Accessing the bindery files directly
3 November 1995
Accessing the bindery files directly
Alastair Grant, Cambridge University
1. Introduction
This document describes a command for accessing the NetWare 3.x bindery
files directly, bypassing the NetWare network API calls.
It can be used for fast bindery access, bulk user management, bypassing
security restrictions, investigating problems etc.
It is quite possible to destroy the bindery completely, or to reveal
information which could be used by hackers to obtain passwords. Users
are assumed to have a basic grasp of good procedures for security and
backup.
2. Command syntax
The basic format of the command is
bindery [options] bindery-spec action action ...
2.1 Specifying a bindery
A bindery specification takes the form
path/.extension
E.g. SYS:SYSTEM/.SYS. The path defaults to the current directory. The
extension defaults to .OLD.
Alternatively an 'active' bindery can be specified:
SERVER server
The bindery will be closed if necessary.
2.2 Actions on the bindery
INFO print info about the bindery
SCHEMA checks the bindery against the schema in BINDERY.SCH
DUMP obj dump all information for the specified object(s)
OBJ list all object records
PROP list all property records
VAL list all value records
VALDATA list all value records, with data
EXPORT export the bindery to a text file; see below
IMPORT import the bindery from a text file
ETC export user password information, suitable for input to the
password-cracking program described below
The following actions apply only if a bindery has been specified by the
SERVER parameter:
CLOSE close the bindery, i.e. make it available for direct access;
users attempting to access the bindery via NetWare API calls
will receive an error
OPEN open the bindery, which causes the server to reload it and
may take some time for large binderies
COPY directory
copy the bindery files into a directory elsewhere
3. Export/import
The bindery can be exported to and imported from a text file. This can
be used for various purposes:
- problem diagnosis and repair
- creation of large binderies given a set of user information
- compaction of binderies
- merging binderies or moving users between binderies while
preserving their passwords
To see the format of the export file, try exporting a small bindery.
4. Password cracking
Passwords are not stored in clear in the bindery. What is stored is a
16-byte value computed via a one-way function from the user's object id
and the password. Given the object id and password it is possible to
generate a candidate password which can be compared against that in the
bindery.
The ETC option of the BINDERY command produces a file containing the
required information, in a format superficially similar to /etc/passwd
on Unix:
userid:pw-hash:object-id:pw-len:name::
e.g.
ttidy:32d8998e098a05830f809b809ea02137:D0000001:8:Terry Tidy
This can then be input into bindery cracking programs. Separating the
functions in this way allows various forms of parallelism:
- the password file can be split into smaller chunks
- the same password file can be worked on by several cracking
programs each with different dictionaries or algorithms
- cracking programs can be run on faster machines
A cracking program BINCRACK is provided which takes such a file as
input. It has command syntax:
bincrack [/verify] [/numsub] pw-file dict-file
/verify lists the passwords that are being tried. /numsub tries
substituting numbers for letters, e.g. "1D10T". This takes a lot longer
as all possible combinations are tried. pw-file is an exported bindery
password file. dict-file is a simple word list.
Versions are available for MS-DOS and for Solaris 1 and Solaris 2 SPARC
systems.
Suitable wordlists can be found at
ftp://ftp.ox.ac.uk/pub/wordlists/
Disclaimer:-
i am not liable for any criminal or bad thing which you have done using this message and document. i am giving here for the educational purpose and care should be taken from your side before using this document and please get a written permission from the person before hacking or doing some thing in the network or system.This document is intended for judicial or educational purposes. I have collected these documents and messages from the internet for educational purpose only. always use these documents for doing good only. I don't want to promote computer crime and I'm not responible of your actions in any way. If you want to hack a computer, do the decent thing and ask for permission first. please read and use this for useful purpose only to protect the systems and information from the bad people. always seek permission from the system owner or who ever responcible for the system by written and then go ahead. Give a full report with honestly to the person or company about your experiments and findings from the system. Always Do Good Think Good and Belive Good.
i am presenting here, what are all i am reading and what are all experiences which I got. i am just sharing here. வணக்கம்....நான் விவேக்.. இங்கு எனக்கு கிடைத்த தகவலும் .. என்னை கவர்ந்த செய்திகளும் உங்களுக்கு தருகின்றேன் ...
Subscribe to:
Post Comments (Atom)
How to Get files from the directory - One more method
import os import openpyxl # Specify the target folder folder_path = "C:/Your/Target/Folder" # Replace with the actual path # Cre...
-
http://podian.blogspot.com/ One of the Good blog in Tamil so you can read current news also.
-
ஸ்ரீ இராம நாம மந்திர மகிமை 🌷 1. நமக்கு நன்மை வரவேண்டுமானால் 'ராம நாமத்தை இடைவிடாமல் கூறவேண்டும். நமது ஒவ்வொரு மூச்சும் ...
No comments:
Post a Comment