Pentesters???

Darryl Licht

New member
Guru
VIP
Local time
12:49 PM
Messages
1,934
Location
So Cal (I.E.)
Hey any of you into Pentesting? Wired, wireless, password recovery, strictly white hat stuff. If so, what are your stories, experiences, favorite tools, etc???
 

My Computer

Computer Manufacturer/Model Number
Homebrew PC - "Alpha_Dawg"
OS
Windows 7 Ultimate 64 bit Steve Ballmer Signature Edition
CPU
Intel Core 2 Quad - Q9550 - 2.83GHz stock - OC'd to 3.6GHz
Motherboard
Gigabyte EP45-UD3P
Memory
4GB DDR2 800MHz (PC6400) OCZ Reaper
Graphics Card(s)
Nvidia GE Force 8800 GTS
Sound Card
Asus Xonar DX
Monitor(s) Displays
Samsung SyncMaster 2333HD
Screen Resolution
1920 x 1080
Hard Drives
WD Caviar Black 750GB - 7200RPM - 32MB cache
WD Caviar Green 1.5TB - 5400RPM - 64MB cache
WD Caviar Green 2.0TB - 5400RPM - 64MB cache
PSU
PC Power & Cooling Silencer 750
Case
Gigabyte 3D Aurora
Cooling
Case is Air - 5ea. 120mm fans (mix of Arctic and Xigmatec)
Keyboard
MS Natural Wireless KB
Mouse
MS Wireless Mouse
Internet Speed
50 mbps down/5 mbps up
Other Info
AVerMedia - AVerTVHD G2 Dual Tuner Card
are you getting into the field? or just curious to see what tools people use to detect/exploit?
 

My Computer

OS
7 Pro
exploiter!
 

My Computer

Computer Manufacturer/Model Number
The Vampire
OS
Windows 7 Ultimate
CPU
Intel i5 2500k @ 3.30
Motherboard
P8Z68 V-Pro
Memory
G.Skill Ripjaws 1600 2x4 Gb
Graphics Card(s)
BFG GTX 260 MAXCORE 55 OC 896MB GDDR3
Sound Card
Onboard
Monitor(s) Displays
50'' Sony Display Panel
Screen Resolution
1360 x 768
Hard Drives
Seagate 750 GB
WD 160 GB
PSU
OCZ 750 Watts ZT Series Fully Modular PSU 80 Plus Bronze
Case
NZXT Red Phantom
Cooling
120mm x2 Intake, 120mm x 1 and 200mm x2 Exhaust
Keyboard
LX710 Logitech Wireless Keyboard
Mouse
Logitech Wireless Mouse
I don't have any of the tools now, but when I was in college I was able to scan IPs for open ports by the thousands and access computer terminals and upload/download, manipulate files, view screens and capture keys...

Messed around on a few friends computers with their permission. Never did anything malicious, but was into how to gain entry. I had probably about 10 diff. programs to allow access and prevent entry into my own computer. I Also knew how to get into a computer around the passwords and stuff like that. :P

I haven't messed with any of that though in at least 10 years. But it was fun :)
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS G60-RBBX05
OS
Win7 Home Premium 64x
CPU
Intel Core 2 Duo P7450 / 2.13 GHz (2.29 with Extreme Turbo)
Memory
4 GB PC-6400 Hyundai (2X2) at 800Mhz
Graphics Card(s)
NVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Monitor(s) Displays
16" LED Backlit
Screen Resolution
1366 x 768 on laptop 1600x1050 max res on 22" external mon
Hard Drives
OCZ Agility 3 60GB SSD / 320 GB - Serial ATA-150 - 7200 rpm
PSU
6-cell Lithium ion { lasts 1.5 hours }
Case
ASUS G60 Laptop
Keyboard
Chicklet type back-lit (white light) keyboard
Mouse
Logitech G9 Laser Mouse 3200dpi and 1000 reports per minute
Internet Speed
Comcast 8.60mb/s up - 3.11mb/s down
Antivirus
MSE
Browser
Firefox
Other Info
General mid-budget gaming Comp. Low batterylife - High FrameRates - currently overheating problems :(

2nd Rig: Case: Rosewill BLACKHAWK Gaming ATX Mid Tower Computer Case

Mobo: GIGABYTE GA-990FXA-UD3
CPU: AMD FX-6200 Zambezi 3.8GHz (4.1GHz Turbo)
Heatsink: COOLER MASTER V8 CPU Cooler
RAM: Patriot Viper 3 8GB (2 x 4GB) 240-Pin DDR3 SDRAM 1866 (PC3 15000)
GPU: SAPPHIRE Radeon HD 6850 1GB 2
Pen testing isn't that much fun - too many 'rules' that must be followed when pen testing :(

CEH - is a fun cert to get, learn quite a lot without being pinned down by rules and regulations.
 

My Computer

OS
7 Pro
I've been learning and "playing" more and more with Linux based tools such as BackTrack which includes all the commonly used tools in one bootable Live CD. BTW, most of the best tools are Linux based... so in my opinion if I want to protect, I must know my enemy!

I was utterly amazed at the speed and ease of cracking into a WEP based wireless network... I have understood for years not to use WEP encryption, but I had no idea how easy it was to crack! A 13 year old with a laptop could be on your network now; using your bandwidth, or going into your shared folders. I setup a dummy router for this of course. It was cracked and I was using its Internet and changing router configuration within minutes!

I also tried cracking my own WPA encrypted wireless... Which I thought to be more secure. As I found out... it wasnt!

I do not use a word for my password, ever! I use a mix of typically upper and lowercase with numerals, some passwords I add special symbols to as weel for more security! My first attempt failed... a quick check of the huge word list I used contained a dictionary and a list of commonly used passwords and my pw of course wasnt in it. On my second try, after editing the word list and randomly adding my pw into it; I then cracked my WPA encryption in under 20 minutes!

I now run a WPA2 encrypted wireless network! :D

I have used older tools like BackOrifice (in the day), BackTrack, Ophcrack (and similar tools for getting Windows passwords), and others. I find them invaluable tools in my consulting business. I use them for those situations when I am repairing a system and the user forgot to give me a password, or isnt available, or has lost/forgotten/changed it.
 

My Computer

Computer Manufacturer/Model Number
Homebrew PC - "Alpha_Dawg"
OS
Windows 7 Ultimate 64 bit Steve Ballmer Signature Edition
CPU
Intel Core 2 Quad - Q9550 - 2.83GHz stock - OC'd to 3.6GHz
Motherboard
Gigabyte EP45-UD3P
Memory
4GB DDR2 800MHz (PC6400) OCZ Reaper
Graphics Card(s)
Nvidia GE Force 8800 GTS
Sound Card
Asus Xonar DX
Monitor(s) Displays
Samsung SyncMaster 2333HD
Screen Resolution
1920 x 1080
Hard Drives
WD Caviar Black 750GB - 7200RPM - 32MB cache
WD Caviar Green 1.5TB - 5400RPM - 64MB cache
WD Caviar Green 2.0TB - 5400RPM - 64MB cache
PSU
PC Power & Cooling Silencer 750
Case
Gigabyte 3D Aurora
Cooling
Case is Air - 5ea. 120mm fans (mix of Arctic and Xigmatec)
Keyboard
MS Natural Wireless KB
Mouse
MS Wireless Mouse
Internet Speed
50 mbps down/5 mbps up
Other Info
AVerMedia - AVerTVHD G2 Dual Tuner Card
In the efforts of helping someone learn about security,
nMap,
Ophcrack,
Backtrack,
netscan,

then there is another side the human aspect.
 

My Computer

Computer Manufacturer/Model Number
SMN-Productions
OS
Windows 7 x86/x64, Server 2008r2, Web Server 2008
CPU
i7 v2 3930K Steping stone 2
Motherboard
ASUS Rampage IV Extreme
Memory
G.SKILL Ripjaws Z Series 32GB
Graphics Card(s)
AMD HD 5770
Monitor(s) Displays
Acer 21" and Samsung 20"
Hard Drives
Patriot Pyro 80GB
PSU
1000 Watt
Case
HAF-X
Cooling
4 Fans
Keyboard
Black Widow Ultimate
Back
Top