As earlier in one of my blogs, i have written about network security, i have written about using strong passwords and updating them frequently, here i will show why we need to do so.
For this you need to have cain&abel installed on your machine. You can get it from the link provided here.
Next install it on the machine.
Now run it..... you will get the window as shown here...
Start the sniffer by pressing onto it.........
It will start sniffing packets from the LAN.
Now it captures the request which a computer from LAN sends to the remote computer whom it is tryig to access. It sends its NTLM hash. So unless someone access the machine on which we have run the sniffer, we can't get its hash.
So there is a trick to get as much requests as possible by sharing a folder having "CACHY" name so that people try to click on it and try to open it, then the sniffer will capture its NTLM session hash.
To view the hashes captured, goto sniffer tab -> passwords and then click on SMB on the left hand side...
Now just right click on the HASH you want to crack and select "send to cracker".
Now goto the CRACKER tab and select LM & NTLM hash from the left side....
You will get all the hashes which you have sent for cracking..
Now right click on any hash which you want to crack, select brute force attack -> NTLM session security hashes
Now it will ask for the specifications about which kind of password it is..
Now here comes some common user error exploits....
1. Most of the users keep their passwords as simple words of english or numbers.
2. The password is of small length
3. Password comprises of either alphabets or simply numbers.
4. Only one kind of case-letters is used, either upper-case letters or lower-case letters.
5. Less than 8 characters. 4. Only one kind of case-letters is used, either upper-case letters or lower-case letters.
So predicting this first leads to saving a lot of time and makes cracking possible in a short span of time.
So in the dialog box which appears, choose the predefined characterset or have your own...
Minimize the password length so that it can be guessed soon if it is really small..
Then start the cracking..
This is how you can crack the passwords of the remote machines...
If you have some hash which has complex password and you are unable to break it, then you can submit it to the websites which accept hashes and they will give you the result of cracking after it is cracked..
This cracking is by Brute Force method about which i have explained in one of my ppt uploaded. You can watch it here...
http://pingmeup.blogspot.com/2010/05/cracking-using-rainbow-tables.html
So after watching this i hope you will try to keep strong network passwords..
I hope you would have enjoyed this blog...
If you do, then do share it with others..
THANKS....... :)
How much time it would take????
ReplyDeleteIt depends on the complexity of the password....
ReplyDeleteIf it is a number, then within few seconds, if it consists of upto 5 or 6 characters, then within minutes.... but if it consists of both alphabets and numbers or uppercase and lowercase characters... then it takes time. In that case, you can use Rainbow tables.... they are much faster than this...
ReplyI basically think we all don't have to face all this deceit and lies from our spouse…in a case of mine when i got sick and tired of all the lies and deceit i had to contact a friend of mine to get me the contact of one of the best hackers in the states ..then i met cryptocyberhacker@gmail.com .He saved me from the lies of my cheating boyfriend by hacking his phone.. In case you need help with hacking any phone or account, Hack into any hack websites, Hack into any company website, Hack into any database system and grant your admin privilege, Hack pay-pal account, Hack word press blogs Server crashed hack or other jobs.. Contact cryptocyberhacker@gmail.com.Tell him i referred you.
ReplyDeleteContact us(wizardcyprushacker@gmail.com )
ReplyDeleteif you need help with these:
?CLEAR CRIMINAL RECORDS
?DETECTABLE & UNDETECTABLE HACK ( PC,iPhone, Android or Organization computers)
?WEBSITES/SOCIAL MEDIA HACK (FB,Email, Skype,Tinder,Twitter,WhatsApp,Snapchat,Instagram,Telegram e.t.c)
?FLIP CASH AND COIN DOUBLING
?LOAD CREDIT CARDS
?BINARY OPTIONS SCAM RETRIEVALS
?BITCOINS (BTC) HACK
?PAYPAL ACCOUNT HACK (Verified acct only)
?INSTITUTION RESULT UPGRADE (College or High School)
?DATABASE HACK
?MONEY TRANSFER (specific to certain accounts)
?LOAN WITHOUT COLLATERALS
?WE INSTALL UNNOTICEABLE TRACK SOFTWARE ON TARGET'S DEVICE
?AND MANY OTHER CYBER RELATED ISSUES.
All these were carried out in the shortest time possible with significant experience on each aspect.
Contact:
Email: wizardcyprushacker@gmail.com