13.07.2015 Views

PDF - Xakep Online

PDF - Xakep Online

PDF - Xakep Online

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ÂçëîìÕÀÊÅÐ\¹39\Ìàðò\2002ÌÎÍÑÒÐÛ Â ÃÎÐÎÄÅ!Äåíèñ Ìûñåíêî < Folder4>Ãðàôè÷åñêèé èíòåðôåéñ BeatLMÎäíàêî ñóùåñòâóþò ñïåöèàëüíûå ñðåäñòâà, ïðåäíàçíà÷åííûåäëÿ âçëîìà òîëüêî ÑÓÁÄ. Íàïðèìåð,MySQL brute force password hash cracker(www.securiteam.com/tools/5YP0H0A40O.html), êîòîðûéïîçâîëÿåò âçëàìûâàòü çàøèôðîâàííûå ïàðîëèê áàçå äàííûõ MySQL.Íà ñåðâåðå www.cqure.net òû ìîæåøü ñêà÷àòü åùåíå çàêîí÷åííóþ, íî óæå ýôôåêòèâíóþ óòèëèòó SQLAuditing Tool, êîòîðàÿ ïîçâîëÿåò ïîäáèðàòü ïàðîëèäëÿ ïîëüçîâàòåëåé, çàðåãèñòðèðîâàííûõ MS SQLServer. Àíàëîãè÷íûå äåéñòâèÿ (òîæå äëÿ MS SQLServer) ïîçâîëÿåò âûïîëíèòü óòèëèòà SQLdict(http://ntsecurity.nu).Äðóãèå ñðåäñòâàÅñëè òû íå ñìîã ïîäîáðàòü ïàðîëü ñ ïîìîùüþ ðàññìîòðåííûõïðîã - íå ïåðåæèâàé. Ïîïðîáóé êàêîåíèáóäüäðóãîå ñðåäñòâî, ïåðå÷èñëåííîå íèæå.Íà ñòðàíèöå http://kapheine.hypa.net/authforce/index.phpòû ñìîæåøü íàéòè ñîôòèíó AuthForce äëÿ âçëîìà Webñåðâåðîâ,à íà ñòðàíèöå www.jps.net/coati/archives/slurpie.tgz äîñòóïíà î÷åíü èíòåðåñíàÿ óòèëèòàSlurpie, ÿâëÿþùàÿñÿ ïîëíûì àíàëîãîì John the Ripper çàîäíèì íåáîëüøèì èñêëþ÷åíèåì. Slurpie ïîçâîëÿåò îñóùåñòâëÿòüïîäáîð ïàðîëÿ, ðàñïðåäåëÿÿ ýòó çàäà÷ó ñðåäèíåñêîëüêèõ ñåðâåðîâ, íà êîòîðûõ òåáå íóæíî áóäåòçàïóñòèòü ñîîòâåòñòâóþùèå óòèëèòû.Çàêàí÷èâàÿ îïèñàíèå ñðåäñòâ ïîäáîðà ïàðîëåé,õî÷ó åùå ïàðó ñëîâ ñêàçàòü è î êîììåð÷åñêèõ ïðîäóêòàõ,êîòîðûå õîòü è ñòîÿò äåíåã (ïîä÷àñ íåìàëûõ),íî è çà÷àñòóþ ÿâëÿþòñÿ áîëåå ýôôåêòèâíûìè,÷åì èõ áåñïëàòíûå ñîðîäè÷è. Êàê è â ïðåäûäóùåéñâîåé ñòàòüå, ïîñâÿùåííîé îáìàííûì ñèñòåìàì(ñìîòðè Õ #12’01), ÿ êîñíóñü ðåøåíèé êîìïàíèèInternet Security Systems, õîðîøî çíàêîìîéâ Ðîññèè.Ïîäáîð ïàðîëåé ðåàëèçîâàí âî âñåõ òðåõ ñêàíåðàõîò ýòîé êîìïàíèè:* Internet Scanner - ïîèñê óÿçâèìîñòåé è ïîäáîð ïàðîëåéíà óðîâíå ñåòè (äëÿ Web-ñåðâåðîâ, ìàðøðóòèçàòîðîâ,ìåæñåòåâûõ ýêðàíîâ è ò.ä.);* System Scanner - ïîèñê óÿçâèìîñòåé è ïîäáîð ïàðîëåéíà óðîâíå îïåðàöèîííîé ñèñòåìû Linux,Solaris, Windows NT, 2000, HP UX, AIX è ò.ä.;* Database Scanner - ïîèñê óÿçâèìîñòåé è ïîäáîðïàðîëåé íà óðîâíå ÑÓÁÄ (MS SQL Server, Oracle èSybase).Çàêëþ÷åíèå çàêëþ÷åíèå õî÷ó ñêàçàòü, ÷òî åñëè áû þçåðû âûáèðàëèñåáå íîðìàëüíûå ïàðîëè, ñîâìåùàþùèå âñåáå è öèôðû, è áóêâû â ðàçëè÷íîì ðåãèñòðå è èìåþùèåäëèíó íå ìåíåå 8 ñèìâîëîâ, òî æèçíü õàêåðîâñóùåñòâåííî áû îñëîæíèëàñü. À ïîêà ìîãó òîëüêîïîðåêîìåíäîâàòü íåðàäèâûì ïîëüçîâàòåëÿì ïîâåñèòüíàä ñâîèì ðàáî÷èì ñòîëîì ïëàêàò: «À òû ñìåíèëñâîé ïàðîëü?»Õîòÿ, åñëè âñïîìíèòü, ÷òî áîëüøèíñòâî þçåðîâ âåøàþòïðÿìî íà ìîíèòîð áóìàæêó, íà êîòîðîé íàïèñàíýòîò óæàñíûé, òàê òðóäíî çàïîìèíàåìûé è âîîáùåíåèçâåñòíî êàêèì èäèîòîì ïðèäóìàííûéïàðîëü... :)< Âçëîì >20/03\021 2 3 455 Íüþñû Ôåððóì PC_Zone X-Ñòèëü Âçëîì

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!