June 28, 2009
Final Build
June 21, 2009
Local Password Bypass
Ok, for most of you out there in the IT fields you have probably come across a situation where you needed access to a machine and the password was not available for on of millions of weird reasons.
Originally I used a suite of tools called the PC Doctor (not to be confused with The Computer Doctor) which resets the password parameter.
I also used OphCrack (bootable CD or as part of Backtrack 3 & 4) which cracked the Hash with pre-configured rainbow tables. This could take between 5 - 15 minutes depending on the targets processor.
I finally found a new tool, thanks to Snubbs at HAK5, which is fast and undetectable.

The tool is called Kon-Boot which is deployed as a bootable CD or Floppy.
Instead of cracking a password or changing the password, it temporarily changes the kernel so you just press enter and you get into the local machine. The only downside is this is for local machine use only and does not log you into Active Directory (to my knowledge).
Another plus is that this disk can be used for both Microsoft as well as some Linux Distros. Just insert the disk, boot up, press any key when the screen comes up and press enter when asked for the windows password. (see the website for Linux instructions)
According to the website this disk works on Windows XP, Vista, 7, Server 2003, Server 2008, and with Grub 0.97 Gentoo, Ubuntu, Debian and Fedora.
Attention all bored hackers. If anyone can test this program on the following systems and report back, i'll re-edit this post and credit your find. Windows 95, 98, NT workstation, 2000, ME, XP CE, XP SE, NT server and server 2000. Also Kubuntu, Edubuntu, Mepis, OpenSuse, and any other mainstream Linux Distros.
May 28, 2009
Contest Submission
So I was watching this weeks episode of Hak5 and I had almost forgotten that there was a contest on mapping your home LAN, so I hurried to my visio console and threw together the computer doctors home map and submitted it. It would be cool to win, but even if I don't, it was fun to make. To see my submission and all the others, check out the user submission page.
May 21, 2009
Taking Time Out
So as most of you know I've been studying for my 70-291 like crazy lately. So to blow off some steam, I took a day off just to play with the boys. I also gave Drake his first big boy haircut. Hope you enjoy a few moments of fun with my boys and remember to take time off to enjoy your summer as well.
May 17, 2009
IPSEC Request, Reply or Require
While this isn't the first instructional video I've produced, it is the very first video I've ever put into a blog, so please forgive the few mishaps towards the end of the video, and as always I hope you enjoy.
May 14, 2009
How VPN Access Works
- User "dials in"
- Rule number 1 asks "is it between 6am and 6pm?" lets assume it's is... go to the next rule
- Rule number 2 asks "are you a member of our ADUC (active directory)?" lets again assume yes... go to the next rule
- Rule number 3 asks "are you authorized for dial-in / vpn access?" lets again assume yes... go to the next rule (NOTE: many times this question becomes a stumbling block because the system admin or other IT personnel forgot to check the dial-in access in the users active directory profile)
- Rule number 4 asks "are you using the right security protocol?" (ie. MS-ChapV1 or EAP ect.) lets assume yes again... access is granted!!!

If at any time one or more of those questions are answered with a no, the user is denied access and should call their local helpdesk for help troubleshooting their access denial.
May 13, 2009
How we resolve websites through the use of DNS
For this example we are useing http://www.google.com/ which is broken up as www(web server).google(secondary level domain).com(top level domain).(root level domain)
- The user types http://www.google.com/ into their favorite browser and presses enter
- The PC initiates a recursive query to their corprate, home, or ISP DNS server.
- The DNS server looks at their root hints to find the root zone server and does the first interitive query to it
- The root zone server sends the information about which top level domain server should be contacted next
- The DNS server does it's next interitive query to the top level domain server
- The top level domain server sends information about which second level domain server should be contacted next
- The DNS sever does it's next interitive query to the second level domain server
- The second level domain server sends informaiton about where it's web server is located
- The DNS does it's last interitive query to the web server
- The web server sends it's IP address to the DNS server
- The DNS server closes the recursive query after giving the web server IP to the PC
- The PC goes directly to the web server in question using the direct IP address

May 08, 2009
Pulling Rabbits Out Of Hats

- So the first thing I did was CTRL+ALT+DEL to bring up the task manager and run a new program. From the run line I entered the http for the avast antivirus program and downloaded it and had it do a full computer scan which took about 45 minutes and I came up with nothing noteworthy ruling out a virus.
- The second thing I did was CTRL+ALT+DEL to run the http for the SuperAntispyware download to look for other malware, rootkit, ect. and after it did it's full system scan that took about 1 hour I came up with a handful of cookies, but nothing noteworthy again. Now I'm frustrated because I have 1:45 invested with no results.
- So I do what every good IT professional should do. www.google.com thats right, you heard it here, google it. Somewhere out there, there is someone smarter than you, thats had the same problem as you, and wants the world to know how smart they really are. I found someone who said that if you run explorer.exe in this situation that it will re-fire explorer and everything will be back to normal, so I tried it and got the error that windows could not find explorer.exe.
- I went to the command line (cmd) and clearly saw that explorer.exe was right where it was supposed to be so I took an educated guess, went to regedit, found the key for explorer and changed the name to explorer.bak, re-ran explorer.exe and presto-chango-rearrango, windows did it's thing when there is no registry for explorer and it made a new one and everything came back.
- I learned that the customer already had AVG which found the virus and removed it, but not before the damage was done to the registry.
So to summerize boys and girls
- never assume
- have your tools ready
- bring your laptop to do research
- learn how to effectively use google including boolean string searches
- never let them see you sweat
- don't forget to pat yourself on the back when you finally have that rabbit out of the hat
Feel free to send you stories in on the comment line (use more than one comment if you need and I'll string them together in upcoming articles)
April 30, 2009
Your Comments...
April 29, 2009
Malware on legit sites, more common than you think.

For the past seven years I've watched the influx of spyware, adware and malware become a daily problem for my customers and co-workers and one question has always troubled me. "how did I get this?" After quizzing the already frustrated user about e-mail, downloads and websites I would always assume game downloads or porn sites. Before chucking the problem up to one of these reasons, read this article by avast.
My suggestion to all of my customers has always been
- Always use a good antivirus software. The most expensive one at the store may not be the greatest, the one with the best known name may not be the greatest. Top 5 antivirus programs to purchase are Viper, Bitdefender, Kaspersky, Panda and Norton. Top free antivirus programs are AVG, Avast and Avira.
- Always use a antispyware program. Isn't this the same as antivirus? No. Doesn't antivirus do the same thing? NO. Doesn't my antivirus take care of this too? YOU AREN'T LISTENING. NO, NO, NO!!!! You can not rely on your anti-virus software to take care of anything more than viruses which leave you wide open to all kinds of malware. The best one I've found that specializes in root-kit attacks is SuperAntispyware (programmed by geniuses and named by a 5 year old, i'm sure)
- If you have an anti-phishing filter (not to be confused with NO FISHING) on your browser please keep it turned on.
- Quit reading mail from people you don't know and quit sending the chain mail. To all my readers, you will not save little timmy's leg, there is no little girl saving the deer with water from her hand, there is no stalker in the wal-mart parking lot under your car, there is no gang initiation waiting for you to flash your headlights, or any of thousand other ridiculous chainmail stories that just aren't true, and you'll for sure not find a thousand dollars from Bill Gates, true love, world peace, or anything else at the end of these insane e-mails. Get an education at snopes.com for God's sake.
April 20, 2009
Active Directory Primer
Well I've got one for you. Two ways to look at creating users in active directory GUI (I'm working on a database project that can add multiple users in the server 2003 command line with dsadd and will talk about that when the bugs are out)

- The first way, which is the simplest but most time consuming is to go directly to the user group or the OU that is assigned to you and click add new user or the picture of the user (single human) and when the GUI opens you fill in the name, the address, the fax number, the phone number, give them and e-mail address, create their roaming profile, create their network folder, add them to all the groups you think they fall in and then wait for the user to call and complain about which network resources they still need access to, (more on NTFS troubleshooting in the future, just remember high/high/low for principle of least privilege), and then blame their supervisor for not knowing what groups the employee should have been in.
- The second way is to re-evaluate your current ADUC structure and make a group for each department and create a new "template" user with all the generic info about their site, add a home directory of \\server\folder\%username% (the %username% is a universal variable, if you don't understand how this saves time then google it) and the same for their roaming profile.
Now all you have to do is add their group to the security tab on the system NTFS folders in question and your done... unless you need to have your group access shares outside your local domain, don't know what an OU was, are not sure what a roaming profile is, or enjoy setting up one account at a time.
Still on target part 2
.jpg)
I've got multiple interviews this week so hopefully I'll be back to work soon.
I thought I felt a little tingle in my back recently and upon investigation I found that there are daggers stuck in my back, so for future posts I'll add dagger of the week comments (except for the truly poisonous one's which I'll just delete)
WHOISDNS writes again "still no job huh? thats weird with all your experience and certifications you should be making atleast $70,000 by now...."
To which I reply "Nope"
My question to you is, why do you care? I never get any comments from anyone except you. You seem so happy that I don't have a job at this point. Why is that? I'd hate to think that maybe you contributed to me being terminated. But it doesn't matter much to me, keep up the good work at baker and taylor and make sure you don't learn anything new especially how to keep my databases running when something goes wrong. I'd hate to think my old department didn't immediately fall back into the same old complacent slump of fixing antique crap, putting users off and making excuses for why new projects can't be achieved.
Hex Converter
Hex To ASCII Converter
Integer to Byte converter
This is a tool to practice converting between decimal and binary representations. After you have practiced for a while and feel that you know how to do the conversions, take the quiz.

