-
Grand Future Air Dried Beef Dog Food

Carnivore Diet for Dogs

Air Dried Dog Food | Real Beef
Go Back   Automotive Forums Car Chat > Coffee Break (Off-Topic) > COMPLETELY off-topic
Register FAQ Community
COMPLETELY off-topic Talk about anything other than cars. But you can't be mad and angry in this forum!
Reply Show Printable Version Show Printable Version | Subscription Subscribe to this Thread
 
Thread Tools
  #1  
Old 08-31-2005, 02:01 AM
Oz's Avatar
Oz Oz is offline
Aussie Mod
 
Join Date: Dec 2001
Posts: 13,239
Thanks: 0
Thanked 2 Times in 2 Posts
Send a message via AIM to Oz
Penetration Testing

Hi all,
Just saw a penetration demonstration by Jesper Johannsen (Microsoft), where he penetrates a corporate domain controller (and therefor the HR database ) through a dodgy authentication routine on a web server with a SQL back end. About 8 or 9 machines to get there, but it blew my mind. The web server had port 80 open and port 443 echoing, but nothing running. He managed to forward TS through the 443 port ad get full GUI access to the lot!!!

It's made me very, very paranoid about network security in general.

For all those who work in IT, if you ever get the opportunity to see him in action, jump on it.

__________________
Quote:
Originally Posted by RaeRae1
Blessed are the cracked ones for they are the ones that let in the light.
Reply With Quote
  #2  
Old 09-03-2005, 12:52 PM
Neutrino's Avatar
Neutrino Neutrino is offline
Yaya Master
 
Join Date: Jan 2002
Posts: 7,152
Thanks: 0
Thanked 3 Times in 2 Posts
Send a message via AIM to Neutrino
Re: Penetration Testing

Quote:
Originally Posted by Oz
Hi all,
Just saw a penetration demonstration by Jesper Johannsen (Microsoft), where he penetrates a corporate domain controller (and therefor the HR database ) through a dodgy authentication routine on a web server with a SQL back end. About 8 or 9 machines to get there, but it blew my mind. The web server had port 80 open and port 443 echoing, but nothing running. He managed to forward TS through the 443 port ad get full GUI access to the lot!!!

It's made me very, very paranoid about network security in general.

For all those who work in IT, if you ever get the opportunity to see him in action, jump on it.


sounds like fun. Btw what server sofware was the domain controller using and what security measures were in place?
__________________

(\__/)
(='.'=) This is Bunny. Copy and paste bunny into your
(")_(") signature to help him gain world domination
Reply With Quote
  #3  
Old 09-12-2005, 08:30 PM
Oz's Avatar
Oz Oz is offline
Aussie Mod
Thread starter
 
Join Date: Dec 2001
Posts: 13,239
Thanks: 0
Thanked 2 Times in 2 Posts
Send a message via AIM to Oz
Re: Penetration Testing

Server 2003, firewall blocking inbound connections, 2 ports open. From there he used a range of different exploits, from password hashes and modifying HTML header packets to exploiting trust relationships on the internal LAN and sloppy password management.
__________________
Quote:
Originally Posted by RaeRae1
Blessed are the cracked ones for they are the ones that let in the light.
Reply With Quote
 
Reply

POST REPLY TO THIS THREAD

Go Back   Automotive Forums Car Chat > Coffee Break (Off-Topic) > COMPLETELY off-topic


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -5. The time now is 04:04 PM.

Community Participation Guidelines | How to use your User Control Panel

Powered by: vBulletin | Copyright Jelsoft Enterprises Ltd.
 
 
no new posts