Home
[blog] Its not nmap but it gets the job done -- portqry
User Rating: / 1
Written by Chris Gates   
Sunday, 03 August 2008
Scanning once you are on the LAN can pose a problem. Nmap requires installing pcap and usually an interactive install (metacab is an option depending on scope) and some AV's will flag on those types of things (which is understandable). Since there is no native scanning capability in windows you are forced to either install something or upload a standalone binary. Foundstone's scanline is one option but its not one of my favorites. You can write your own and upload that but I'd hate to have some custom code submitted to some AV vendor by some motivated admin. Or you can upload Microsoft's portqry.

 C:\>portqry -n server1.company.com -e 3389
Querying target system called:
server1.company.com 
Attempting to resolve name to IP address...
Name resolved to 10.1.1.1
querying...
TCP port 3389 (unknown service): LISTENING


Checking out the KB article on portqry will give you some of its more useful features. Some fun options are its ability to send default ldap queries:

 portqry -n myserver -p udp -e 389

 
UDP port 389 (unknown service): LISTENING or FILTERED
Sending LDAP query to UDP port 389...

LDAP query response:

currentdate: 12/13/2003 05:42:40 (unadjusted GMT)
subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=domain,DC=example,DC=com dsServiceName: CN=NTDS Settings,CN=myserver,CN=Servers,CN=Default-First-Site-Name,CN=Sites,
CN=Configuration,DC=domain,DC=example,DC=com namingContexts: DC=domain,DC=example,DC=com
defaultNamingContext: DC=domain,DC=example,DC=com
schemaNamingContext: CN=Schema,CN=Configuration,DC=domain,DC=example,DC=com configurationNamingContext: CN=Configuration,DC=domain,DC=example,DC=com
rootDomainNamingContext: DC=domain,DC=example,DC=com
supportedControl: 1.2.840.113556.1.4.319
supportedLDAPVersion: 3
supportedLDAPPolicies: MaxPoolThreads
highestCommittedUSN: 4259431
supportedSASLMechanisms: GSSAPI
dnsHostName: myserver.domain.example.com
ldapServiceName: domain.example.com:myserver$@domain.EXAMPLE.COM
serverName: CN=myserver,CN=Servers,CN=Default-First-Site-Name,CN=Sites,
CN=Configuration,DC=domain,DC=example,DC=com
supportedCapabilities: 1.2.840.113556.1.4.800
isSynchronized: TRUE
isGlobalCatalogReady: TRUE
domainFunctionality: 0
forestFunctionality: 0
domainControllerFunctionality: 2

======== End of LDAP query response ========

UDP port 389 is LISTENING


and "sqlpings"

 portqry -n 192.168.1.20 -e 1434 -p udp

You receive the following output:


Querying target system called:

192.168.1.20

querying...

UDP port 1434 (ms-sql-m service): LISTENING or FILTERED

Sending SQL Server query to UDP port 1434...

Server's response:
ServerName SQL-Server1
InstanceName MSSQLSERVER
IsClustered No
Version 8.00.194
tcp 1433
np \\SQL-Server1\pipe\sql\query

==== End of SQL Server query response ====

UDP port 1434 is LISTENING

It also does snmp queries and ISA queries and evidently RPC end-point mapping as well.

There are other fun features and the localhost options are worth looking into as well.

Some of the not so fun stuff. No randomizing ports. You can do an ordered list or ranges but no random. ONLY ONE HOST AT A TIME :-( but that's what batch files are for.

If anyone else is using this for pentests please let me know your thoughts.

Additional information on metacab: http://www.phx2600.org/forum/viewtopic.php?t=951&start=0

--

Comments?  post up in the forum!

Show comments (0) - Add comments to this article:

Last Updated ( Sunday, 03 August 2008 )
[blog] DHCP Script Injection
User Rating: / 3
Written by Chris Gates   
Sunday, 03 August 2008
Very cool paper and demo over at MWR InfoSecurity on DHCP Script Injection.

The paper covers attacking the pfsense admin interface and injecting script into the DHCP hostname field. Because the admin interface runs as root your code is executed as root. The demo also uses a CRSF attack to change the password but I think its far more interesting to be able to inject script into the interface and run with all the exploitation options available there. They also released the tool to do it.

Full Paper
http://www.mwrinfosecurity.com/publications/mwri_behind-enemy-lines_2008-07-25.pdf

Paper on the DHCP Script Injection http://www.mwrinfosecurity.com/publications/mwri_pfsense-dhcp-script-injection_2008-07-28.pdf

Demo
http://www.mwrinfosecurity.com/publications/pfsense.htm

Comments?  Start a thread in the forum

Show comments (0) - Add comments to this article:

Last Updated ( Sunday, 03 August 2008 )
CrackMe 0x04
User Rating: / 3
Written by Chris Gates   
Friday, 18 July 2008
Objective:

Deliver Solution write up and License Key

Bonus:

What does the License Key mean?

Download CrackMe04.zip

md5sum: 990a8d0d120c9321294e18c2b77320ff  crackme04.exe

sha1sum: 9a9ad3b099116ab5e93dd9ae0843232bc0ff6cb4  crackme04.exe

Submissions are due to chris@[thissite].com by 23:59 EST 17 August 2008



Show comments (1) - Add comments to this article:

<< Start < Previous 1 2 3 4 5 6 Next > End >>

Results 1 - 6 of 36
Polls
What brought you to LSO?
  
Who's Online
We have 42 guests online
Latest Forum Posts
1: Re:User Awareness Programs by lepht
2: IT Security/Penetration Tester by nikkimorris
3: Re:Challenge1:Level4 by pobri19
4: Re:w3af and OpenVAS by fiuvertiz
5: Re:Unable to execute first cgi script in tutorial by j0e
6: Re:Windows CMD Line f00 by dobbelina
7: Re:Interested in membership upgrade by chris
8: Challenge is back by iggyzenoid
9: Re:Web Application Vulnerability Scanners (suck) by j0e
10: Re:How to set up a Hacking Lab by iggyzenoid
11: Using nmap and ndiff for asset management by chris
12: 2 kinds of security threats... by chris
13: Re:Is there a big demand for CPTS professionals? by j0e
14: Re:Firewall by fiuvertiz
15: Re:Is there such a tool? by fiuvertiz
16: HackLab by iggyzenoid
17: Re:TsCrack , TsGrinder and Rdestop Tools by ozanus
18: Re:Bawitdaba and SQL Injection by j0e
19: Re:Oysters by lepht
20: Re:TEMPEST by FireWraith

show last 4hrs - 24hrs