<?xml version="1.0" encoding="utf-8"?><!DOCTYPE article  PUBLIC '-//OASIS//DTD DocBook XML V4.4//EN'  'http://www.docbook.org/xml/4.4/docbookx.dtd'><article><articleinfo><title>BruteForce_ssh</title><revhistory><revision><revnumber>29</revnumber><date>2008-03-18 17:28:22</date><authorinitials>localhost</authorinitials><revremark>converted to 1.6 markup</revremark></revision><revision><revnumber>28</revnumber><date>2007-03-31 12:36:46</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>27</revnumber><date>2007-03-31 12:34:45</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>26</revnumber><date>2007-03-31 12:34:23</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>25</revnumber><date>2007-03-31 12:02:21</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>24</revnumber><date>2007-03-31 12:00:41</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>23</revnumber><date>2007-01-12 18:06:35</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>22</revnumber><date>2007-01-12 18:05:26</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>21</revnumber><date>2007-01-12 18:02:47</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>20</revnumber><date>2007-01-12 18:00:23</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>19</revnumber><date>2007-01-12 17:58:59</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>18</revnumber><date>2007-01-12 17:57:52</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>17</revnumber><date>2007-01-12 17:54:45</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>16</revnumber><date>2007-01-12 15:30:59</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>15</revnumber><date>2007-01-12 15:29:59</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>14</revnumber><date>2007-01-12 15:23:32</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>13</revnumber><date>2007-01-12 15:23:22</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>12</revnumber><date>2007-01-12 15:20:43</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>11</revnumber><date>2007-01-12 15:19:52</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>10</revnumber><date>2007-01-12 15:17:38</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>9</revnumber><date>2007-01-12 15:17:02</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>8</revnumber><date>2007-01-12 15:11:42</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>7</revnumber><date>2007-01-12 11:15:19</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>6</revnumber><date>2007-01-12 10:46:34</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>5</revnumber><date>2007-01-12 10:45:09</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>4</revnumber><date>2007-01-12 10:41:08</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>3</revnumber><date>2007-01-12 10:40:21</date><authorinitials>ac3bf1</authorinitials><revremark>\</revremark></revision><revision><revnumber>2</revnumber><date>2007-01-12 10:28:08</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>1</revnumber><date>2007-01-12 10:21:14</date><authorinitials>ac3bf1</authorinitials></revision></revhistory></articleinfo><section><title>Brute Force ssh (per n00b)</title><section><title>Programmi e File Necessari</title><para><emphasis role="strong"> NON </emphasis> è necessario scaricare tutti i file. Leggere <emphasis role="strong"> ATTENTAMENTE </emphasis> le descrizioni! </para><itemizedlist><listitem><para>Scegliere <emphasis role="strong"> 1 </emphasis> fra i seguenti file: </para><itemizedlist><listitem override="none"><informaltable><tgroup cols="4"><colspec colname="col_0"/><colspec colname="col_1"/><colspec colname="col_2"/><colspec colname="col_3"/><tbody><row rowsep="1"><entry colsep="1" rowsep="1"><para> <ulink url="http://www.ac3bf1.org/files/sec/all_merged.tar.gz">all_merged.tar.gz</ulink> </para></entry><entry colsep="1" rowsep="1"><para> <ulink url="http://www.ac3bf1.org/files/sec/all_merged.zip">all_merged.zip</ulink> </para></entry><entry colsep="1" rowsep="1"><para> (<emphasis role="strong">~20MB!</emphasis> - 67MB scompattato) </para></entry><entry colsep="1" rowsep="1"><para> - Molteplici password </para></entry></row><row rowsep="1"><entry colsep="1" rowsep="1"><para> <ulink url="http://www.ac3bf1.org/files/sec/common_merged.tar.gz">common_merged.tar.gz</ulink> </para></entry><entry colsep="1" rowsep="1"><para> <ulink url="http://www.ac3bf1.org/files/sec/common_merged.zip">common_merged.zip</ulink> </para></entry><entry colsep="1" rowsep="1"><para> (~6.5MB - 18MB scompattato) </para></entry><entry colsep="1" rowsep="1"><para> - Selezione di password comuni </para></entry></row></tbody></tgroup></informaltable></listitem></itemizedlist></listitem><listitem><para>Programma necessario: </para><itemizedlist><listitem override="none"><para><ulink url="http://www.ac3bf1.org/files/sec/guess-who-0.44.tgz">guess-who-0.44.tgz</ulink> (16.1 KB) - Programmino Linux per svolgere il brute Forcing </para></listitem></itemizedlist></listitem><listitem><para>In caso si voglia creare dei file con le password più personalizzati scaricare il seguente programma </para><itemizedlist><listitem override="none"><para><ulink url="http://www.ac3bf1.org/files/sec/uumerge.zip">uumerge.zip</ulink> (55.1 KB) - Programmino Wind0ws per fare il merge di file di testo </para></listitem></itemizedlist></listitem><listitem><para>Archivi con le password in file separati </para><itemizedlist><listitem override="none"><para><ulink url="http://www.ac3bf1.org/files/sec/common.tar.gz">common.tar.gz</ulink> | <ulink url="http://www.ac3bf1.org/files/sec/common.zip">common.zip</ulink> (35 file - 6322.2 KB) - Archivio con diversi file di testo non uniti in un unico file<emphasis role="strong">(~6MB)</emphasis>  </para><para> <ulink url="http://www.ac3bf1.org/files/sec/all.tar.gz">all.tar.gz</ulink> | <ulink url="http://www.ac3bf1.org/files/sec/all.zip">all.zip</ulink> (46 file - 19130.5 KB) - Archivio con diversi file di testo non uniti in un unico file <emphasis role="strong">(~20MB!)</emphasis> </para></listitem></itemizedlist></listitem></itemizedlist></section><section><title>Procedura</title><para>Se si vuole creare i file con le password manualmente, scaricare <ulink url="http://www.ac3bf1.org/files/sec/common.tar.gz">common.tar.gz</ulink> (6322.2 KB) o <ulink url="http://www.ac3bf1.org/files/sec/all.tar.gz">all.tar.gz</ulink> (19130.5 KB) a seconda di quante password si vogliano avere per il brute forcing, e <ulink url="http://www.ac3bf1.org/files/sec/uumerge.zip">uumerge.zip</ulink> (55.1 KB) che gira sotto Wind0ws (alternativa linux?) per fare il merge dei file che si vuole. </para><para> In seguito scompattare guess-who-0.44.tgz e digitare solamente <code> make </code> per compilare </para><para> Il <code> Makefile </code> ha come nome di output <code> b </code>, quindi basta digitare <code> ./b </code> per avere una lista dei comandi. </para><para> Esempio di comando </para><screen><![CDATA[./b -l LOGIN -h IP/DNS -p PORTA -2 < PASSWORD_FILE]]></screen><para>rimpiazzando: </para><para> LOGIN con il login che si desidera usare per il bruteforce </para><para> IP/DNS con l'indirizzo IP del computer &quot;vittima&quot; da testare </para><para> PORTA con la porta ssh (di solito 22) </para><para> PASSWORD_FILE con il percorso completo del file con le password. </para></section></section></article>