WinInfo Daily News   |   Windows IT Pro
in
Microsoft Technet

IT Pro Tips


Why I Can Hack Your Network in a Day

By Mark Burnett

I watched a very interesting WebCast today called Why I Can Hack Your Network in a Day. The WebCast is from a TechEd 2007 presentation by Marcus Murry, a Swedish pen-tester. Marcus’ clever humor and knowledge of the hacking tools makes for an entertaining and informative session.

After a short intro, Marcus jumps right into doing actual demonstrations with commonly-used hacking tools. In his first demo he showed how easily he could build a Trojan using a tool called Beast. He attached the Trojan to Microsoft’s Rootkit Revealer tool and renamed it as “Tech Ed 2007 Rootkit Revealer Special Edition.”

TIP: Don't ever be fooled if you happen to find a 16GB USB flash drive just laying on the ground.  It could very easily have been planted by someone who loaded it with Trojans.  This is an extremely effective technique because whether the victim intends to keep it or not, chances are that they will at least plug it in to see who belongs to. 

 

After the Trojan runs, Marcus showed how he could remotely steal files, upload his hacking tools, or even view the remote desktop.

He also did a number of demos on how he could crack both WEP and WPA using widely available tools such as Aircrack-ng. My favorite quote from this demo was “If I were sniffing TechEd I would know everything there is to know about you guys. I’m not; but I would.”

What was interesting and quite effective was that instead of the traditional PowerPoint slides with endless bullet points, he used Microsoft OneNote with diagrams and scribbles for the non-demo parts of the presentation.

The presentation went on to demo a number of other attacks using a variety of tools, including wireless sniffing with AirPcap, a Terminal Services man-in-the-middle attack and ARP poisoning with Cain & Abel, and HTML injection using Paros.

The fact is that we hear so much about all these attacks that we almost become desensitized to the threats. Even for someone like me with a number of years in the security business, seeing usernames and passwords popping never loses its impact. Despite all our progress in security, the fact is that we still have a long way to go before we are actually as secure as we think we are.

It is a very entertaining WebCast, and I highly recommend it to anyone of any level. You can view Why I Can Hack Your Network in a Day on TechNet.

Published Mar 10 2008, 12:01 AM by itprotipsadmin
Filed under:

Comments

No Comments
SPONSORED LINKS FEATURED LINKS

Interested in Email Encryption? Read about the advantages of identity-based encryption in this free report. Order Your SQL Fundamentals CD Today! Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD. Virtualization Congress Oct. 14-16 in London Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16. IT ConnectionsDive into the new Microsoft platforms and products you implement and support with the experts from Microsoft, TechNet Magazine, Windows ITPro and industry gurus. There are 70+ sessions and interactive panels with networking opportunities. Attention User Group Leaders...Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes and add Windows IT Pro & SQL Server Mag articles alongside your own message!. Master SharePoint with 3 eLearning SeminarsLearn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today! Get SQL Server 2008 at WinConnectionsDon’t miss Microsoft Exchange and Windows Connections conferences, the premier events for Microsoft IT Professionals in Las Vegas, November 10-13. Every attendee will receive a copy of SQL Server 2008 Standard Edition with one CAL.
Windows IT Pro |  Subscribe |  Register |  Windows FAQ |  Media Kit |  WinInfo News |  Europe Edition |  About Us |  Contact Us/Customer Service |  Affiliates/Licensing
SQL Server Magazine |  Office & SharePoint Pro |  Windows Dev Pro |  IT Library |  Technical Resources Directory |  Windows Excavator |  ITTV |  IT Job Hound

Copyright © 2008 Penton Media, Inc., All rights reserved.  Terms and Use | Privacy Statement | Reprints and Licensing