Saturday, 11 February 2017

acccheck

This tool is designed as a password dictionary attack tool, that targets Windows Authentication via SMB protocol. It's a wrapper script around 'smbclient' binary and as a result is dependent on it for its execution.

Server Message Block (SMB) Protocol is a network file sharing protocol and as implemented in Microsoft Windows is known as Microsoft SMB Protocol. The set of message packets that defines a particular version of the protocol is called a dialect. The Common Internet File System (CIFS) Protocol is a dialect of SMB. Both SMB and CIFS are also available on VMS, several versions of Unix, and other operating systems.

SMB can run on top of the Session Layer:
Directly over TCP, port 445;
Via the NetBIOS API, which in turn can run on several transports;
On UDP ports 137, 138 & TCP ports 137, 139 (NetBIOS over TCP/IP);
On several legacy protocols such as NBF (incorrectly referred to as NetBEUI).
The SMB “Inter-Process Communication” (IPC) system provides named pipes and was one of the first inter-process mechanisms commonly available to programmers that provides a means for services to inherit the authentication carried out when a client first connected to an SMB server.


The simplest way to run acccheck is a follows:

1. ./acccheck 198.168.10.1 
This mode of execution attempts to connect to the target ADMIN share with the username ‘Administrator’ and a [BLANK] for the password.

1. ./acccheck.pl -t 192.168.10.1 -u test -p test
This mode of execution attempts to connect to the target IPC share with the username ‘test’ and a password ‘test’.

Each -t, -u and -p flags can be substituted by -T, -U and -P, where each represents an input file rather than a single input from standard in.

E.g.
1. ./acccheck.pl -T iplist -U userfile -P passwordfile
Only use -v mode on very small dictionaries, otherwise, this has the affect of slowing the scan down to the rate the system writes to standard out.

Any username/password combinations found are written to a file called ‘cracked’ in the working directory.


3 comments:

  1. Hi Guy's

    Fresh & valid spammed USA SSN+Dob Leads with DL available in bulk.

    >>1$ each SSN+DOB
    >>3$ each with SSN+DOB+DL
    >>5$ each for premium fullz (700+ credit score with replacement guarantee)

    Prices are negotiable in bulk order
    Serious buyer contact me no time wasters please
    Bulk order will be preferable

    CONTACT
    Telegram > @leadsupplier
    ICQ > 752822040
    Email > leads.sellers1212@gmail.com

    OTHER STUFF YOU CAN GET

    SSN+DOB Fullz
    CC's with CVV's (vbv & non-vbv)
    USA Photo ID'S (Front & back)

    All type of tutorials available
    (Carding, spamming, hacking, scam page, Cash outs, dumps cash outs)

    SMTP Linux Root
    DUMPS with pins track 1 and 2
    WU & Bank transfers
    Socks, rdp's, vpn
    Php mailer
    Sql injector
    Bitcoin cracker
    Server I.P's
    HQ Emails with passwords
    All types of tools & tutorials.. & much more

    Looking for long term business
    For trust full vendor, feel free to contact

    CONTACT
    Telegram > @leadsupplier
    ICQ > 752822040
    Email > leads.sellers1212@gmail.com

    ReplyDelete
  2. ICQ 752822040
    TELEGRAM @killhacks

    Fullz & Toolz Available
    USA/UK/CANADA
    Good Credit Scores & fresh
    Spamming, Carding complete courses/Tutorials & Tools
    Hack-ing & Attacking
    24/7

    ICQ 752822040
    TELEGRAM @killhacks
    WICKR peeterhacks

    ReplyDelete
  3. Have You Ever Been A Victim to Scam⁉️
    Here Is What You Need To Do❗❕

    Contact PYTHONAX Immediately✔

    🔥 PYTHONAX are individuals that uses their skill in computing science to track down scammers using transactions records and communications contacts.

    If you have been a victim of any of this scam listed, you need to contact PYTHONAX-;
    ❌Cryptocurrency investments scams.
    ❌Buying and Selling scams.
    ❌Romance & Dating Scams.
    ❌Loan or Grant Scams. E.t.c.......


    📢 We do not require your personal information, You can remain anonymous when contacting us. We only want to help you get your money back, a few info would be required from you and if you can provide this info, we will do everything we can to help you.

    ℹ You need to understand that scammers are very careful when spending money they got from scamming people, the money has to be well cleaned and pass through a business in order for them to be able to put it in a bank account.

    ⚠️ Beware of individuals who impersonate us, and post false testimonials online or comment to lure you to them. We do not report or share stories of jobs we have done or taken. We keep info of every client discreet.

    📧 Contact PYTHONAX today using the emails below-:
    Pythonaxhelp@protonmail.com
    Pythonaxservices@protonmail.com

    ReplyDelete