Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Czech
Danish
Dutch
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
In a previous video we discussed SS H and that it's really not always that much of a low hanging fruit.
So we've got SS h here and say we want to attack it.
Now there are three reasons we're going to do this and this is from a realistic perspective.
If we see SS H on an assessment we're going to try to brute force against it or use weak or default
credentials and we're going to do that because one we're going to test password strength too we're going
to see if we can get in with a weak password or default password.
And if we can also attest to password strength correct and 3 we're going to see how well the blue team
performs.
Do they catch us.
Do they see us brute forcing this should be something that should alert when is being performed.
But you would be surprised how often it does not.
So during a pen test I am as loud as possible.
This is not a red team assessment where we're trying to be quiet.
This is a pen test where we are as loud as possible and we are hoping to be caught.
Sometimes just it or just told to tone it down a little bit you know hey we're seeing you.
Can you be more quiet.
And we just want to be caught some time so we can give kudos in a report and say Hey you saw scanning
here and here and kudos to you but you didn't see a scanning here in here.
So this is how we really help fine tune a blue team and help fine tune a client as well is being loud
sometimes.
So we're going to practice being loud today and we're also going to practice brute force attacks and
we have the perfect opportunity to do that with an essay sage port being open on this machine.
So what we're gonna do is we're going to use a tool called the Hydra and then I'll show you the Midas
plate way as well.
So Hydra is a brute force tool.
So the syntax for Hydra is going to be this.
We're gonna say a Hydra and then we're going to give a dash L for the user that we're going to be utilizing
in this case.
I want to attack root and then we're going to give a capital P for the password list.
So if we want to use a password list with L we can just say capital L but here we're going to say capital
P for the password list and then we're just gonna say user share wordless Metis ploy.
And I'm just going to double tab in this folder so you can see how many words are actually in here.
There's quite a bit of wordless and you can space space and it has wordless for all different kinds
of things built in and these are all over Cally.
So it's good to know your folder locations but user shareware list is one that will use quite a bit.
And what we're going to do is we're going to utilize an attack with these Unix passwords here.
We have a Unix users in Unix passwords.
We're going to utilize the Unix password list and just try to brute force with that.
So we'll say Unix passwords something like that and then we're going to need to specify what we're attacking.
So we are attacking SS h like this and our IP address of our machine or attacking port 22 and then we
need to have a certain amount of attempts or threads at once and we're going to limit that to four and
then I'm going to do a capital V for verbosity just because I want to see the user attempts flow through
so that we can actually see what's going on here.
So once you got the syntax ready to go go ahead and hit enter and you're going to see that it's starting
to attempt root log in password with all these weak passwords here and hopefully it might find something.
But let's go ahead and open up a a new terminal here.
And we're going to use make this a little bigger and I'm going to load up Mets played as well.
Yeah we're gonna run the same exact thing in Mets point but I think it's good to know multiple frameworks
and multiple tools to perform the same task.
So here we're going to search for something like SSD age and this is going to be an auxiliary module
so we'll just scroll up and we're going to look for something like SSA to log in perfect log in and
check scanner and make sure we don't have anything else.
And it looks good to me.
Let's go ahead and take this SSA log in and we're gonna go ahead and say use options
and now we have kind of our brute force options here.
Let me make this a little bigger sense prettier so we've got a brute force speed from zero to five five
being the fastest dribbling passwords.
No no no.
We can set a hard password and we could set a hard user name.
We could set a user and password file a user pass user as password file again.
We can have a password file as well.
So we have a lot of different options here that we can utilize but we're gonna go ahead and do the same
kind of thing we're going to say set user name and we're just gonna say room and then we're going to
say set pass file and similar to what we just use.
We're gonna say user share wordless Meadows flight and then we're going to say lyrics
unique sorry Unix passwords and that should set the pass file and then we just seen our host as well
set our host and we'll say 1 9 2 1 6 8 5 7 1 3 4 say options one more time and you can see that we've
got our password file set we've got our our host set we've got our our port on twenty two threads is
one username route and we should be good to go now we can set multiple threads here we could set threads
to like 10 this is really going to amp it up I mean this should be detected in a second but we're gonna
try to run it and we could set actually let me control see let's set verbose to true as well just so
you could see that it's actually working set verbose to true and then we're gonna run this and then
it's going to attempt different credentials here and it'll say Hey I found it in the light up green
and then we'll know it's good.
So this is actually going kind of slow surprisingly and you can see here that we are at attempt 112
116.
So this is out also going slow and we do not have a successful attempt or a log in I actually don't
believe there's going to be one but you never know.
I believe I remember taking this off line and trying to crack the password and wasn't any kind of weak
password.
So you can let your brute brute force run if you want to go with it but I'm going to go ahead and kill
mine and that's it for this video.
So from here we're going to talk about a similar methodology called credential stuffing which we've
already talked about before except we're not brute forcing but we're using common knowledge to our advantage.
So we'll talk about a little bit of Chris stuffing in the next video.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.