• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Need "hacking" tools for a class.

Gooberlx2

Lifer
Okay, so I know this sounds sketchy, but I need some hacking tools to try to "hack" into some guinea pig machines setup for our securities class.

I've got some info gathering tools already:
- Superscan port scanner
- Ethereal
- Sam Spade

Now I'm looking for stuff that would aid me to get root/admin access to these machines.

If you watched TechTV a week or something ago where the guy got access, changed the desktop icons and crashed the computer, I need to find the methods of doing that (without actually doing it since everyone else in the class needs to do so as well).

Any suggestions/links?
 
Any suggestions/links?

In the U.S. (under current law) actually responding to your thread (depending on what you really do with the info) may be aiding a felony. (I'm not saying I agree with the law, just pointing out why I won't actually answer the question).

Bill

 
Originally posted by: bsobel
Any suggestions/links?

In the U.S. (under current law) actually responding to your thread (depending on what you really do with the info) may be aiding a felony. (I'm not saying I agree with the law, just pointing out why I won't actually answer the question).

Bill


I don't think aiding someone to test the security of a system they have permission to test would be included.

I know my university offered a class exactly like this. There were 4 teams and each team would secure their computer. Each team would then try to hack into other teams machines. The team with the least hacks got an A. Grades went down from there.
 
Originally posted by: bsobel
Any suggestions/links?

In the U.S. (under current law) actually responding to your thread (depending on what you really do with the info) may be aiding a felony. (I'm not saying I agree with the law, just pointing out why I won't actually answer the question).

Bill

LOL 😀

Yes but he doesn't know you from Adam!
 
But posting here will give real wannabe hackers the information and tools in order to do it 🙂


Confused
 
Originally posted by: Codewiz
Originally posted by: bsobel
Any suggestions/links?

In the U.S. (under current law) actually responding to your thread (depending on what you really do with the info) may be aiding a felony. (I'm not saying I agree with the law, just pointing out why I won't actually answer the question).

Bill


I don't think aiding someone to test the security of a system they have permission to test would be included.

I know my university offered a class exactly like this. There were 4 teams and each team would secure their computer. Each team would then try to hack into other teams machines. The team with the least hacks got an A. Grades went down from there.


Very cool class.

 
Originally posted by: Confused
But posting here will give real wannabe hackers the information and tools in order to do it 🙂


Confused

True. People could always PM me if they felt so inclined. 🙂
 
I don't think aiding someone to test the security of a system they have permission to test would be included.

Your right, but you don't have any way of knowing that this is how the information will actually be used (no offense to Gooberfx2 who seems on the level here).
Bill
 
Originally posted by: bsobel
I don't think aiding someone to test the security of a system they have permission to test would be included.

Your right, but you don't have any way of knowing that this is how the information will actually be used (no offense to Gooberfx2 who seems on the level here).
Bill

Correct, but if we provide knowledge in good faith, no person is going to hold us accountable.

 
Note....

Enumerating accounts/shared off unsecured Windows boxen isn't really much of a hack. What that guy did on TechTV is about as lame as you can get.

There are countless tools available for enumeration, and that's what he did. One then simply needs to brute force any account found from the enumeration. Again, that's what he did.

I wrote my own tools to do this, and you're welcome to the code if you want it; however, I won't distribute the binary.

[edit]Update to remove specific references...[/edit]
 
Originally posted by: dejitaru
Everything's for a "class" these days. They don't supply you with tools?

No, not really. One of the points is for us to find out what we can on our own. Also, I want to go the extra yard.

Doesnt this violate the DMCA?

No. I have permission, I don't see why it would. Besides, I'm not stealing movies or mp3s so I don't see why the Digital Media Copyright Act would have any bearing (unless I just don't know enough about it, which is always possible 😛).
 
Originally posted by: Gooberlx2
Originally posted by: dejitaru
Everything's for a "class" these days. They don't supply you with tools?

No, not really. One of the points is for us to find out what we can on our own. Also, I want to go the extra yard.

Doesnt this violate the DMCA?

No. I have permission, I don't see why it would. Besides, I'm not stealing movies or mp3s so I don't see why the Digital Media Copyright Act would have any bearing (unless I just don't know enough about it, which is always possible 😛).

Actually DMCA stands for Digital Millennium Copyright Act. Not Media.....
 
Originally posted by: Codewiz
Originally posted by: Gooberlx2
Originally posted by: dejitaru
Everything's for a "class" these days. They don't supply you with tools?

No, not really. One of the points is for us to find out what we can on our own. Also, I want to go the extra yard.

Doesnt this violate the DMCA?

No. I have permission, I don't see why it would. Besides, I'm not stealing movies or mp3s so I don't see why the Digital Media Copyright Act would have any bearing (unless I just don't know enough about it, which is always possible 😛).

Actually DMCA stands for Digital Millennium Copyright Act. Not Media.....

Ooooohhhhhhhh!!! My bad. 😱
Anyway, I hardly think that the powers that be would care much about this. Anyway, further research has clued me in on some things. Good discussion though. 😉
 
Back
Top