Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Brute force Terminal Server


BluePain's Avatar
Member
0 0

Hello, nice to meet you all. To go right to the case… Is it possible to brutforce a Terminal Server. Because back home I have a Windows 2003 server and it have a TS service that I would like to test out. I found this prog called tsgrinder that use a diconary to look for the password. But is it possible to Brutforce it?

I would be wery happy if somone could answer my question :) ps: Sorry for my very bad english. :(


nanoymaster's Avatar
the master of nanoy(.org)
0 0

I'm not 100% sure of your question. But it might be worth giving brutus a try it is usually used for bruteforcing telnet. Just an idea


BluePain's Avatar
Member
0 0

I am sorry if you dident understand my qustion. What I ment to say was that I would like to test out the security on server. And as most Windows 2003 server they have the reomte descop service that you can enter frome the internett our frome a local Pc. And this service did make me wonder. How secure is it. What can I do to find out the pasword on the Admin account? So I startet to test out different things. The best way I did find was to use a dictonary atack to send out and test paswords on it because there are no security that throw you out of the system if you fail. But this do not allways work becasue if you have a password like this "h64fh4i33y2" are there bout numbers and letters that are not in the dictonary. So brutforce is the only way. Is there som program that can brutforce a TS server? Our is there som other options her like taking the hash our somthing? Thanks for all the answers.

The Brutus dident work so well. It are used to take out telnet server. And I dont use that. But thanks anyway :D


ghost's Avatar
0 0

One thing to note, in Microsoft's NTLM hashing, /#@!%^&*($\"' – All valid characters in a password. I don't remember per se how many there were, but iit would increase your password security by n^l, where n is the number of valid input characters, and l is the length of the password.

Of course, anything can be cracked, given time and intelligence.


BluePain's Avatar
Member
0 0

Zekasu wrote: One thing to note, in Microsoft's NTLM hashing, /#@!%^&*($\"' – All valid characters in a password. I don't remember per se how many there were, but iit would increase your password security by n^l, where n is the number of valid input characters, and l is the length of the password.

Of course, anything can be cracked, given time and intelligence.

Yes, that wy I keep trying :) But if brutforce is out. What other possibilitis do I have to crack/hack my Windows 2003 server?