But I had an idea: This can be a pretty good small research for fun.
- Only publicly available tools can be used for this hack, so no tool development. This is a CTF for script bunniez, and we can't haz code!
- Only hacks without user interaction are allowed (IE based sploits are out of scope).
- I need instant remote code execution. For example, if I can drop a malware to the c: drive, and change autoexec.bat, I'm still not done, because no one will reboot the CTF machine in a real CTF for me. If I can reboot the machine, that's OK.
- I don't have physical access.
PORT STATE SERVICE VERSION 139/tcp open netbios-ssn 137/udp open|filtered netbios-ns 138/udp open|filtered netbios-dgm Running: Microsoft Windows 3.X|95 OS details: Microsoft Windows for Workgroups 3.11 or Windows 95 TCP Sequence Prediction: Difficulty=25 (Good luck!) IP ID Sequence Generation: Broken little-endian incremental
- CIFS NULL Session Permitted
- Weak LAN Manager hashing permitted
- SMB signing not required
- Windows 95/98/ME Share Level Password Bypass
- TCP Sequence Number Approximation Vulnerability
- ICMP netmask response
- CIFS Share Readable By Everyone
- Weak LAN Manager hashing permitted - without user interaction or services looking at the network, useless (I might be wrong here, will check this later)
- TCP Sequence Number Approximation Vulnerability - not interesting
- ICMP netmask response - not interesting
- CIFS Share Readable By Everyone - unless there is a password in a text file, useless
- CIFS NULL Session Permitted - this could be interesting, I will check this later ...
- Windows 95/98/ME Share Level Password Bypass - BINGO!
I believe all characters between ALT+033 and ALT+255 can be used in the share password in Windows 95, but as it is case insensitive, we have 196 characters to use, and a maximum length of 8 characters. In worst case this means that we can guess the full password in 1568 requests. The funny thing is that the share password is not connected to (by default) any username/account, and it cannot be locked via brute force.
More info
- Hacker Tools Software
- Hacking Tools Windows 10
- Hack Apps
- Hacking Tools For Pc
- Hack Tools For Ubuntu
- Hacking Tools Hardware
- Game Hacking
- Hacking Tools Windows 10
- Pentest Tools List
- Hacker Tools 2020
- Nsa Hacker Tools
- Hacker Tools Free
- Hack Website Online Tool
- Hacker Hardware Tools
- What Are Hacking Tools
- Pentest Tools Open Source
- Hacker Tools Linux
- Hacker
- Tools Used For Hacking
- Hacking Tools For Windows
- Hacking Tools Download
- Physical Pentest Tools
- Hack Tools
- Underground Hacker Sites
- Hacking Tools For Beginners
- Hacker Search Tools
- Hack Tools Online
- Android Hack Tools Github
- Hacker Tools Apk Download
- Hacking Tools Usb
- Underground Hacker Sites
- Hack Tools For Pc
- Pentest Tools For Mac
- Hacking Tools For Beginners
- Pentest Tools Url Fuzzer
- Hack And Tools
- Best Hacking Tools 2020
- Hacker Search Tools
- Pentest Tools Port Scanner
- Pentest Box Tools Download
- Hacker Tools Online
- Hacker Tools For Mac
- Hack Tools Online
- Pentest Tools For Ubuntu
- Hacking Tools Software
- Pentest Tools Find Subdomains
- Hack Tool Apk
- Github Hacking Tools
- Pentest Tools For Windows
- Hacking App
- Hacking Tools And Software
- Hacker Tool Kit
- Hacking Apps
- Hack Tools For Ubuntu
- Hacking Tools 2019
- Hack Tools For Pc
- Hacker Tools 2020
- Hack Website Online Tool
- Hacking Tools And Software
- Pentest Tools List
- What Are Hacking Tools
- Pentest Tools Port Scanner
- Game Hacking
- Hacking Tools 2020
- What Are Hacking Tools
- Hack Tools For Games
- Hack Tools Github
- New Hacker Tools
- Blackhat Hacker Tools
- Tools Used For Hacking