© SANS Institute 2000 - 200
5
, Author retains full rights.
Key fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46
Key fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46
© SANS Institute 2000 - 200
5
Author retains full rights.
38
Diagrams & Screenshots:
Summary of lab testing:
Though these experiment were performed mostly on hubs using Ethereal,
I did perform some tests using dsniff on the switch and was able to grab similar
information. So it is certainly possible to perform this same attack on switched
networks.
It was a trivial effort to capture and parse and break the LANMAN hashes,
with enough modifying of the scripts and tying them together, it could possibly
be performed in seconds instead of minutes. This was effective in getting any
LANMAN hash from any version of any OS that used the MS-CHAP version 1 for
authentication.
Do'stlaringiz bilan baham: |