how to access admin$ shares

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • spiker
    Member
    • Oct 2004
    • 12

    #31
    Originally posted by TheCotMan
    Google is your friend: "what is an smb null session" or Google is your friend: "connect with a" "null sessions" smb

    If these do not work, you can refine the search until it does.

    Question: How can you be "MCSE" if you do not understand what a null session is and how it works?
    [two months left :-]

    Microsoft certifications do not teach to exploit their own vulnerabilities. Null sessions and all may be explained in theory, but practically after trying them if one faces difficulties, then one goes to forums to express the same, which is the purpose of forums anyway, to share knowledge and answer technical queries. You know I've just been trying these forums, but I think the people who claim themselves as security experts, in other words, who are so called ethical hackers, are in a different world of their own. They consider themselves superior technically and look down upon newbies. There is a lot of contradictions.

    Comment

    • Chris
      Great Satan of the East
      • Oct 2001
      • 2866

      #32
      Originally posted by spiker
      Microsoft certifications do not teach to exploit their own vulnerabilities. Null sessions and all may be explained in theory, but practically after trying them if one faces difficulties, then one goes to forums to express the same, which is the purpose of forums anyway, to share knowledge and answer technical queries. You know I've just been trying these forums, but I think the people who claim themselves as security experts, in other words, who are so called ethical hackers, are in a different world of their own. They consider themselves superior technically and look down upon newbies. There is a lot of contradictions.

      It isn't a matter of looking down on newbies. It is, however, a matter of looking down on folks that appear unwilling to do the most redimentary research to find their own answer rather than asking to be spoonfed.

      Also, there is no such thing as an ethical hacker. Hacking isn't unethical so there cannot be an unethical version of it.
      perl -e 'print pack(c5, (41*2), sqrt(7056), (unpack(c,H)-2), oct(115), 10)'

      Comment

      • snyderkv
        Banned
        • Aug 2005
        • 8

        #33
        Null Sessions

        I think this is the information your looking for: NULL Connection to a share using port 139

        Net Use \\servername\ipc$ "" /user:"" exactly how you see it. This works in most internal LAN enviornments. This is how you connect to shares. From here you can Enumerate that servers objects including names, groups and policies.

        If you cannot get to this then try this and see what you can do. You have to be a local admin but not a Domain Admin since they have rights already.

        AT 12:33:00 /interactive cmd ...... to set up a job. Set the time for one minute in the future. Press AT and enter to see the job. Make sure the time is right and set for today not tomorrow.

        Once it's set you can share out the Admin shares I think using the "Net Use" command to share out the shares. This interactive command will allow you to run as "local System" You can use the net add to add groups ot the local account as well to gain access to that machine. net add localgroup adminstrator "domain\group" /ADD or something like that.

        I never tried these as a user since I'm an Enterprise Admin but they do help in daily administration tasks sometimes. Hacking in general is usefull to know if your doing migrations or whatever ex (permissions issues). They should not even call this shit hacking because its not hacking at all. Think of a car as an analogy. You lock your key's inside. Do you brake the window of your 200,000 Diablo ? No you simply stick a slim jim inside the wondow and wallah. The designers designed it that way so you can get inside with minimal effort. Computers are somewhat the same in some aspects. Null sessions exist so older clients can communicate. Read up on it some. Lots of info for what your trying to do.

        I agree with poster. MCSE does not teach anything about this stuff. Not even in Security +. Since I am MCSE + Security and having went through all the software I can say this from experience. Also, this info is free. He can look this stuff up. So dont think your giving out your hard earned secret malicious information. It's like the teller at the 99c store selling a little kid a slim jim. Big Deal
        Last edited by snyderkv; August 14, 2005, 11:00.

        Comment

        • Clp727
          Member
          • Feb 2003
          • 149

          #34
          Spiker,
          If you are an MCSE then you should already atleast know what NAT is, and how to access the admin shares. I doubt your honesty.

          Comment

          • mikedc1760
            Member
            • Apr 2004
            • 67

            #35
            You do realize this topic is almost a year old right? I don't think you do....

            Comment

            • noid
              Fun Enforcement Agent
              • Oct 2001
              • 2394

              #36
              No, he doesnt. Reading comprehension is something he's lacking. He did this in another thread already. Strike two.

              I return whatever i wish . Its called FREEDOWM OF RANDOMNESS IN A HECK . CLUSTERED DEFEATED CORn FORUM . Welcome to me

              Comment

              • snyderkv
                Banned
                • Aug 2005
                • 8

                #37
                Whats wrong with replying to an old thread? And what did I do in another thread? Bring it back alive? Why start another thread when I can reply to the search?

                Strike Nothing.

                Comment

                • noid
                  Fun Enforcement Agent
                  • Oct 2001
                  • 2394

                  #38
                  I was going to let it slide till your 'strike nothing' remark. You bring nothing to the table. Please go bother another forum.

                  I return whatever i wish . Its called FREEDOWM OF RANDOMNESS IN A HECK . CLUSTERED DEFEATED CORn FORUM . Welcome to me

                  Comment

                  • von
                    Banned
                    • Aug 2005
                    • 2

                    #39
                    Hm

                    Bad Mod,

                    Actually you are the one provoking snyder by calling him fucking idiot, fucking moron and fucking schmuck. You are the one who brings nothing.

                    If somebody should be band it should be you IMO.

                    Thanks

                    Comment

                    • noid
                      Fun Enforcement Agent
                      • Oct 2001
                      • 2394

                      #40
                      Why are you talking about yourself in the 3rd person?

                      You so sneaky.

                      synderkv
                      synderkv@yahoo.com
                      143.81.21.2

                      von
                      synderkv@yahoo.com
                      143.81.21.2

                      I return whatever i wish . Its called FREEDOWM OF RANDOMNESS IN A HECK . CLUSTERED DEFEATED CORn FORUM . Welcome to me

                      Comment

                      • astcell
                        Human Rights Issuer
                        • Oct 2001
                        • 7512

                        #41
                        The IP Address is: 143.81.21.2. The host name is: cacheout.kuwait.army.mil.


                        Another idiot. I hope you are better at shooting a rifle than shooting your mouth off.

                        Comment

                        Working...