Harris Cushman
Time to complete this lab was: 30 Minutes
Module 2 Lab
1. GetAcct
The GetAcct software is an enumeration tool created to retrieve sensitive information
about users and accounts. For a malicious actor, this would be an ideal tool to have had for the
reason that the program is capable of identifying private data regarding a user’s computer, which
could be harmful and exploited. The data that can be obtained from the Get Acct software can
make critical data such the user's ID, account names, password policies, and user groups are
visible. If a malicious actor can acquire portions of the data that the GetAcct exposes, the data
could be used to penetrate an organization or user’s assets.
While the application itself appears to be harmless, a malicious actor could use the
application to collect sufficient data to shape and redistribute the policies of the network. In
identifying information such as account names and password policies, a hacker would have the
capability to design password crackers or brute force measures in attempting to penetrate the
system. In obtaining legitimate account credentials, a hacker would be unrestricted to explore the
breached system undetected, integrating with normal network traffic. In having the ability to
know group policy standards could aid a hacker in installing their device on the network and run
unidentified to system administrators; gathering and delivering valuable organizational or user
data.
I believe that the GetAcct does not function due to being outdated and there were security
patches that have been implemented in correcting the vulnerability that GetAcct exposed. In
searching GetAcct on the internet, I discovered that the GetAcct software sidesteps the
"RestrictAnonymous=1" and obtains account information on Windows NT/2000
machines[Azb01]. In conclusion, I believe GetAcct operated under good functionality at one
time but is no longer a viable application. I was able to launch the program and input the victims
IP address but did not receive any data regarding the victim. Additionally, when I attempted to
run the executable file that was included in the zip file, it failed, and an error message was
displayed. While GetAcct may not be commonly used as before, other software applications are
similar and can be just as dangerous or as useful a tool to hackers. I believe the original purpose
of GetAcct was a beneficial and practical tool for users and security professionals who needed to
understand additional information about network and system.
2. SuperScan
SuperScan is an enumeration and scanning application to detect open ports and services
on a target system. Once SuperScan has been installed, the user has many options to choose from
in the types of scanning needed. There is a scan function that can be performed with just the IP
address of a targeted machine. In the Scan tab of the application, submitting the IP address will
detect open ports and notify the user as to what identifiable services are being run on those open
ports. SuperScan also has an enumeration function that is capable of scanning the targeted
system that can list a variety of relevant information such as NetBIOS information, users and
groups, password and account policies, shares, domains, and remote services and registry items.
When the enumeration function is opened, the user can select a list of checkboxes for the
types of information to be included in the enumeration scan. The list contains several of the
options as previously listed as well as MAC addresses, workstation type, and NULL or Logon
sessions. Upon submitting the Victim’s computer IP address, a list was displayed with all the
NetBIOS information showing the hostname (343-Victim-VM) along with the group this account
is associated with (WORKGROUP). Following the NetBIOS information was MAC address
information and NULL session information. Having the MAC address is important due to the
address containing information like the manufacturer of a network interface. This information
could allow an attacker to circumvent security policies that have been based upon MAC
authentication or the ability to spoof the device on the victim’s network. Having a NULL session
is significant due to the fact that hackers can gain access to passwords, groups, services, users,
and active processes. This single scan tells the attacker this may be a prime target in gaining
access to the system that was scanned.
SuperScan is software that was designed for legitimate purposes but can also be operated
for malicious intentions when in use by criminals. Information Security professionals can benefit
from implementing this tool, as the application exposes potential vulnerabilities and assists in
patching those vulnerabilities before a security failure or breach can occur. Additionally,
knowing what this application can do allows professionals the understanding as to the tools
available to hackers in their attempts to penetrate a system.
3. FreeNetEnumerator
FreeNetEnumerator is an enumeration tool that is designed to enumerate computers in a
domain. This software is a simple to use application that can scan a domain for connected
computers, revealing a comprehensive list of all the computers that it finds. After launching the
application, the box for all computers was marked, and the “Enumerate” button was entered.
Instantaneously, information about the Victim and Attacker computers were displayed providing
fundamental information such as hostname, platform, Operating System (OS), comments, and
service (showing Windows NT/2000 for Attacker). One of the critical functions of the
FreeNetEnumerator is its ability to filter what data is searched for concerning additional devices.
In this module, the instructions were to search all computers and devices, but with the filter, there
is the ability to view only certain and specific devices within the domain, such as SQL servers,
domain controllers, LAN manager workstations, and print sharing servers.
Even though this tool is not as penetrating as the other applications, FreeNetEnumerator
does give information about the systems being used and the ability to map the network. Knowing
this type of information can permit hackers to employ other data collection tools in their pursuit
to breach their target. In having the ability to identify the OS one can recognize how current
systems are that are within the network. This information could be instrumental when it comes to
protecting critical data or network assets and allow security professionals the ability to secure
those devices then.
FreeNetEnumerator is alternative software that is useful and easy to use without going
through a more complicated route to identify users or devices. While this software does not
display nearly as much private data on a user as other software, this could be all the data a hacker
could require to carry out certain tasks in furthering their agenda. Cybersecurity analysts should
be attentive to the fact that this software can be used by anyone. Additionally, the information
that this tool provides can be an wonderful for an organization in there monitoring
documentation functions
fisszseise.200°
flow
xe
ccot
ter
eer)
Preteen
ny
00.00
Piearary
(none)
Peace
conn]
Ponta
eae
Terres
reer
iro
Berg
Sg
cc
Sed
OFS
Sid
&
8)
wont
DOWEL
lt
DB
a)
ron
cr
O
dye
here
to
search
4]
.
Appendix A
Appendix B
So
Ei
©
type
here to search
Cece
recs
Paras
Pars
eran
Patri
Very
eer
er)
0090
rao)
ora)
PEN
TY
eae
ery
Cy
Bo
ite
and
Fol
ay
rene
Gh
Hove
3
coy
Quis
Benaiy|
X
dei
‘ther
ae
©
wu
Dove
Gained
2B
vc
ym
Sect
wien
owrioad
Hare
IF
tongue
Mion
SOL
Serves
[~
Pray
domain
conkers
(POC)
[~
Backup
domain
corte
(BOC)
TF
Seve
ssrosit
aise
[-
Severna
diinservce
I
UN
Manaoewottatine
[Envomae
Iettctne
SesaT
TAKERS
[tom
it
Puro
lasers
Wome
x?
[Sewce
Whdows
NT
Windows
2000
wa
ttn
serve
Iettstrnseavicrn
vn
Piste
if
Paton
las
Mosca
wow
x?
[SeveMane
tonsa
sce
Tr
Si
Appendix C