The Real Deal

Admin's picture
The Real Deal
THE REAL DEAL /////////////////////////////////////////////////////////////////////////////// THIS MISSION ALTHOUGH BEING THE LAST IS NOT THAT MUCH MORE DIFFICULT THAT THE OTHERS.  WE     WILL HAVE TO USE THE KEYSNIFFER AGAIN; HOWEVER, ON THE BRIGHT SIDE THERE ARE PLENTY OF FILE   UPLOAD PORTS TO GAIN QUICK ACCESS TO.  AFTER LOGGING INTO THEIR LAN I LOCATE THE EMPLOYEE     FILE AND DO AN OPEN: COMMAND WHICH OPENS IT IN AN EXTERNAL EDITOR INSTEAD OF DUMPING THE      CONTENTS TO THE SCREEN.  FROM THERE I RETURN TO THE E-MAIL WINDOW SO I CAN COPY THE NEW       RECORD AND REMEMBER WHICH ONE IT IS I AM SUPPOSED TO MODIFY.  I EDIT THE FILE MAKING SURE     THE OLD KEY IS GONE AND THE NEW ONE IS REPLACING IT AND THEN DISCONNECT.  WHEN YOU EDIT       A FILE ORDER DOES NOT MATTER, EVEN WHEN THE DATABASE LOOKS SORTED.  NOT NECESSARY TO MANUAL   SORT.                                                                                         #############################################################################################       //                                                                                      CMD   // whois:production                                                //  12:17 PM 7.16.03       //                                                                                      WHOIS // 40.78.123.225     : EA Production Server                        //  12:27 PM 7.16.03 WHOIS // 81.100.177.8      : Blacksteel Production Server                //  12:27 PM 7.16.03 WHOIS // 95.210.229.53     : Zeneon Production Server                    //  12:27 PM 7.16.03 WHOIS // 98.1.156.230      : MS Production Server                        //  12:27 PM 7.16.03       // 4 Search Results Found                                          //  12:27 PM 7.16.03       //                                                                                      CMD   // pscan:40.78.123.225                                             //  12:43 PM 7.16.03       //                                                                                      START // Initializing Port Scanner...                                    //  12:43 PM 7.16.03 SCAN  // Port Scanning: 40.78.123.225                                    //  12:44 PM 7.16.03       // --------------------------------------------------------------- //  12:46 PM 7.16.03 OPEN  // Port: 1     Class: Miscellaneous TCP Port Service Multiplexer   //  12:46 PM 7.16.03 OPEN  // Port: 5     Class: File Upload   Remote Job Entry               //  12:46 PM 7.16.03 OPEN  // Port: 49    Class: Connection    TACAS                          //  12:46 PM 7.16.03 OPEN  // Port: 129   Class: Miscellaneous Password Generator Protocol    //  12:46 PM 7.16.03 OPEN  // Port: 139   Class: Connection    NETBIOS Session Service        //  12:46 PM 7.16.03 OPEN  // Port: 3049  Class: File Upload   Ccmail Server                  //  12:46 PM 7.16.03 OPEN  // Port: 4343  Class: File Upload   UNICALL                        //  12:46 PM 7.16.03       // --------------------------------------------------------------- //  12:46 PM 7.16.03       // Scan Completed : 12:46 PM 7.16.03                               //  12:46 PM 7.16.03 PSCAN // Ports Vulnerable : True                                         //  12:46 PM 7.16.03 EXIT  // Terminating Port Scanner                                        //  12:46 PM 7.16.03       //                                                                                      CMD   // connect:40.78.123.225:3049                                      //  12:50 PM 7.16.03       //                                                                                            // Connecting to: 40.78.123.225 on port 3049                       //  12:50 PM 7.16.03       // LAN Connection Established to (40.78.123.225)...                //  12:51 PM 7.16.03       // EA Production Server                                            //  12:51 PM 7.16.03       //                                                                                      CMD   // launch:keysniffer                                               //  12:55 PM 7.16.03       //                                                                                      PCQ   // PCQ.Launching(keysniffer)                                       //  12:55 PM 7.16.03 FOUND // =============================================================== //   1:15 PM 7.16.03       // KeySniffer --> Username: columnar                               //   1:15 PM 7.16.03       //                Password: inductor                               //   1:15 PM 7.16.03       // =============================================================== //   1:15 PM 7.16.03       //                                                                                      CMD   // login:columnar:inductor                                         //   1:23 PM 7.16.03       //                                                                                            // LAN Login Successfull                                           //   1:24 PM 7.16.03       //                                                                                      CMD   // c:                                                              //   1:24 PM 7.16.03       //                                                                                      DIR   // File Name                     Size      Type  E  C  Date        //   1:24 PM 7.16.03       // =============================================================== //   1:24 PM 7.16.03       // documents\                                    0  0  12.16.02    //   1:24 PM 7.16.03       // macross\                                      0  0  12.16.02    //   1:24 PM 7.16.03       // programs\                                     0  0  12.16.02    //   1:24 PM 7.16.03       // autoexec.bat                  12k       .bat  0  0  12.16.02    //   1:24 PM 7.16.03       // config.sys                    6k        .sys  0  0  12.16.02    //   1:24 PM 7.16.03       //                                                                                      CMD   // c:\documents\                                                   //   1:29 PM 7.16.03       //                                                                                      DIR   // File Name                     Size      Type  E  C  Date        //   1:29 PM 7.16.03       // =============================================================== //   1:29 PM 7.16.03       // admin\                                        0  0  12.16.02    //   1:29 PM 7.16.03       // user\                                         0  0  12.16.02    //   1:29 PM 7.16.03       //                                                                                      CMD   // c:\documents\user\                                              //   1:30 PM 7.16.03       //                                                                                      DIR   // File Name                     Size      Type  E  C  Date        //   1:30 PM 7.16.03       // =============================================================== //   1:30 PM 7.16.03       // applications\                                 0  0  12.16.02    //   1:30 PM 7.16.03       // projects\                                     0  0  6.24.03     //   1:30 PM 7.16.03       // ntuser.dat                    120k      .dat  0  0  12.16.02    //   1:30 PM 7.16.03       //                                                                                      CMD   // c:\documents\user\projects\                                     //   1:32 PM 7.16.03       //                                                                                      DIR   // File Name                     Size      Type  E  C  Date        //   1:32 PM 7.16.03       // =============================================================== //   1:32 PM 7.16.03       // advi_codes.doc                1035k     .doc  0  0  6.24.03     //   1:32 PM 7.16.03       // employee_plan.doc             1035k     .doc  0  0  6.24.03     //   1:32 PM 7.16.03       //                                                                                      CMD   // openl:employee_plan.doc                                         //   1:39 PM 7.16.03       //                                                                                      ERROR // Unidentified Command: openl                                     //   1:39 PM 7.16.03       //                                                                                      CMD   // open:employee_plan.doc                                          //   1:42 PM 7.16.03       //                                                                                      OPEN  // Opening c:\documents\user\projects\employee_plan.doc For Editin //   1:42 PM 7.16.03 OPEN  // g                                                               //   1:42 PM 7.16.03 CLOSE // File Contents Saved                                             //   1:59 PM 7.16.03       //                                                                                      CMD   // disconnect:                                                     //   2:12 PM 7.16.03       //                                                                                      ABORT // Connection Terminated                                           //   2:12 PM 7.16.03       //                                                                                      ############################################################################################# THATS THE TUTORIAL                                                                            I DON'T WANT TO SAY ANYTHING ABOUT THE PLOT.                                                  YOU WILL HAVE TO FIND OUT WHAT HAPPENS FOR YOURSELF.