Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




pen-test logo Penetration Testing mailing list archives

[PEN-TEST] Sniffing web-based NT logins
From: "Batten, Gerald" <GBatten () EXOCOM COM>
Date: Thu, 11 Jan 2001 09:55:37 -0500

I was wondering if there was a tool, or if someone knew how to pick it off
of a regular sniffer, to pick up the NT has of an NT login over the web.
Let me explain...

The server is IIS 5.0, the web clients are IE 5.x, and the server is
configured to take NT authentication to the protected web pages exclusively.
This means that Netscape won't work, and that the passwords are not sent as
the standard Base64 encoding.

So, how are the passwords transferred, and how would I use a sniffer to pick
it up?  I'm assuming that they would be Lanman hashes and that I could pull
them off the wire somehow and use LophtCrack to guess the passwords?

Gerald.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]