WinInfo Daily News   |   Windows IT Pro
in
Microsoft Technet

IT Pro Tips


Why I Can Hack Your Network in a Day

By Mark Burnett

I watched a very interesting WebCast today called Why I Can Hack Your Network in a Day. The WebCast is from a TechEd 2007 presentation by Marcus Murry, a Swedish pen-tester. Marcus’ clever humor and knowledge of the hacking tools makes for an entertaining and informative session.

After a short intro, Marcus jumps right into doing actual demonstrations with commonly-used hacking tools. In his first demo he showed how easily he could build a Trojan using a tool called Beast. He attached the Trojan to Microsoft’s Rootkit Revealer tool and renamed it as “Tech Ed 2007 Rootkit Revealer Special Edition.”

TIP: Don't ever be fooled if you happen to find a 16GB USB flash drive just laying on the ground.  It could very easily have been planted by someone who loaded it with Trojans.  This is an extremely effective technique because whether the victim intends to keep it or not, chances are that they will at least plug it in to see who belongs to. 

 

After the Trojan runs, Marcus showed how he could remotely steal files, upload his hacking tools, or even view the remote desktop.

He also did a number of demos on how he could crack both WEP and WPA using widely available tools such as Aircrack-ng. My favorite quote from this demo was “If I were sniffing TechEd I would know everything there is to know about you guys. I’m not; but I would.”

What was interesting and quite effective was that instead of the traditional PowerPoint slides with endless bullet points, he used Microsoft OneNote with diagrams and scribbles for the non-demo parts of the presentation.

The presentation went on to demo a number of other attacks using a variety of tools, including wireless sniffing with AirPcap, a Terminal Services man-in-the-middle attack and ARP poisoning with Cain & Abel, and HTML injection using Paros.

The fact is that we hear so much about all these attacks that we almost become desensitized to the threats. Even for someone like me with a number of years in the security business, seeing usernames and passwords popping never loses its impact. Despite all our progress in security, the fact is that we still have a long way to go before we are actually as secure as we think we are.

It is a very entertaining WebCast, and I highly recommend it to anyone of any level. You can view Why I Can Hack Your Network in a Day on TechNet.

Published Mar 10 2008, 12:01 AM by itprotipsadmin
Filed under:

Comments

No Comments
Acceptable Use Policy

SPONSORED LINKS FEATURED LINKS

Get Microsoft Microsoft Certified With Train Signal Computer TrainingTrain Signal’s computer training software videos will teach you the skills you need to get certified and gain experience in areas like Windows Server 2008, Exchange Server, SharePoint Server, and more. Get Mark Minasi’s Windows Server 2008 Audio CDs"Windows expert, consultant and best-selling author Mark Minasi shows you if 2008 is right for you and, if so, how to get the most out of it! Desktop Management is a Never-Ending Job for AdministratorsGet a complete desktop management solution to centralize the management of thousands of desktops that will help you keep up with increased demand with limited manpower. Integrate Fax Servers into Your Unified Communications PlanIn this fundamentals eBook you will learn how you can implement a solution that is easy to support, secure, and integrate. Take Control of Your Email Optimize your email storage – Download this white paper to learn key how-to’s in email storage management. Get Windows IT Pro To Go!The Windows IT Pro Magazine Master CD is a powerful combination of content and convenience.   Order now, and save up to 25%--plus you’ll get online access to new articles each and every month!  Subscribe today!
Windows IT Pro |  Subscribe |  Register |  FAQ for Windows |  Media Kit |  WinInfo News |  Europe Edition |  About Us |  Contact Us/Customer Service |  Affiliates/Licensing
SQL Server Magazine |  Office & SharePoint Pro |  WinDevPro |  asp.netPRO |  IT Library |  Technology Resource Directory |  ITTV |  IT Job Hound

© 2009 Penton Media, Inc.     Terms of Use | Privacy Statement | Reprints and Licensing