A Network Administrator is only as good a the his or her ability
to protect their Servers.
Getting Started
You must first decide what your target is. A company or an individual? A
web server or a PC, or AOL? There are very different methods for each.
To begin hacking web servers
You will need to stock your arsenal with several tools.
Start with a IP
Converter, a port
scanner, and a tool that allows you to do HTTP
Requests. NetView is a good overall tool
to start with that includes all of these.
Using NetView : Click the WebBrute tab and enter the url in the 'Web URL'
box. Click 'Create'. This will form a basic HTTP Request in the 'HTTP
Request' pane of the app. Click 'Verify'. This sends the Request to the
server for that domain, and will return information in the 'HTTP Reply'
pane. This will include the server software and version for the computer
hosting that domain; or, the web server.
Knowing what platform a server is running on is crucial to hackers who wish
to crack it. Copy or log this information in a text file for later
reference.
Next, type the host name (the domain without http://www. ) into the
'computer/host name' field under the NetView tab. Click 'Get IP'. Then, type
the first three numbers of the ip into the three boxes supplied in the
'Range' field. Make sure the 'TCP' selection box is set to 'all'. Click
'Scan'. This will scan the IP addresses in range of the server for open
ports. Port 80 will be open. Depending on the server, it may return several
open ports. For detailed information on what the port numbers mean see the ports
tutorial.
As before, you will want to copy or log this info for later reference. The
next step is to search and test for exploits.

To begin hacking PCs
You can target victims individually via, or en masse via the web. Either
way, you will want to get yourself some r.a.t.s.
You might also want to add an exe
packer and unpacker
to your arsenal. These will allow you to hide your r.a.t. behind a more
friendly looking app.
Using Sub7 : There is detailed documentation available at mobman's site :
www.sub7files.com. But, the method that has worked for me has been to start
with web site. You may want to claim you're offering free pr0n. (Always gets
visitors, usually ones that make fun targets.) Put links to multiple files
with links that say '50,000 free pics with download' or something. Rename
your sub7 server to 'pics.exe' or 'sexxx.exe'. When they click a link to
download their pics, they will get your sub7 (or other) server instead.
Or, you could send out a Britney Spears screensaver to a bunch of people.
(You can get addies from AOL, do a directory search for 'britney spears').
Bind it with a small server like Psychward
and wait for them to load it. It will seem they are installing the
screensaver (they are) but your r.a.t. is installing in the background. Then
you can log on to thier machine and upload a larger server (like sub7).
To begin hacking AOL
Awww, don't you love 'em? I can't give you detailed info on how to do this,
but you can find a lot of info on my site here
and on another site here.
|
Oh, you *have* to do this! Otherwise, you will be in jail very soon.
Here are some basic tips to protect yourself:
- Get a personal firewall. This will log all unsolicited attempts
to connect to your machine. (Some may be by your ISP ;). One that
seems to be popular is BlackICE.
- Get a free web mail address. Use it to send out *anything*
related to your activities, r.a.t.s included. Do not use a real
name or address when you sign up. They do store this info. Do not
have it forwarded to your network address. Do not collect it on
your PC, only via the web.
- Get an AV (anti-virus). A good one is Norton's. (Don't pay, get
a crack. Try a search at www.astalavista.com.) Let it scan
constantly.
- Do not use a real name or address when signing up for any web
space, AOL accounts, etc. Be paranoid.
- If you are doing *anything* strange on AOL, use an older version
(I recommend 4.0) and connect via TCP/IP, (find out how here)
they track the number you dial in from if you dial-up. In fact,
they will have you call them from that number to activate a
dial-up account.
top
|
|

|