Null Session Hacking On Windows

Posted By: SecurityTube_Bot
Posted On: Mon 21 Feb 2011
Views: 10395
Share this video:
Share it on Facebook Share it on Twitter Share it on Reddit Share it on Digg Share it on Stumbleupon
Support SecurityTube:


Description:

A NULL session connection is an unauthenticated connection to an Windows machine. Gaining NULL session access to a Windows system is the number one method for hackers to enumerating information about the machine.  From a NULL session hackers can call APIs and use Remote Procedure calls to enumerate information. These techniques can, and will provide information on passwords, groups, services, users and even active processors. NULL session access can also even be used for escalating privileges and perform DoS attacks.

In this video, L4amer from Practical Exploitation takes us through 3 tools that do enumeration using null sessions. Metasploit, rpcclient, and smbenum.py.

Tags: basics ,


Comments (None)

Login to post a comment