استخدم برنامج الـ Wireshark أستطيع ان أجد الـ packets ولكنى ﻻ أستطيع ان أعرف كيف اقرأ او أجد الباسوورد الخاص بالـ Sharing
أرجوا منكم الافادة
استخدم برنامج الـ Wireshark أستطيع ان أجد الـ packets ولكنى ﻻ أستطيع ان أعرف كيف اقرأ او أجد الباسوورد الخاص بالـ Sharing
أرجوا منكم الافادة
سَبِّحِ اسْمَ رَبِّكَ الْأَعْلَى
معظم الشبكات الان تعتمد على kerberos او NTLM و الاتنين اما الباسورد لا ترسل او مشفرة
Mahmoud Magdy
MVP - Exchange Server. MCITP (Windows Server 2008, Exhcange Server 2010,/2007),CCNP, MCTS(OCS 2007 R2, SCCM 2007)
Tech Lead
Ingazat Information Technology
Follow me on twitter: http://www.twitter.com/_busbar
my blog: http://autodiscover.wordpress.com
Link with me on linkedin: http://www.linkedin.com/profile?viewProfile=&key=71027694
or on experts-exchange.com: http://www.experts-exchange.com/M_1426100.html
هل استطعت ايجاد الـ Packet المناسبة ؟
اذكر أن في برنامج الـ Wireshark مكان تكتب فيه Key word فيقوم بإيصالك إلى الـ Packet التي تحتوي على هذه الكلمة المفتاحية
جرب كتابة SMB أو Password ككلمة مفتاحية قد يساعدك ذلك في الوصول إلى الـ Packet التي تحتوي على كلمة السر والله اعلم
تم تعديل هذه المشاركة بواسطة MoHaMMaD Pro في 20 يوليو 2010 في 14:11
Everything will be fine when we TALK LESS, DO MORE
busbar كتب:معظم الشبكات الان تعتمد على kerberos او NTLM و الاتنين اما الباسورد لا ترسل او مشفرة
بخصوص انها ترسل مشفرة مفيش مشكلة وارد اما بخصوص انها ﻻ ترسل طيب كيف رغم انه بيطلب Authentication وانا بفتح الـ Sharing وبدخل الـ Username والـ Password وأكيد بترسل عشان يتم التأكد منها على الجهاز اللى بيعمل Host للـ Sharing ؟؟؟ لو مخطىء وضح لى أكثر كيف ﻻ ترسل وكيف يتم الدخول بها
MoHaMMaD Pro كتب:هل استطعت ايجاد الـ Packet المناسبة ؟
اذكر أن في برنامج الـ Wireshark مكان تكتب فيه Key word فيقوم بإيصالك إلى الـ Packet التي تحتوي على هذه الكلمة المفتاحية
جرب كتابة SMB أو Password ككلمة مفتاحية قد يساعدك ذلك في الوصول إلى الـ Packet التي تحتوي على كلمة السر والله اعلم
نعم يا أخى انا معى الـ Packet الخاصة بالـ Authentication لبروتوكول الـ SMB انا فعﻻ عملت هذه الخطوة من قبل ان اسأل
No. Time Source Destination Protocol Info
164531 1003.103766 192.168.1.21 192.168.1.13 SMB Session Setup AndX Request, NTLMSSP_AUTH, User: EPCI\Ahmed
Frame 164531 (322 bytes on wire, 322 bytes captured)
Arrival Time: Jul 20, 2010 10:15:11.515572000
[Time delta from previous captured frame: 0.000308000 seconds]
[Time delta from previous displayed frame: 0.000308000 seconds]
[Time since reference or first frame: 1003.103766000 seconds]
Frame Number: 164531
Frame Length: 322 bytes
Capture Length: 322 bytes
[Frame is marked: False]
[Protocols in frame: eth:ip:tcp:nbss:smb:gss-api:spnego:ntlmssp]
[Coloring Rule Name: SMB]
[Coloring Rule String: smb || nbss || nbns || nbipx || ipxsap || netbios]
Ethernet II, Src: QuantaCo_91:f8:58 (00:26:9e:91:f8:58), Dst: Giga-Byt_20:03:13 (00:1f:d0:20:03:13)
Destination: Giga-Byt_20:03:13 (00:1f:d0:20:03:13)
Address: Giga-Byt_20:03:13 (00:1f:d0:20:03:13)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
Source: QuantaCo_91:f8:58 (00:26:9e:91:f8:58)
Address: QuantaCo_91:f8:58 (00:26:9e:91:f8:58)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
Type: IP (0x0800)
Internet Protocol, Src: 192.168.1.21 (192.168.1.21), Dst: 192.168.1.13 (192.168.1.13)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 308
Identification: 0x1387 (4999)
Flags: 0x02 (Don't Fragment)
0.. = Reserved bit: Not Set
.1. = Don't fragment: Set
..0 = More fragments: Not Set
Fragment offset: 0
Time to live: 64
Protocol: TCP (0x06)
Header checksum: 0xa2ca [correct]
[Good: True]
[Bad : False]
Source: 192.168.1.21 (192.168.1.21)
Destination: 192.168.1.13 (192.168.1.13)
Transmission Control Protocol, Src Port: 55694 (55694), Dst Port: netbios-ssn (139), Seq: 429, Ack: 486, Len: 256
Source port: 55694 (55694)
Destination port: netbios-ssn (139)
[Stream index: 4393]
Sequence number: 429 (relative sequence number)
[Next sequence number: 685 (relative sequence number)]
Acknowledgement number: 486 (relative ack number)
Header length: 32 bytes
Flags: 0x18 (PSH, ACK)
0... .... = Congestion Window Reduced (CWR): Not set
.0.. .... = ECN-Echo: Not set
..0. .... = Urgent: Not set
...1 .... = Acknowledgement: Set
.... 1... = Push: Set
.... .0.. = Reset: Not set
.... ..0. = Syn: Not set
.... ...0 = Fin: Not set
Window size: 6912 (scaled)
Checksum: 0x8499 [validation disabled]
[Good Checksum: False]
[Bad Checksum: False]
Options: (12 bytes)
NOP
NOP
Timestamps: TSval 471654, TSecr 872167
[SEQ/ACK analysis]
[This is an ACK to the segment in frame: 164530]
[The RTT to ACK the segment was: 0.000308000 seconds]
[Number of bytes in flight: 256]
NetBIOS Session Service
Message Type: Session message
Flags: 0x00
.... ...0 = Add 0 to length
Length: 252
SMB (Server Message Block Protocol)
SMB Header
Server Component: SMB
[Response in: 164532]
SMB Command: Session Setup AndX (0x73)
NT Status: STATUS_SUCCESS (0x00000000)
Flags: 0x08
0... .... = Request/Response: Message is a request to the server
.0.. .... = Notify: Notify client only on open
..0. .... = Oplocks: OpLock not requested/granted
...0 .... = Canonicalized Pathnames: Pathnames are not canonicalized
.... 1... = Case Sensitivity: Path names are caseless
.... ..0. = Receive Buffer Posted: Receive buffer has not been posted
.... ...0 = Lock and Read: Lock&Read, Write&Unlock are not supported
Flags2: 0xc801
1... .... .... .... = Unicode Strings: Strings are Unicode
.1.. .... .... .... = Error Code Type: Error codes are NT error codes
..0. .... .... .... = Execute-only Reads: Don't permit reads if execute-only
...0 .... .... .... = Dfs: Don't resolve pathnames with Dfs
.... 1... .... .... = Extended Security Negotiation: Extended security negotiation is supported
.... .... .0.. .... = Long Names Used: Path names in request are not long file names
.... .... .... .0.. = Security Signatures: Security signatures are not supported
.... .... .... ..0. = Extended Attributes: Extended attributes are not supported
.... .... .... ...1 = Long Names Allowed: Long file names are allowed in the response
Process ID High: 0
Signature: 0000000000000000
Reserved: 0000
Tree ID: 0
Process ID: 2998
User ID: 20483 (EPCI\Ahmed)
[Primary Domain: EPCI]
[Account: Ahmed]
[Logged In: 164532]
Multiplex ID: 4
Session Setup AndX Request (0x73)
Word Count (WCT): 12
AndXCommand: No further commands (0xff)
Reserved: 00
AndXOffset: 0
Max Buffer: 65535
Max Mpx Count: 2
VC Number: 1
Session Key: 0x00000000
Security Blob Length: 170
Reserved: 00000000
Capabilities: 0x8000d05c
.... .... .... .... .... .... .... ...0 = Raw Mode: Read Raw and Write Raw are not supported
.... .... .... .... .... .... .... ..0. = MPX Mode: Read Mpx and Write Mpx are not supported
.... .... .... .... .... .... .... .1.. = Unicode: Unicode strings are supported
.... .... .... .... .... .... .... 1... = Large Files: Large files are supported
.... .... .... .... .... .... ...1 .... = NT SMBs: NT SMBs are supported
.... .... .... .... .... .... ..0. .... = RPC Remote APIs: RPC remote APIs are not supported
.... .... .... .... .... .... .1.. .... = NT Status Codes: NT status codes are supported
.... .... .... .... .... .... 0... .... = Level 2 Oplocks: Level 2 oplocks are not supported
.... .... .... .... .... ...0 .... .... = Lock and Read: Lock and Read is not supported
.... .... .... .... .... ..0. .... .... = NT Find: NT Find is not supported
.... .... .... .... ...1 .... .... .... = Dfs: Dfs is supported
.... .... .... .... ..0. .... .... .... = Infolevel Passthru: NT information level request passthrough is not supported
.... .... .... .... .1.. .... .... .... = Large ReadX: Large Read andX is supported
.... .... .... .... 1... .... .... .... = Large WriteX: Large Write andX is supported
.... .... 0... .... .... .... .... .... = UNIX: UNIX extensions are not supported
.... ..0. .... .... .... .... .... .... = Reserved: Reserved
..0. .... .... .... .... .... .... .... = Bulk Transfer: Bulk Read and Bulk Write are not supported
.0.. .... .... .... .... .... .... .... = Compressed Data: Compressed data transfer is not supported
1... .... .... .... .... .... .... .... = Extended Security: Extended security exchanges are supported
Byte Count (BCC): 193
Security Blob: A181A73081A4A281A104819E4E544C4D5353500003000000...
GSS-API Generic Security Service Application Program Interface
SPNEGO
negTokenTarg
responseToken: 4E544C4D5353500003000000180018004000000018001800...
NTLMSSP
NTLMSSP identifier: NTLMSSP
NTLM Message Type: NTLMSSP_AUTH (0x00000003)
Lan Manager Response: 10BB4A9FAF9A2D2A00000000000000000000000000000000
Length: 24
Maxlen: 24
Offset: 64
NTLM Response: 06F23601E447C02BD3E668D0318C9954BF8283E517896076
Length: 24
Maxlen: 24
Offset: 88
Domain name: EPCI
Length: 8
Maxlen: 8
Offset: 112
User name: Ahmed
Length: 10
Maxlen: 10
Offset: 120
Host name: UBUNTU
Length: 12
Maxlen: 12
Offset: 130
Session Key: 9145E32909755946B84A8D8242B5CF5F
Length: 16
Maxlen: 16
Offset: 142
Flags: 0x60088215
0... .... .... .... .... .... .... .... = Negotiate 56: Not set
.1.. .... .... .... .... .... .... .... = Negotiate Key Exchange: Set
..1. .... .... .... .... .... .... .... = Negotiate 128: Set
...0 .... .... .... .... .... .... .... = Negotiate 0x10000000: Not set
.... 0... .... .... .... .... .... .... = Negotiate 0x08000000: Not set
.... .0.. .... .... .... .... .... .... = Negotiate 0x04000000: Not set
.... ..0. .... .... .... .... .... .... = Negotiate Version: Not set
.... ...0 .... .... .... .... .... .... = Negotiate 0x01000000: Not set
.... .... 0... .... .... .... .... .... = Negotiate Target Info: Not set
.... .... .0.. .... .... .... .... .... = Request Non-NT Session: Not set
.... .... ..0. .... .... .... .... .... = Negotiate 0x00200000: Not set
.... .... ...0 .... .... .... .... .... = Negotiate Identify: Not set
.... .... .... 1... .... .... .... .... = Negotiate NTLM2 key: Set
.... .... .... .0.. .... .... .... .... = Target Type Share: Not set
.... .... .... ..0. .... .... .... .... = Target Type Server: Not set
.... .... .... ...0 .... .... .... .... = Target Type Domain: Not set
.... .... .... .... 1... .... .... .... = Negotiate Always Sign: Set
.... .... .... .... .0.. .... .... .... = Negotiate 0x00004000: Not set
.... .... .... .... ..0. .... .... .... = Negotiate OEM Workstation Supplied: Not set
.... .... .... .... ...0 .... .... .... = Negotiate OEM Domain Supplied: Not set
.... .... .... .... .... 0... .... .... = Negotiate 0x00000800: Not set
.... .... .... .... .... .0.. .... .... = Negotiate NT Only: Not set
.... .... .... .... .... ..1. .... .... = Negotiate NTLM key: Set
.... .... .... .... .... ...0 .... .... = Negotiate 0x00000100: Not set
.... .... .... .... .... .... 0... .... = Negotiate Lan Manager Key: Not set
.... .... .... .... .... .... .0.. .... = Negotiate Datagram: Not set
.... .... .... .... .... .... ..0. .... = Negotiate Seal: Not set
.... .... .... .... .... .... ...1 .... = Negotiate Sign: Set
.... .... .... .... .... .... .... 0... = Request 0x00000008: Not set
.... .... .... .... .... .... .... .1.. = Request Target: Set
.... .... .... .... .... .... .... ..0. = Negotiate OEM: Not set
.... .... .... .... .... .... .... ...1 = Negotiate UNICODE: Set
Native OS: Unix
Native LAN Manager: Sambaسَبِّحِ اسْمَ رَبِّكَ الْأَعْلَى
تماما رؤية الـ Packet أنعشت ذاكرتي :)
ما قاله الأخ busbar صحيح لم تعد كلمة المرور ترسل في الـ Packet
فبعد رؤيتي لهذه :
Lan Manager Response: 10BB4A9FAF9A2D2A00000000000000000000000000000000
تذكرت أن طريقة الـ Authentication اختلفت فأصبحت كلمة المرور لا ترسل بشكل Plain text كسابق عهدها
و إنما أصبحت الطريقة المعتمدة أن يقوم الـ Client بصنع شيفرة أو Hash key و يقوم بإرسالها مع اسم المستخدم و اسم المجال (Domain) إلى السيرفر
هذا الـ Hash key تم توليده عن طريق الباسورد التي تم ادخالها بشكل أساسي (وليس كلي) ولكن بعد العديد من العمليات الرياضية و الإضافات عليها والله أعلم
و بعد وصول الـ Packet (الذي يحوي على الـHash Key و باقي المعلومات) إلى السيرفر يقوم بفحص اسم المستخدم مع الموجود لديه في الـ database و يقوم بتوليد الـ Hash key ذاته ولكن من خلال الباسورد الخاصة بهذا المستخدم و الموجودة في الـ database فإن توافقت النتيجة التي لدى السيرفر مع التي لدى المستخدم يتم الدخول
هذه الطريقة في الـ Authentication تسمى بحسب ما أذكر Lan Manager Challenge/Response و تتم على عدة مراحل (أي تفاوض بين السيرفر و العميل NEGOTIATION)
أي يصعب كثيرا الوصول إلى كلمة المرور والله أعلم
على حد علمي ولكن لست متأكداً بعض البرامج تقوم بدراسة هذه الـ Hash حتى تصل إلى العمليات التي تمت عليها و تزيل الاضافات و تعيدها إلى الشكل الأصلي (كلمة المرور)
أرجو أن تكون قد اتضحت الفكرة و أن لا يكون فيها أي خطأ بحكم النسيان :)
بتوفيق الله ..
تم تعديل هذه المشاركة بواسطة MoHaMMaD Pro في 21 يوليو 2010 في 21:52
Everything will be fine when we TALK LESS, DO MORE
and if kerberos is used then it is called tickets.
read more about TGTs
Mahmoud Magdy
MVP - Exchange Server. MCITP (Windows Server 2008, Exhcange Server 2010,/2007),CCNP, MCTS(OCS 2007 R2, SCCM 2007)
Tech Lead
Ingazat Information Technology
Follow me on twitter: http://www.twitter.com/_busbar
my blog: http://autodiscover.wordpress.com
Link with me on linkedin: http://www.linkedin.com/profile?viewProfile=&key=71027694
or on experts-exchange.com: http://www.experts-exchange.com/M_1426100.html
MoHaMMaD Pro كتب:تماما رؤية الـ Packet أنعشت ذاكرتي :)
ما قاله الأخ busbar صحيح لم تعد كلمة المرور ترسل في الـ Packet
فبعد رؤيتي لهذه :
Lan Manager Response: 10BB4A9FAF9A2D2A00000000000000000000000000000000تذكرت أن طريقة الـ Authentication اختلفت فأصبحت كلمة المرور لا ترسل بشكل Plain text كسابق عهدها
و إنما أصبحت الطريقة المعتمدة أن يقوم الـ Client بصنع شيفرة أو Hash key و يقوم بإرسالها مع اسم المستخدم و اسم المجال (Domain) إلى السيرفر
هذا الـ Hash key تم توليده عن طريق الباسورد التي تم ادخالها بشكل أساسي (وليس كلي) ولكن بعد العديد من العمليات الرياضية و الإضافات عليها والله أعلم
و بعد وصول الـ Packet (الذي يحوي على الـHash Key و باقي المعلومات) إلى السيرفر يقوم بفحص اسم المستخدم مع الموجود لديه في الـ database و يقوم بتوليد الـ Hash key ذاته ولكن من خلال الباسورد الخاصة بهذا المستخدم و الموجودة في الـ database فإن توافقت النتيجة التي لدى السيرفر مع التي لدى المستخدم يتم الدخول
هذه الطريقة في الـ Authentication تسمى بحسب ما أذكر Lan Manager Challenge/Response و تتم على عدة مراحل (أي تفاوض بين السيرفر و العميل NEGOTIATION)
أي يصعب كثيرا الوصول إلى كلمة المرور والله أعلم
على حد علمي ولكن لست متأكداً بعض البرامج تقوم بدراسة هذه الـ Hash حتى تصل إلى العمليات التي تمت عليها و تزيل الاضافات و تعيدها إلى الشكل الأصلي (كلمة المرور)
أرجو أن تكون قد اتضحت الفكرة و أن لا يكون فيها أي خطأ بحكم النسيان :)
بتوفيق الله ..
افادك الله احب الناس اللى توضح من العمق ده :)
busbar كتب:and if kerberos is used then it is called tickets.
read more about TGTs
انا فعﻻ اليومين دول بقرأ عن الـ Tickets الخاصة بـ Kerberos
شكراً جزيﻻ لكم ولتعاونكم
سَبِّحِ اسْمَ رَبِّكَ الْأَعْلَى
المتواجدون خلال آخر دقيقتين · يتحدّث كل ٣٠ ثانية
جارٍ التحقق من المتواجدين…