Diagrams & Screenshots:
Summary of lab testing:
Though these experiment were performed mostly on hubs using Ethereal,
I did perform some tests using dsniff on the switch and was able to grab similar
information. So it is certainly possible to perform this same attack on switched
networks.
It was a trivial effort to capture and parse and break the LANMAN hashes,
with enough modifying of the scripts and tying them together, it could possibly
be performed in seconds instead of minutes. This was effective in getting any
LANMAN hash from any version of any OS that used the MS-CHAP version 1 or
version 2 for authentication.
It was a little slower in cracking the MS-CHAP version 2 NT Encryption
based hashes, but not significantly.
Do'stlaringiz bilan baham: |