• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 4719
  • Last Modified:

Netbios - Using IPC$ null session to compromise windows system

I am doing security penetration testing from a Linux (RH9.0) environment...

1: Port scan

2: nmblookup

3: smbclient

I have accessed my computer (remotely) using a null session to

//server/IPC$

with the following smbclient command

[user@localhost /] smbclient //server/IPC$ "" -dt/share -I 172.16.0.1 -N -W WORKGROUP

which gives me the prompt

smb \>

I do not have write access.

Where do I go from here on a Linux machine?

I want to emumerate users/shares/etc..  but I am using Linux...  Any ideas?

Also, what else can be done to gain access once you have a null session?


0
cduke250
Asked:
cduke250
  • 3
  • 2
1 Solution
 
Rich RumbleSecurity SamuraiCommented:
PERL !-)
http://www.roth.net/perl/scripts/scripts.asp?Null.pl
http://www.xav.com/perl/site/lib/Win32/NetResource.html

You can use perl in windows alot, even run it on them ... I remember using cygwin and a few others on winblows, and it was doing a fine job, then I found a book that helped me administer M$ how I always wanted too...
http://www.amazon.com/exec/obidos/tg/detail/-/1578700566/qid=1083120410/sr=8-1/ref=sr_8_xs_ap_i1_xgl14/104-5064769-9078301?v=glance&s=books&n=507846

I also found that *nix can make ton's of API calls and other very usefull interactions with M$ without much fuss :)

I hope that script helps ... it's very similar to how you can do the same thing's with windows itself... (winfo.exe is a great program)
GL!
-rich
0
 
cduke250Author Commented:
Sorry little confused here...

Are you saying to download perl and then download win32 and lanman libs/src and then compile this script in linux?

Will it work from linux or do I have to wine it?

I installed wine but haven't been able to get enum.exe , dumpSEC, nete, user2sid, sid2user to work with it yet...  wine debug
says it can't find certain functions of the netapi32.dll files.  

0
 
Rich RumbleSecurity SamuraiCommented:
no no the native perl should work... I was going a bit off topic- the win32 book i mentioned is for running perl on win2k etc... sorry... Perl doesn't compile... you save the script in a txt file, and make sure you have the modules it calls (use Win32::Lanman;use Win32::TieRegistry) that's all.  then run it...  "./null.pl"

wine won't work for most of those tools, VMware would... but you might as well have a M$ pc then...
-rich
0
 
cduke250Author Commented:
Tell me where to download win32::lanman and win32::tieregistry and how to install and you got yourself 400 points rich.
0
 
Rich RumbleSecurity SamuraiCommented:
CPAN owns
Normally most of these are included, Perl will just make a CALL to them... http://www.cpan.org/misc/cpan-faq.html#How_installed_modules
http://www.cpan.org/modules/by-module/Win32/  (search for "tie" and "lanman"
and look here for additional help
http://perl.about.com/library/weekly/aa030500a.htm (4 page article)
GL!
-rich



0

Featured Post

A Cyber Security RX to Protect Your Organization

Join us on December 13th for a webinar to learn how medical providers can defend against malware with a cyber security "Rx" that supports a healthy technology adoption plan for every healthcare organization.

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now