_Hacking_
, 16 2006 . 19:29 ()
(WIN2000/XP)
NT- Win2000 WinXP. , NT4. , , , Microsoft ( ), . , , " ". - , , .
Win2k/XP, .. , WinNT . , , NT- . , , , . - .
NT
, , - . . , WinNT SAM (%__%system32configSAM). , , , . , . SAM - . . " ", NTFS (Trinux, PicoBSD, ..). , , - "Win9x ( ) + WinNT ( )". , SAM- Win9x , FAT32-. - WinNT FAT- . Win9x , NT . , - NT FAT' , 98- , WinNT. , NT (, , ..) NTFS, NT FAT- . - - Win9x.
- NT. , . , LophtCrack . , . , : , - , . . L0phtCrack ( ), " " (, ) . : , NT , , . , , , .
? , - ( SAM, , ). , - " " (bruteforce) . .
, WinNT . . - LM-hash, LanMan, - NT', NT-hash. LM- , . , (.., , , , ), , , , LM-hash. , (, , )? , .
, , - LM-hash' , . . . , Local Security Policy, Local Security Settings -> Security Options "Network Security: LAN Manager authentification level" (Send LM & NTLM responses) - Send NTLM response only ( NTLMv2, NT4/Win9x).
: , , . , , , ... :). - , .
WinNT , ( , , , , ). - ADMIN$ IPC$. , (IPC - InterProcess Communication). , , , , net.exe, Win2k/XP:
C:>net use 127.0.0.0 ipc$ ""/u:'' ( "" ).
, IPC$ - (null-session) - WinNT, NT, XP. , . , ? , . , , , - , . (regedit32.exe) HKLMSYSTEMCurrentControlSetControlLsa REG_DWORD restrictanonymous (, , ) 1 2. 1 (.. null-session , - , ). 2 . , (GetAcct, user2sid, ..), restrictanonymous, 1, 2 (, , ). " " (network neiborhood), - , ....
, " " (Server) Services REG_DWORD HKLMSYSTEMCurrentControlSetServicesLanmanServerParameters AutoShareWks 0. .
, . IPC$ .
, NetBIOS (, ). WinNT nbtstat.
? , , , . , .
, , , NetBIOS - ? , , . , " TCP/IP" -> "" " NetBIOS TCP/IP". " " " Microsoft". , , ( ). .
, C:>netstat -a. NetBIOS . , %__%system32driversetcservices, .
, NT (administrator) - , Microsoft . - , . ( nbtstat), , Administrator, , ! Local Security Policy -> Security Options, Rename administratior account .
, . WinNT, ...
-, . - . , Disabled, Manual. , . GUI' (Administrative Tools -> Services), , sc.exe. WinXP , Win2000 Win2k Resource Kit. sc.exe . , , , , , Services.
-, , , . , SP3 Win2000 , , , Microsoft TechNet Downloads, . MS - MS Baseline Security Analyser ( nshc.exe). , . , ( Win2k Resource Kit) MBSA, , . , . , . , X-Spider', ShadowSecurityScanner', Retina' Nessus' , . , .
-, , . NT (ACL - Access Control List), // . , . - , RunAs ( ).
. . , 90% "" , , , . , ?