Exploit-DB updates

Friday, September 9, 2011

Mounting a windows partition

This is a quite "how-to" on mounting a partition in GNU/Linux. First we need to identify which partition we want to mount. To do this we'll issue the fdisk command;

~ # fdisk -l

This lists the partitions, we're looking for a partition that has NTFS under the system column.

   Device Boot      Start         End      Blocks   Id  System
/dev/sda1   *           1         192     1536000   27  Unknown
/dev/sda2             192        7734    60579043+   7  HPFS/NTFS                  <----
/dev/sda3           29333       30402     8586240   17  Hidden HPFS/NTFS
/dev/sda4            7734       29333   173495297    5  Extended
/dev/sda5           28962       29333     2976768   82  Linux swap / Solaris
/dev/sda6           28591       28962     2972672   82  Linux swap / Solaris
/dev/sda7           18273       18496     1798144   82  Linux swap / Solaris
/dev/sda8            7734       18273    84653056   83  Linux


Now we want to create a directory in our /media/ directory which is where we'll mount the windows partition.

mkdir -p /media/Winblows

Now we're reading to mount it in the directory we just created.

mount -t ntfs -o nls=utf8,umask=0222 /dev/sda2 /media/Winblows

That should successfully mount your windows ntfs partition in the directory we created, hope this helps!

VNC Weak Password Bash Scanner

This is an old bash script I wrote some time ago, it uses the .jar that I coded a while back to parse nmap logs for IP's. You can find the bash script at the following pastebin and the jar used to parse the nmap logs below that.

Script - http://pastebin.com/swQGK6mi

Jar - http://hakhub.blogspot.com/2011/05/bash-scripting-friendly-java-ip-parser.html

Friday, August 26, 2011

Python and Shell Commands (Popen) example

Well I've recently moved back to python after learning PHP/MySQL for a while, so as I learned I coded a small program to issue remote commands. It essentially opens a given socket and waits for a connection, when a connection is established it prompts the user for validation. If validation is successful it passes a shell (limited to /bin tools) which you can use to issue remote commands. It also adds an iptables firewall rule to accept all packets on the port you specified which it then deletes when you exit the shell. All activity is logged to Logfile.log, including failed login attempts and their IP.

Things you can learn from this script: 

User Validation using the hashlib and a sha512'd password 
Command line arguments
Popen shell commands 
Reading/Writing Files
Basic sockets 

I wrote another small script to connect to the host, but in the end I decided to just use netcat instead. Example usage;

Host:
~$ python recon.py 1984

Client:

~$ nc -vv 19.84.20.11 1984

Script - http://pastebin.com/Mx600RA8

Getting started with iptables

Okay so I have probably talked about iptables before, and used it in previous tutorials, but now I've decided to talk about it in particular. iptables is extremely useful and powerful if configured properly. We'll start off with a very basic rule, allowing all traffic to and from telnet.

iptables -A INPUT -p tcp --destination-port 23 -j ACCEPT

Now we should be allowing all connections on port 23 (telnet).

We can view the rules we have like so;

iptables -L

If we had wanted to list the table with numeric values instead, use the (-n) flag. In addition, we can specify what rules we want to list (INPUT, OUTPUT, etc) and increase the verbosity to see the packet and byte statistics.

iptables -L INPUT -n -v

Now, that's nice and all but I'd like to filter out SSH on this laptop to drop any packets coming from IP's other than mine. In order to do this, I would issue the following command.

iptables -A INPUT -p tcp --dport 22 ! -s 19.84.20.11 -j DROP

Now any packets coming from a source ip other than the one I specified will be dropped for ssh. This applies to blacklisting IP's, which can easily be circumvented with proxies like TOR though. But if we had wanted to accept all packets except a specific IP, than we can issue the same command with (-j ACCEPT) rather than dropping it.


iptables -A INPUT -p tcp --dport 22 ! -s 19.84.20.11 -j ACCEPT

Now everyone but my home network can ssh into this box.

If we wanted to "flush" our chain, we can issue the following command;

iptables -F

That will have removed all the rules in the chain.
Another nice feature of iptables is the ability to redirect traffic to another port, so for example if we issued the following command than we would be redirecting the unwanted traffic from SSH to our honeypot's port.

iptables -t nat -A PREROUTING -p tcp --dport 22 ! -s 19.84.20.11 -j REDIRECT --to-port 1984

Now, nat rules are located in a separate are than you average rules. If we wanted to view these rules than we would need to explicitly specify that it's the nat rules we want to see or modify. For example, to view the rules and then flush them we would issue the following;

iptables -t nat -L -nv

iptables -t nat -F

That about wraps it up for my "how to" on getting started with iptables. Hope this helps someone else out there.