|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2002-02-12, 22:18
|
Psyruss420 
Regular
|
|
|
|
Novell Hacking involving NDS Tree exploit
This hack is being attempted on a Netscape enterprise 3.5/for netware mime 1.0, uses NetWare 5 LDAP v3 for NDS vrs 3.0. Using the NDS Tree exploit (read access to the tree listing using bug in lcgi/ndsobj.nlm) I have obtained a good amount of information (all tree branches, account names, ports and network addys). When I was viewing one of the accounts information from NDS, it had a listing in it as follows under the heading "Proxy password" REMOTE ADMIN 0000 61 47 39 33 5a 48 6b 3d aG93ZHk=
I assume the aG93ZHk= is the encyrpted password, and if it is, what can I use to decrypt it? I've seen a few algorithm keys pertaining to Novell but not for this, or if there was a way to download the account listings in a .nlm format so it can jus be dropped in NDS cracker...I haven't seen the format for the nlm pw files, perhaps it would be possible to just get any nlm file, change the essentials (aG93ZHk=) and drop it in da cracker. Any info on this would be appreciated
|
|
#2
 2002-02-13, 05:59
|
syphon detonator 
Regular
|
|
|
|
Re: Novell Hacking involving NDS Tree exploit
well your smart enough to give us all the necesary info so i applaud you for that. abviously you know something about hacking but seem a little low on the crypto info. you cant decrypt the password. there is no way to reverse decrypt with todays advanced algos but i would imagine it can be cracked. you will need the encrypted password file so you can crack it but as you said the algo may be difficult to find. cracking consits of taking the original pwd file and having the computer automaticly gueseing every posibly pwd then encryting it. after you made up pwd is encrypted it is checed against the original file. if it matches then you have a 90% or greater chance that you have found the key.
your best bet eould be to post at a few other bbs's because i dont think many of us are that advanced (im sure as hell not). i recomend the book "applied cryptograpy" which is freely available on the net.
good luck
|
|
#3
 2002-02-17, 19:09
|
Psyruss420 
Regular
|
|
|
|
Re: Novell Hacking involving NDS Tree exploit
Thanks for the response. I deny the lack of cryptography though you bastad! =) I have searched high and low for *real* hacker boards, but all I ever can find are dumbass good for nothing more less flame boards full of "dUd3 h0w do i hax0r yah00 emailz dud3!!!!!" its rather pathetic actually. Well, back to my search of others who do not suck...
-Psyruss
|
|
#4
 2002-02-18, 00:07
|
soullace 
Regular
|
|
|
|
Re: Novell Hacking involving NDS Tree exploit
code:
REMOTE ADMIN 0000 61 47 39 33 5a 48 6b 3d aG93ZHk=
To me that looks like base64 encoding. If you convert to base16 you get these hex values: 70 6F 77 68 79 00 which to me looks like the string "powhy" with null termination, base64 conversion is described in rfc 2535
|
|
#5
 2002-02-18, 09:41
|
|
|
Re: Novell Hacking involving NDS Tree exploit
quote: Originally posted by Psyruss420: I assume the aG93ZHk= is the encyrpted password, and if it is, what can I use to decrypt it?
howdy
|
|
#6
 2002-02-18, 12:56
|
Psyruss420 
Regular
|
|
|
|
Re: Novell Hacking involving NDS Tree exploit
Using "The Reiners" crypto alg thats what I came up with, unfortunately it isn't right...I think my best bet would be to find a way to download the *.nlm file in itself, and then just drop it in one of the many Novell crackers that support *.nlm. Thanks for the input -Psyruss
|
|
#7
 2002-02-20, 00:03
|
soullace 
Regular
|
|
|
|
Re: Novell Hacking involving NDS Tree exploit
hehehe i guess converting it by hand wasn't very smart :]
|
|
#8
 2002-02-22, 17:16
|
cense 
Regular
|
|
|
|
Re: Novell Hacking involving NDS Tree exploit
quote: hehehe i guess converting it by hand wasn't very smart :]
hey, in my opinion it is a lot smarter to figure out what encoding it was by looking and to try and figure it out in your brain. It takes much less effort to just plug it into a decoding program... "props" (hehe, i dont like that word) to you soullace. -- cEnsE evil, corruption and bad taste
|
|
#9
 2002-02-23, 00:06
|
soullace 
Regular
|
|
|
|
Re: Novell Hacking involving NDS Tree exploit
thanks... it would have been more impressive if i would have gotten it right. I must have been a couple of bits off in my translation. Oh well im human, thats what we make programs for anyways.
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|