الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

كيف يمكننى اقتناص باسسورد ال Sharing من ال Packtes الخاصة ب SMB Protocol

بدأه Ah.K.EL-Saman في 19 يوليو 2010 · 6 رد · 856 مشاهدة · في منتدى الشبكات العام
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

استخدم برنامج الـ Wireshark أستطيع ان أجد الـ packets ولكنى ﻻ أستطيع ان أعرف كيف اقرأ او أجد الباسوورد الخاص بالـ Sharing

أرجوا منكم الافادة

سَبِّحِ اسْمَ رَبِّكَ الْأَعْلَى

#2

معظم الشبكات الان تعتمد على kerberos او NTLM و الاتنين اما الباسورد لا ترسل او مشفرة

Mahmoud Magdy

MVP - Exchange Server. MCITP (Windows Server 2008, Exhcange Server 2010,/2007),CCNP, MCTS(OCS 2007 R2, SCCM 2007)

Tech Lead

Ingazat Information Technology

Follow me on twitter: http://www.twitter.com/_busbar

my blog: http://autodiscover.wordpress.com

Link with me on linkedin: http://www.linkedin.com/profile?viewProfile=&key=71027694

or on experts-exchange.com: http://www.experts-exchange.com/M_1426100.html

#3

هل استطعت ايجاد الـ Packet المناسبة ؟

اذكر أن في برنامج الـ Wireshark مكان تكتب فيه Key word فيقوم بإيصالك إلى الـ Packet التي تحتوي على هذه الكلمة المفتاحية

جرب كتابة SMB أو Password ككلمة مفتاحية قد يساعدك ذلك في الوصول إلى الـ Packet التي تحتوي على كلمة السر والله اعلم

تم تعديل هذه المشاركة بواسطة MoHaMMaD Pro في 20 يوليو 2010 في 14:11

Everything will be fine when we TALK LESS, DO MORE


#4
busbar كتب:

معظم الشبكات الان تعتمد على kerberos او NTLM و الاتنين اما الباسورد لا ترسل او مشفرة

بخصوص انها ترسل مشفرة مفيش مشكلة وارد اما بخصوص انها ﻻ ترسل طيب كيف رغم انه بيطلب Authentication وانا بفتح الـ Sharing وبدخل الـ Username والـ Password وأكيد بترسل عشان يتم التأكد منها على الجهاز اللى بيعمل Host للـ Sharing ؟؟؟ لو مخطىء وضح لى أكثر كيف ﻻ ترسل وكيف يتم الدخول بها

MoHaMMaD Pro كتب:

هل استطعت ايجاد الـ Packet المناسبة ؟

اذكر أن في برنامج الـ Wireshark مكان تكتب فيه Key word فيقوم بإيصالك إلى الـ Packet التي تحتوي على هذه الكلمة المفتاحية

جرب كتابة SMB أو Password ككلمة مفتاحية قد يساعدك ذلك في الوصول إلى الـ Packet التي تحتوي على كلمة السر والله اعلم

نعم يا أخى انا معى الـ Packet الخاصة بالـ Authentication لبروتوكول الـ SMB انا فعﻻ عملت هذه الخطوة من قبل ان اسأل

No.     Time        Source                Destination           Protocol Info
 164531 1003.103766 192.168.1.21          192.168.1.13          SMB      Session Setup AndX Request, NTLMSSP_AUTH, User: EPCI\Ahmed

Frame 164531 (322 bytes on wire, 322 bytes captured)
    Arrival Time: Jul 20, 2010 10:15:11.515572000
    [Time delta from previous captured frame: 0.000308000 seconds]
    [Time delta from previous displayed frame: 0.000308000 seconds]
    [Time since reference or first frame: 1003.103766000 seconds]
    Frame Number: 164531
    Frame Length: 322 bytes
    Capture Length: 322 bytes
    [Frame is marked: False]
    [Protocols in frame: eth:ip:tcp:nbss:smb:gss-api:spnego:ntlmssp]
    [Coloring Rule Name: SMB]
    [Coloring Rule String: smb || nbss || nbns || nbipx || ipxsap || netbios]
Ethernet II, Src: QuantaCo_91:f8:58 (00:26:9e:91:f8:58), Dst: Giga-Byt_20:03:13 (00:1f:d0:20:03:13)
    Destination: Giga-Byt_20:03:13 (00:1f:d0:20:03:13)
        Address: Giga-Byt_20:03:13 (00:1f:d0:20:03:13)
        .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
        .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
    Source: QuantaCo_91:f8:58 (00:26:9e:91:f8:58)
        Address: QuantaCo_91:f8:58 (00:26:9e:91:f8:58)
        .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
        .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
    Type: IP (0x0800)
Internet Protocol, Src: 192.168.1.21 (192.168.1.21), Dst: 192.168.1.13 (192.168.1.13)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
        0000 00.. = Differentiated Services Codepoint: Default (0x00)
        .... ..0. = ECN-Capable Transport (ECT): 0
        .... ...0 = ECN-CE: 0
    Total Length: 308
    Identification: 0x1387 (4999)
    Flags: 0x02 (Don't Fragment)
        0.. = Reserved bit: Not Set
        .1. = Don't fragment: Set
        ..0 = More fragments: Not Set
    Fragment offset: 0
    Time to live: 64
    Protocol: TCP (0x06)
    Header checksum: 0xa2ca [correct]
        [Good: True]
        [Bad : False]
    Source: 192.168.1.21 (192.168.1.21)
    Destination: 192.168.1.13 (192.168.1.13)
Transmission Control Protocol, Src Port: 55694 (55694), Dst Port: netbios-ssn (139), Seq: 429, Ack: 486, Len: 256
    Source port: 55694 (55694)
    Destination port: netbios-ssn (139)
    [Stream index: 4393]
    Sequence number: 429    (relative sequence number)
    [Next sequence number: 685    (relative sequence number)]
    Acknowledgement number: 486    (relative ack number)
    Header length: 32 bytes
    Flags: 0x18 (PSH, ACK)
        0... .... = Congestion Window Reduced (CWR): Not set
        .0.. .... = ECN-Echo: Not set
        ..0. .... = Urgent: Not set
        ...1 .... = Acknowledgement: Set
        .... 1... = Push: Set
        .... .0.. = Reset: Not set
        .... ..0. = Syn: Not set
        .... ...0 = Fin: Not set
    Window size: 6912 (scaled)
    Checksum: 0x8499 [validation disabled]
        [Good Checksum: False]
        [Bad Checksum: False]
    Options: (12 bytes)
        NOP
        NOP
        Timestamps: TSval 471654, TSecr 872167
    [SEQ/ACK analysis]
        [This is an ACK to the segment in frame: 164530]
        [The RTT to ACK the segment was: 0.000308000 seconds]
        [Number of bytes in flight: 256]
NetBIOS Session Service
    Message Type: Session message
    Flags: 0x00
        .... ...0 = Add 0 to length
    Length: 252
SMB (Server Message Block Protocol)
    SMB Header
        Server Component: SMB
        [Response in: 164532]
        SMB Command: Session Setup AndX (0x73)
        NT Status: STATUS_SUCCESS (0x00000000)
        Flags: 0x08
            0... .... = Request/Response: Message is a request to the server
            .0.. .... = Notify: Notify client only on open
            ..0. .... = Oplocks: OpLock not requested/granted
            ...0 .... = Canonicalized Pathnames: Pathnames are not canonicalized
            .... 1... = Case Sensitivity: Path names are caseless
            .... ..0. = Receive Buffer Posted: Receive buffer has not been posted
            .... ...0 = Lock and Read: Lock&Read, Write&Unlock are not supported
        Flags2: 0xc801
            1... .... .... .... = Unicode Strings: Strings are Unicode
            .1.. .... .... .... = Error Code Type: Error codes are NT error codes
            ..0. .... .... .... = Execute-only Reads: Don't permit reads if execute-only
            ...0 .... .... .... = Dfs: Don't resolve pathnames with Dfs
            .... 1... .... .... = Extended Security Negotiation: Extended security negotiation is supported
            .... .... .0.. .... = Long Names Used: Path names in request are not long file names
            .... .... .... .0.. = Security Signatures: Security signatures are not supported
            .... .... .... ..0. = Extended Attributes: Extended attributes are not supported
            .... .... .... ...1 = Long Names Allowed: Long file names are allowed in the response
        Process ID High: 0
        Signature: 0000000000000000
        Reserved: 0000
        Tree ID: 0
        Process ID: 2998
        User ID: 20483  (EPCI\Ahmed)
            [Primary Domain: EPCI]
            [Account: Ahmed]
            [Logged In: 164532]
        Multiplex ID: 4
    Session Setup AndX Request (0x73)
        Word Count (WCT): 12
        AndXCommand: No further commands (0xff)
        Reserved: 00
        AndXOffset: 0
        Max Buffer: 65535
        Max Mpx Count: 2
        VC Number: 1
        Session Key: 0x00000000
        Security Blob Length: 170
        Reserved: 00000000
        Capabilities: 0x8000d05c
            .... .... .... .... .... .... .... ...0 = Raw Mode: Read Raw and Write Raw are not supported
            .... .... .... .... .... .... .... ..0. = MPX Mode: Read Mpx and Write Mpx are not supported
            .... .... .... .... .... .... .... .1.. = Unicode: Unicode strings are supported
            .... .... .... .... .... .... .... 1... = Large Files: Large files are supported
            .... .... .... .... .... .... ...1 .... = NT SMBs: NT SMBs are supported
            .... .... .... .... .... .... ..0. .... = RPC Remote APIs: RPC remote APIs are not supported
            .... .... .... .... .... .... .1.. .... = NT Status Codes: NT status codes are supported
            .... .... .... .... .... .... 0... .... = Level 2 Oplocks: Level 2 oplocks are not supported
            .... .... .... .... .... ...0 .... .... = Lock and Read: Lock and Read is not supported
            .... .... .... .... .... ..0. .... .... = NT Find: NT Find is not supported
            .... .... .... .... ...1 .... .... .... = Dfs: Dfs is supported
            .... .... .... .... ..0. .... .... .... = Infolevel Passthru: NT information level request passthrough is not supported
            .... .... .... .... .1.. .... .... .... = Large ReadX: Large Read andX is supported
            .... .... .... .... 1... .... .... .... = Large WriteX: Large Write andX is supported
            .... .... 0... .... .... .... .... .... = UNIX: UNIX extensions are not supported
            .... ..0. .... .... .... .... .... .... = Reserved: Reserved
            ..0. .... .... .... .... .... .... .... = Bulk Transfer: Bulk Read and Bulk Write are not supported
            .0.. .... .... .... .... .... .... .... = Compressed Data: Compressed data transfer is not supported
            1... .... .... .... .... .... .... .... = Extended Security: Extended security exchanges are supported
        Byte Count (BCC): 193
        Security Blob: A181A73081A4A281A104819E4E544C4D5353500003000000...
            GSS-API Generic Security Service Application Program Interface
                SPNEGO
                    negTokenTarg
                        responseToken: 4E544C4D5353500003000000180018004000000018001800...
                        NTLMSSP
                            NTLMSSP identifier: NTLMSSP
                            NTLM Message Type: NTLMSSP_AUTH (0x00000003)
                            Lan Manager Response: 10BB4A9FAF9A2D2A00000000000000000000000000000000
                                Length: 24
                                Maxlen: 24
                                Offset: 64
                            NTLM Response: 06F23601E447C02BD3E668D0318C9954BF8283E517896076
                                Length: 24
                                Maxlen: 24
                                Offset: 88
                            Domain name: EPCI
                                Length: 8
                                Maxlen: 8
                                Offset: 112
                            User name: Ahmed
                                Length: 10
                                Maxlen: 10
                                Offset: 120
                            Host name: UBUNTU
                                Length: 12
                                Maxlen: 12
                                Offset: 130
                            Session Key: 9145E32909755946B84A8D8242B5CF5F
                                Length: 16
                                Maxlen: 16
                                Offset: 142
                            Flags: 0x60088215
                                0... .... .... .... .... .... .... .... = Negotiate 56: Not set
                                .1.. .... .... .... .... .... .... .... = Negotiate Key Exchange: Set
                                ..1. .... .... .... .... .... .... .... = Negotiate 128: Set
                                ...0 .... .... .... .... .... .... .... = Negotiate 0x10000000: Not set
                                .... 0... .... .... .... .... .... .... = Negotiate 0x08000000: Not set
                                .... .0.. .... .... .... .... .... .... = Negotiate 0x04000000: Not set
                                .... ..0. .... .... .... .... .... .... = Negotiate Version: Not set
                                .... ...0 .... .... .... .... .... .... = Negotiate 0x01000000: Not set
                                .... .... 0... .... .... .... .... .... = Negotiate Target Info: Not set
                                .... .... .0.. .... .... .... .... .... = Request Non-NT Session: Not set
                                .... .... ..0. .... .... .... .... .... = Negotiate 0x00200000: Not set
                                .... .... ...0 .... .... .... .... .... = Negotiate Identify: Not set
                                .... .... .... 1... .... .... .... .... = Negotiate NTLM2 key: Set
                                .... .... .... .0.. .... .... .... .... = Target Type Share: Not set
                                .... .... .... ..0. .... .... .... .... = Target Type Server: Not set
                                .... .... .... ...0 .... .... .... .... = Target Type Domain: Not set
                                .... .... .... .... 1... .... .... .... = Negotiate Always Sign: Set
                                .... .... .... .... .0.. .... .... .... = Negotiate 0x00004000: Not set
                                .... .... .... .... ..0. .... .... .... = Negotiate OEM Workstation Supplied: Not set
                                .... .... .... .... ...0 .... .... .... = Negotiate OEM Domain Supplied: Not set
                                .... .... .... .... .... 0... .... .... = Negotiate 0x00000800: Not set
                                .... .... .... .... .... .0.. .... .... = Negotiate NT Only: Not set
                                .... .... .... .... .... ..1. .... .... = Negotiate NTLM key: Set
                                .... .... .... .... .... ...0 .... .... = Negotiate 0x00000100: Not set
                                .... .... .... .... .... .... 0... .... = Negotiate Lan Manager Key: Not set
                                .... .... .... .... .... .... .0.. .... = Negotiate Datagram: Not set
                                .... .... .... .... .... .... ..0. .... = Negotiate Seal: Not set
                                .... .... .... .... .... .... ...1 .... = Negotiate Sign: Set
                                .... .... .... .... .... .... .... 0... = Request 0x00000008: Not set
                                .... .... .... .... .... .... .... .1.. = Request Target: Set
                                .... .... .... .... .... .... .... ..0. = Negotiate OEM: Not set
                                .... .... .... .... .... .... .... ...1 = Negotiate UNICODE: Set
        Native OS: Unix
        Native LAN Manager: Samba

سَبِّحِ اسْمَ رَبِّكَ الْأَعْلَى

#5

تماما رؤية الـ Packet أنعشت ذاكرتي :)

ما قاله الأخ busbar صحيح لم تعد كلمة المرور ترسل في الـ Packet

فبعد رؤيتي لهذه :

Lan Manager Response: 10BB4A9FAF9A2D2A00000000000000000000000000000000

تذكرت أن طريقة الـ Authentication اختلفت فأصبحت كلمة المرور لا ترسل بشكل Plain text كسابق عهدها

و إنما أصبحت الطريقة المعتمدة أن يقوم الـ Client بصنع شيفرة أو Hash key و يقوم بإرسالها مع اسم المستخدم و اسم المجال (Domain) إلى السيرفر

هذا الـ Hash key تم توليده عن طريق الباسورد التي تم ادخالها بشكل أساسي (وليس كلي) ولكن بعد العديد من العمليات الرياضية و الإضافات عليها والله أعلم

و بعد وصول الـ Packet (الذي يحوي على الـHash Key و باقي المعلومات) إلى السيرفر يقوم بفحص اسم المستخدم مع الموجود لديه في الـ database و يقوم بتوليد الـ Hash key ذاته ولكن من خلال الباسورد الخاصة بهذا المستخدم و الموجودة في الـ database فإن توافقت النتيجة التي لدى السيرفر مع التي لدى المستخدم يتم الدخول

هذه الطريقة في الـ Authentication تسمى بحسب ما أذكر Lan Manager Challenge/Response و تتم على عدة مراحل (أي تفاوض بين السيرفر و العميل NEGOTIATION)

أي يصعب كثيرا الوصول إلى كلمة المرور والله أعلم

على حد علمي ولكن لست متأكداً بعض البرامج تقوم بدراسة هذه الـ Hash حتى تصل إلى العمليات التي تمت عليها و تزيل الاضافات و تعيدها إلى الشكل الأصلي (كلمة المرور)

أرجو أن تكون قد اتضحت الفكرة و أن لا يكون فيها أي خطأ بحكم النسيان :)

بتوفيق الله ..

تم تعديل هذه المشاركة بواسطة MoHaMMaD Pro في 21 يوليو 2010 في 21:52

Everything will be fine when we TALK LESS, DO MORE


#6

and if kerberos is used then it is called tickets.

read more about TGTs

Mahmoud Magdy

MVP - Exchange Server. MCITP (Windows Server 2008, Exhcange Server 2010,/2007),CCNP, MCTS(OCS 2007 R2, SCCM 2007)

Tech Lead

Ingazat Information Technology

Follow me on twitter: http://www.twitter.com/_busbar

my blog: http://autodiscover.wordpress.com

Link with me on linkedin: http://www.linkedin.com/profile?viewProfile=&key=71027694

or on experts-exchange.com: http://www.experts-exchange.com/M_1426100.html

#7
MoHaMMaD Pro كتب:

تماما رؤية الـ Packet أنعشت ذاكرتي :)

ما قاله الأخ busbar صحيح لم تعد كلمة المرور ترسل في الـ Packet

فبعد رؤيتي لهذه :

Lan Manager Response: 10BB4A9FAF9A2D2A00000000000000000000000000000000

تذكرت أن طريقة الـ Authentication اختلفت فأصبحت كلمة المرور لا ترسل بشكل Plain text كسابق عهدها

و إنما أصبحت الطريقة المعتمدة أن يقوم الـ Client بصنع شيفرة أو Hash key و يقوم بإرسالها مع اسم المستخدم و اسم المجال (Domain) إلى السيرفر

هذا الـ Hash key تم توليده عن طريق الباسورد التي تم ادخالها بشكل أساسي (وليس كلي) ولكن بعد العديد من العمليات الرياضية و الإضافات عليها والله أعلم

و بعد وصول الـ Packet (الذي يحوي على الـHash Key و باقي المعلومات) إلى السيرفر يقوم بفحص اسم المستخدم مع الموجود لديه في الـ database و يقوم بتوليد الـ Hash key ذاته ولكن من خلال الباسورد الخاصة بهذا المستخدم و الموجودة في الـ database فإن توافقت النتيجة التي لدى السيرفر مع التي لدى المستخدم يتم الدخول

هذه الطريقة في الـ Authentication تسمى بحسب ما أذكر Lan Manager Challenge/Response و تتم على عدة مراحل (أي تفاوض بين السيرفر و العميل NEGOTIATION)

أي يصعب كثيرا الوصول إلى كلمة المرور والله أعلم

على حد علمي ولكن لست متأكداً بعض البرامج تقوم بدراسة هذه الـ Hash حتى تصل إلى العمليات التي تمت عليها و تزيل الاضافات و تعيدها إلى الشكل الأصلي (كلمة المرور)

أرجو أن تكون قد اتضحت الفكرة و أن لا يكون فيها أي خطأ بحكم النسيان :)

بتوفيق الله ..

افادك الله احب الناس اللى توضح من العمق ده :)

busbar كتب:

and if kerberos is used then it is called tickets.

read more about TGTs

انا فعﻻ اليومين دول بقرأ عن الـ Tickets الخاصة بـ Kerberos

شكراً جزيﻻ لكم ولتعاونكم

سَبِّحِ اسْمَ رَبِّكَ الْأَعْلَى

مواضيع مشابهة

عدد الزوار حالياً

المتواجدون خلال آخر دقيقتين · يتحدّث كل ٣٠ ثانية

—الإجمالي—أعضاء مسجّلون—زوار بدون تسجيل

جارٍ التحقق من المتواجدين…