Daniel Compton, Information Security Consultant of 7Safe, took the audience through a demonstration of common risks found that he sees whilst carrying out penetration tests for clients. This covered two main areas which were "client side attacks" and "pivot attacks". The demonstrations were all based on fully patched Windows operating systems with anti-virus protection, firewall protection and the latest patches for 3rd party products. Once the client victim computer was exploited from the Internet, Daniel demonstrated how it was possible to pivot and dive deep into the internal corporate network and extracting passwords and credit card data. You can watch the video demonstration here.
Cool vid dude, but I seem to have some troubles with ophcrack. I got a hash (and I actually know the pass, I just want to test ophcrack) and well I appear to have no 'tables' installed.. Nothing happens when i press crack and also the bottom windows on ophcrack is empty in my screen. Whats wrong? and how do I solve it?
Thanks!!!
blacksiddis 1 year ago
@blacksiddis You will need to manually download these from Ophcrack. If using something like Backtrack it will not have the tables installed by default due to the size it would make the installer.
7Safe 1 year ago
why upload whosthere-alt instead of using meterpreter's incognito module? (This is a true question, I don't know advantages for that...)
mihiguy 1 year ago
@mihiguy You could use incognito to impersonate the token for the administrator, but for the demo we wanted to extract the hash of the password to show passing the hash techniques.
7Safe 1 year ago