Login Register






[TUT]Hamachi - Defacing a local webpage filter_list
Author
Message
[TUT]Hamachi - Defacing a local webpage #1
Hi,

so, we all know hamachi, for those who don't:
Quote:Hamachi is a zero-configuration virtual private network (VPN) shareware application that is capable of establishing direct links between computers that are behind NAT firewalls without requiring reconfiguration (in most cases); in other words, it establishes a connection over the Internet that emulates the connection that would exist if the computers were connected over a local area network.
source: http://en.wikipedia.org/wiki/Hamachi_(software)

Okay, so first of all, download hamachi here: https://secure.logmein.com/US/labs/
Now run in terminal:
Code:
dpkg -i logmein-hamachi_2.0.1.13-1_i386.deb
if you get an error, you might want to run in terminal:
Code:
apt-get install -f

so after its all installed, run in terminal:
Code:
hamachi help
this will show you all commands you can use. Note that you have to put "hamachi" in front of every command!

Now go and find some hamachi group and connect.



Okay I have made my own network named: HackCommunityTest with password: HC
you can join if you want, but never ever try to pentest anybody without their permission!!!

[Image: snapshot1p.png]

so now we are connected and we have our target, its name is "TEST"

Lest run nmap to find out the OS and open ports:

Code:
nmap -O [target hamachi IP]

I have my results bellow:

[Image: snapshot2yn.png]

from the scan we can tell it might be Windows XP and it has open port 445, thats awesome for our exploit netapi which you know from enc0des guide: Basics of gaining acces!

So lets make this short, lets expect you have allready picked up your exploit and payload. Now lets set the rhost, lhost. We will be using hamachi ip's.

To find your hamachi IP, just type in terminal:
Code:
hamachi

[Image: snapshot3x.png]

If all goes good, we will get a meterpreter.

Now lets go into the defacing part,

My victim is running XAMPP for hosting the website, xampp is installed in C:\ by default, you might need to search a bit Smile

so I'll use
Code:
cd ..
to get to C:\ and list all files:

few commands you might need:

Code:
ls = lists all files in current dirrectory pwd = prints working dirrectory

[Image: snapshot4t.png]

now, usually, the website is in htdocs, lets search for it and go inside.

Once you are in, you might find "index.php" or something similar, you can download it by using command:
Code:
download index.php [where it should download]

then edit it on your computer and delete it from the victims computer by using:
Code:
del index.php

and uploading your edited page:

Code:
upload /root/index.php

Enjoy!!

PS: if you have any questions, feel free to post it here!

EDIT: Remember! There are some more secure LogMeIn networks, that allow connection only to one, defined host computer! In nets like this, you can't attack anyone unless you control the HOST! There are more kinds of nets and all behave a bit different, check official LogMeIn page for more info!
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: [TUT]Hamachi - Defacing a local webpage #2
So for this to work you and the target have to be connected to the vpn.... Once one machine on a network was connected to the VPN does that expose other machine on that subnet as well? Assuming I haven't been able to gain access to the remote machine within that group would I be able to scan the subnet for possible weaker links or is that not possible?

Reply

RE: [TUT]Hamachi - Defacing a local webpage #3
Can I try to penetrate TEST system on your created hamachi server?
I know I can,
Be what I wanna be,
If I work hard at it,
I'll be where I wanna be!!!
:thumbs:

Reply

RE: [TUT]Hamachi - Defacing a local webpage #4
(05-01-2011, 02:57 AM)thegreatbeast666 Wrote: So for this to work you and the target have to be connected to the vpn.... Once one machine on a network was connected to the VPN does that expose other machine on that subnet as well? Assuming I haven't been able to gain access to the remote machine within that group would I be able to scan the subnet for possible weaker links or is that not possible?

Imagine the hamachi group as a LAN. That means that everybody in the group can be hacked the same way as you would hack others in your LAN group.

However, you can't hack anybody in their LAN, that means that the only vulnerable computers are in the hamachi network.

anyway I'm trying to find a way around it Smile

(05-01-2011, 11:48 AM)S1lentZ Wrote: Can I try to penetrate TEST system on your created hamachi server?

Yes, but first of all I would like to secure the network a bit to prevent people from causing bigger harm Smile I will offer then some TEST machines so people can train legally Smile
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: [TUT]Hamachi - Defacing a local webpage #5
OK, waiting for your TEST machines Smile
I know I can,
Be what I wanna be,
If I work hard at it,
I'll be where I wanna be!!!
:thumbs:

Reply

RE: [TUT]Hamachi - Defacing a local webpage #6
I think I figured it out. When you hook to the VPN you may be assigned that subnet but that does not remove you from your own network resources. If you are able to spawn a metasploit shell then I think I could go a few different routes to get what I want. First, I could create a script that gathered network resource information easy enough. But that information isn't likely to give me much info if those IP's are private and served on a closed network. Still, being able to execute commands on the host could open up a lot of possibilities for automating information gathering. Better yet, you were to create a remote desktop we could attempt to access resources that way.
BUT I think the best solution would be to create a direct vpn between you and the host. This would give you access to that subnet. Now, I know that metasploit PRO offers a service that does this but for how much it costs F*** that. with a little research I see that there is a lot of open source code for vpn's. I had been working on another USB based device project but I think this one is greater. I am low on resources right now but once I get a few test machines up and running I will make this happen. (Or burn...) I will be sure to post my results if I ever get them. I thought I would share though and maybe someone else might get it first the only language I know is C# and a little java so it will be difficult :0) that's all for now

Thank you 1llusion for the great post, its given me a lot to think about.

Peace
O one more thing, I havent been able to use it yet because of the above mentioned resources issue but pass the hash might work for this also once you have the other remote address.

Reply

RE: [TUT]Hamachi - Defacing a local webpage #7
(05-02-2011, 05:32 AM)thegreatbeast666 Wrote: I think I figured it out. When you hook to the VPN you may be assigned that subnet but that does not remove you from your own network resources. If you are able to spawn a metasploit shell then I think I could go a few different routes to get what I want. First, I could create a script that gathered network resource information easy enough. But that information isn't likely to give me much info if those IP's are private and served on a closed network. Still, being able to execute commands on the host could open up a lot of possibilities for automating information gathering. Better yet, you were to create a remote desktop we could attempt to access resources that way.
BUT I think the best solution would be to create a direct vpn between you and the host. This would give you access to that subnet. Now, I know that metasploit PRO offers a service that does this but for how much it costs F*** that. with a little research I see that there is a lot of open source code for vpn's. I had been working on another USB based device project but I think this one is greater. I am low on resources right now but once I get a few test machines up and running I will make this happen. (Or burn...) I will be sure to post my results if I ever get them. I thought I would share though and maybe someone else might get it first the only language I know is C# and a little java so it will be difficult :0) that's all for now

Thank you 1llusion for the great post, its given me a lot to think about.

Peace
O one more thing, I havent been able to use it yet because of the above mentioned resources issue but pass the hash might work for this also once you have the other remote address.

wow nice post, I'll definetly think about it. My idea right now was to write a network worm, that would deliver a backdoor payload and giving you access to the computer through HTTP (like mirkov4 or any other HTTP bot does) also, I have found a LogMeIn hamachi 0day, so the worm could actually spread through LogMeIn. From there, if it would try atacking random hosts, you would get effect similar to the SLAMMER worm since, in theory, people are connected to more then 1 hamachi subnet. Maths take over here Tongue Smile
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: [TUT]Hamachi - Defacing a local webpage #8
WOW very nice 1llsuion. I would give you like 50 reps if i can awsome.

Reply

RE: [TUT]Hamachi - Defacing a local webpage #9
(05-03-2011, 12:16 AM)enc0de Wrote: WOW very nice 1llsuion. I would give you like 50 reps if i can awsome.

Lol thanks =)
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: [TUT]Hamachi - Defacing a local webpage #10
So did you bought this hamachi software coz as far as I seen on net it is not free.

Reply