TheNetwork Administrator.com

                                                A Website Dedicated to Computer Professional...and some not so Professional

A Network Administrator is only as good a the his or her ability to protect their Servers.


Getting Started

You must first decide what your target is. A company or an individual? A web server or a PC, or AOL? There are very different methods for each.

To begin hacking web servers


You will need to stock your arsenal with several tools. Start with a IP Converter, a port scanner, and a tool that allows you to do HTTP Requests. NetView is a good overall tool to start with that includes all of these.

Using NetView : Click the WebBrute tab and enter the url in the 'Web URL' box. Click 'Create'. This will form a basic HTTP Request in the 'HTTP Request' pane of the app. Click 'Verify'. This sends the Request to the server for that domain, and will return information in the 'HTTP Reply' pane. This will include the server software and version for the computer hosting that domain; or, the web server.

Knowing what platform a server is running on is crucial to hackers who wish to crack it. Copy or log this information in a text file for later reference.

Next, type the host name (the domain without http://www. ) into the 'computer/host name' field under the NetView tab. Click 'Get IP'. Then, type the first three numbers of the ip into the three boxes supplied in the 'Range' field. Make sure the 'TCP' selection box is set to 'all'. Click 'Scan'. This will scan the IP addresses in range of the server for open ports. Port 80 will be open. Depending on the server, it may return several open ports. For detailed information on what the port numbers mean see the ports tutorial.

As before, you will want to copy or log this info for later reference. The next step is to search and test for exploits.


To begin hacking PCs


You can target victims individually via, or en masse via the web. Either way, you will want to get yourself some r.a.t.s. You might also want to add an exe packer and unpacker to your arsenal. These will allow you to hide your r.a.t. behind a more friendly looking app.

Using Sub7 : There is detailed documentation available at mobman's site : www.sub7files.com. But, the method that has worked for me has been to start with web site. You may want to claim you're offering free pr0n. (Always gets visitors, usually ones that make fun targets.) Put links to multiple files with links that say '50,000 free pics with download' or something. Rename your sub7 server to 'pics.exe' or 'sexxx.exe'. When they click a link to download their pics, they will get your sub7 (or other) server instead.

Or, you could send out a Britney Spears screensaver to a bunch of people. (You can get addies from AOL, do a directory search for 'britney spears'). Bind it with a small server like Psychward and wait for them to load it. It will seem they are installing the screensaver (they are) but your r.a.t. is installing in the background. Then you can log on to thier machine and upload a larger server (like sub7).

To begin hacking AOL


Awww, don't you love 'em? I can't give you detailed info on how to do this, but you can find a lot of info on my site here and on another site here.

Anonymity


Oh, you *have* to do this! Otherwise, you will be in jail very soon. Here are some basic tips to protect yourself:

  • Get a personal firewall. This will log all unsolicited attempts to connect to your machine. (Some may be by your ISP ;). One that seems to be popular is BlackICE.

  • Get a free web mail address. Use it to send out *anything* related to your activities, r.a.t.s included. Do not use a real name or address when you sign up. They do store this info. Do not have it forwarded to your network address. Do not collect it on your PC, only via the web.

  • Get an AV (anti-virus). A good one is Norton's. (Don't pay, get a crack. Try a search at www.astalavista.com.) Let it scan constantly.

  • Do not use a real name or address when signing up for any web space, AOL accounts, etc. Be paranoid.

  • If you are doing *anything* strange on AOL, use an older version (I recommend 4.0) and connect via TCP/IP, (find out how here) they track the number you dial in from if you dial-up. In fact, they will have you call them from that number to activate a dial-up account.

    top

 

Hacking The IT Cube: The Information Technology Survival Guide -- Douglas Chick