Thursday, June 25, 2009

Penetration Test Tip: Add already guessed or cracked passwords to wordlist

When doing a penetration test, password attacks, while they lack the "sex appeal" of using the latest exploits in Metasploit to 0wn a b0x3r, are still disturbingly effective. Additionally, those same passwords are likely to be used on other machines, whether they be initial passwords for new/unused accounts or the same individual uses the same password on different systems.

Either way, once you guess a password (using enum.exe or the like) or crack a password from an encrypted hash (using John the Ripper or the like), add that password to the beginning of the master wordlist or dictionary list that you will use for the remainder of the penetration test, so that password is checked earlier rather than later.

Want to learn more? Check out:
SANS Security 560: Network Penetration Testing and Ethical Hacking

or

SANS Security 504: Hacker Techniques, Exploits and Incident Handling

-R

Labels: , , , , ,

Monday, March 30, 2009

IT Security Training: SANS Security 560 - Network Penetration Testing and Ethical Hacking, Denver, CO - starting Apr. 14, 2009

I am running a Mentor class of SANS Security 560 - Network Penetration Testing and Ethical Hacking here in Denver, starting April 14, 2009. To sign up, login to your portal account at http://portal.sans.org, then navigate to:

http://www.sans.org/mentor/details.php?nid=14819

for more details and to register. As a favor to me, if you do register, please enter MENTOR RECRUIT in the comments section. That way, SANS knows I marketed my own class :)

Hope to see you there!

-Rich

Labels: , , , , ,