مرحبا جميعا
اخواني انا عندي مشروع دراسي اعمل عليه
واحناج الى افكار منكم
المشروع هو التالي:
اجراء عمليات scan لبعض انظمة النشغيل
واستخلاص الفجوات الموجودة في هذه الانظمة ومن ثم مهاجمة هذه الانظمة بالهجوم الملائم
اولا قمت بعمل scan التالي:
scans on Windows XP, server 2003, and Fedora 8.
I ran these scanners over network on virtual machines.
• SSS: Shadow Security Scanner.
• Sara: Security Auditors Research Assistant.
• GFI LANGUARD N.S.S 8.0. is a licensed version but without the report option. That is why I captured images of the scan results.
• eEye Retinna Network Security Scanner.
1. Windows XP
• SSS Tool Vulnerability Information
o It reported that there were 0 vulnerabilities in Windows XP
• Sara Tool Vulnerability information:
o Buffer overflow vulnerability: it allows remote attackers to excute arbitrary code via a crafted rpc message.
• GFI LANGUARD Tool Vulnerability Information:
• Retinna Vulnerability Information:
o Null session.
o No remote registry access available.
2. Windows server 2003
• SSS Tool Vulnerability Information
o It reported that there were no vulnerabilities in Windows Server 2003.
• Sara Tool Vulnerability information:
o Check Windows 2003 and confirm patched for MS06-040
o Microsoft RPC Services may be vulnerable to buffer overflow
o LSASS may be vulnerable to buffer overflow
o SMB: Null Sessions possible from arbitrary users
o SMB: One or more visible shares
o Check Windows 2003 and confirm patched for MS06-040
• GFI LANGUARD Tool Vulnerability Information:
• Retinna Vulnerability Information:
Rank Vulnerability Name Count
1. ASN.1 Vulnerability Could Allow Code Execution HTTP Check 1
2. ASN.1 Vulnerability Could Allow Code Execution 1
3. Windows Cumulative Patch 835732 Remote 1
4. Null Session 1
5. No Remote Registry Access Available 1
6. DCOM Enabled 1
7. Windows RPC Cumulative Patch 828741 Remote 1
8. Windows RPC DCOM interface buffer overflow 1
9. Windows RPC DCOM multiple vulnerabilities 1
10. WebDAV enabled 1
3. Fedora 8
• SSS Tool Vulnerability Information
o It reported that there were no vulnerabilities in Fedora 8
• Sara Tool Vulnerability information:
o user root with passwd '' can access service ssh
o user root with passwd 'pa$$w0rd' can access service ssh red ARC-005
o Null Sessions
SMB: Null Sessions possible from arbitrary users yellow CVE-2000-1200
SMB: User list can be dumped yellow CVE-2000-1200
o Samba server nmbd may be vulnerable yellow CVE-2007-5398
o visible SMB shares
SMB: One or more visible shares brown ARC-021
• GFI LANGUARD Tool Vulnerability Information:
• Retina Vulnerability Information
Rank Vulnerability Name Count
1. User Never Logged On 2
2. Apache-SSL Client Certificate Forging 2
3. HTTP TRACE method supported 2
4. Cached Logon Credentials 1
5. Max Password Age 1
6. Min Password Age 1
7. Min Password Length 1
8. Password History 1
9. TCP IP Security 1
10. Windows Cumulative Patch 835732 Remote 1
11. Allocate CDROMS 1
12. Auto Sharing Drive Problem - NT Server 1
13. Auto Sharing Drive Problem - NT Wks 1
14. Clear Page File 1
15. CrashonAuditFail 1
16. NTFS 8 Dot 3 1
17. Printer Driver Sec 1
18. Shutdown without Logon 1
فهل لي باحد يساعدني ببعض الطرق التي ممكن ان استحدمها لاقتحام هذه الانظمة؟
انا اعد بان اقدم الكتاب الذي سأنشأه هدية باسم هذا المنتدى وشكرا