by Thorn View Post
China, testing the US DOD.
Darn and I was hoping I good get a job and get rich quick or something.
Not to mention the war stories I could tell.
__________________
Please visit the new forums for any and all help with Back Track 4 Final.
BackTrack-Linux is the new home.
Reply With Quote
  #9 (permalink)  
Old 05-23-2008, 12:05 PM
thorin's Avatar
Senior Member
 
Join Date: Feb 2006
Location: Northern Hemisphere
Posts: 2,545
Default

Maybe I'm being overly harsh but I call BS.

How do you land a Gov't contract with the skills (writing and technical) demonstrated in the original post?

Quote:
Originally Posted by Thorn View Post
And it is just me, or are picture signatures one of the most annoying things people can do on a forum?
No it's not just you. I often end up adblocking things like that.

Quote:
Originally Posted by theprez98 View Post
Sorry, it's just you.

I'd ban them if I could.
Huh? It's just him but you'd ban them if you could?

Oh looky looky, sig pic is in a list'able directory (as are the parent directories):
http://home.hccnet.nl/ea.abbink/images/alien/

Even better, seemingly way out of date apache server:
Code:
Apache/1.3.26 Server at home.hccnet.nl Port 80
__________________
I'm a compulsive post editor, you might wanna wait until my post has been online for 5-10 mins before quoting it as it will likely change.

I know I seem harsh in some of my replies. SORRY! But if you're doing something illegal or posting something that seems to be obvious BS I'm going to call you on it.
Reply With Quote
  #10 (permalink)  
Old 05-23-2008, 12:12 PM
archangel.amael's Avatar
Moderator
 
Join Date: Nov 2007
Location: I changed it for you.
Posts: 4,192
Default

Quote:
Originally Posted by thorin View Post
Maybe I'm being overly harsh but I call BS.

How do you land a Gov't contract with the skills (writing and technical) demonstrated in the original post?
Well I thought the same thing, but I was hoping to get rich quick and be able to tell some tales of the ol' tiger team hax0rs the big bad gov.


Quote:
Oh looky looky, sig pic is in a list'able directory (as are the parent directories):
http://home.hccnet.nl/ea.abbink/images/alien/

Even better, seemingly way out of date apache server:
Code:
Apache/1.3.26 Server at home.hccnet.nl Port 80
OOPS! Maybe that was not meant to be seen, or maybe it's part of a uber leet honeypot!
__________________
Please visit the new forums for any and all help with Back Track 4 Final.
BackTrack-Linux is the new home.
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:34 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2