Hack The Net
Hack The Net
14./15.10.2005
Hack.lu 2005
Unsafe
Network
DMZ
Packet Filter
Applicaton
Gateway
Packet Filter
Safe
Network
14./15.10.2005
Hack.lu 2005
14./15.10.2005
Hack.lu 2005
- deface a website
14./15.10.2005
Hack.lu 2005
information gathering
-- know your enemy like yourself - visit targets websites
use nslookup tools to receive informations about DNS& EMAIL Server, looking for names like oracle, TestLinux, ....
14./15.10.2005
Hack.lu 2005
information gathering
-- know your enemy like yourself -www.dns.lu
Domain name: hack.lu
Domain name holder:
CSRRT-LU ASBL,
2 rue de la Paix
L - 3541 Dudelange
Administrative Contact:
Arbogast Fred
CSRRT-LU ASBL,
2 rue de la Paix
L - 3541 Dudelange
[email protected]
Technical Contact:
Dulaunoy Alexandre
10 rue du Faubourg
B - 6811 Les Bulles- Chiny
[email protected]
Name Servers:
ns0.freeblind.net
ns1.freeblind.net
14./15.10.2005
Nslookup
> server ns0.freeblind.net
Default Server: ns0.freeblind.net
Address: 158.64.24.250
> set type=ANY
> hack.lu
Server: ns0.freeblind.net
Address: 158.64.24.250
hack.lu nameserver = ns0.freeblind.net
hack.lu nameserver = ns1.freeblind.net
hack.lu internet address = 213.169.96.28
hack.lu MX preference =
10, mail exchanger = mail.hack.lu
hack.lu nameserver = ns0.freeblind.net
hack.lu nameserver = ns1.freeblind.net
ns0.freeblind.net
internet address = 158.64.24.250
ns1.freeblind.net
internet address = 158.64.24.251
mail.hack.lu
internet address = 213.169.96.28
Hack.lu 2005
information gathering
-- know your enemy like yourself -www.ripe.de
inetnum:
netname:
descr:
country:
address:
phone:
phone:
fax-no:
e-mail:
e-mail:
14./15.10.2005
213.169.96.0 213.169.127.255
LU-ASTRANET-20021104
SESM S.A. (Astra-Net)
LU
SESM S.A.
Chateau de Betzdorf,
L-6815 Betzdorf
G.-D. Luxembourg,
+352 710 725 242
+352 710 725 677
+352 710 725 482
[email protected]
[email protected]
Hack.lu 2005
information gathering
-- know your enemy like yourself - footprinting @ google
site:<targetdomain>
site:<targetdomain>
site:<targetdomain>
site:<targetdomain>
site:<targetdomain>
site:<targetdomain>
site:<targetdomain>
site:<targetdomain>
14./15.10.2005
intitle:index.of
error | warning
login | logon
username | userid
password
admin | administrator
inurl:backup | inurl:bak
intranet
Hack.lu 2005
14./15.10.2005
Hack.lu 2005
14./15.10.2005
Hack.lu 2005
10
Hack.lu 2005
11
Hack.lu 2005
12
14./15.10.2005
Hack.lu 2005
13
advanced techniques
-- IDS evasion - bypass IDS by manipulating the patterns
fragrouter supports all known techniques
examples:
Unicode in case of ASCII
replace www.target.com/etc/passwd with
www.target.com/etc/./passwd
fragmentation of packets on IP Level
14./15.10.2005
Hack.lu 2005
14
thank you
14./15.10.2005
Hack.lu 2005
15