sexta-feira, 7 de dezembro de 2012

unable to contact ip driver error code 2 [FIXED]

Step #1 ----------------------------------------------------------------------
These steps are copied from http://support.microsoft.com/kb/325356
11. Locate the Nettcpip.inf file in %winroot%\inf, and then open the file in Notepad.
12. Locate the [MS_TCPIP.PrimaryInstall] section.
13. Edit the Characteristics = 0xa0 entry and replace 0xa0 with 0x80.
14. Save the file, and then exit Notepad.
15. In Control Panel, double-click Network Connections, right-click Local Area Connection, and then select Properties.
16. On the General tab, click Install, select Protocol, and then click Add.
17. In the Select Network Protocols window, click Have Disk.
18. In the Copy manufacturer's files from: text box, type c:\windows\inf, and then click OK.
19. Select Internet Protocol (TCP/IP), and then click OK.
Note This step will return you to the Local Area Connection Properties screen, but now the Uninstall button is available.
20. Select Internet Protocol (TCP/IP), click Uninstall, and then click Yes.
RESTART

succesfull uninstallation of TCP/IP will remove numerous keys from the registry including
HKLM/system/CurrentControlSet/services/tcpip
HKLM/system/CurrentControlSet/services/dhcp
HKLM/system/CurrentControlSet/services/dnscache
HKLM/system/CurrentControlSet/services/ipsec
HKLM/system/CurrentControlSet/services/policyagent
HKLM/system/CurrentControlSet/services/atmarpc
HKLM/system/CurrentControlSet/services/nla
These represent various interconnected and interdependant services.

For good measure you should delete the following keys before reinstalling TCP/IP in step #2
HKLM/system/CurrentControlSet/services/winsock
HKLM/system/CurrentControlSet/services/winsock2

Step #2
Reinstall of TCP/IP
----------------------------------------------------------------------
Following the above substep #13, replace the 0x80 back to 0xa0, this will eliminate the related "unsigned driver" error that was encountered during the uninstallation phase.

Return to "local area connection"> properties > general tab > install > Protocol > TCP/IP

You may receive an "Extended Error" failure upon trying to reinstall the TCP/IP, this is related to the installer sub-system conflicting with the security database status.

to check the integrity of the security database
esentutl /g c:\windows\security\Database\secedit.sdb

There may be a message saying database is out of date
first try the recovery option
esentutl /r c:\windows\security\Database\secedit.sdb

this did not work for me, I needed the repair option
esentutl /p c:\windows\security\Database\secedit.sdb

rerun the /g option to ensure that integrity is good and database is up to date.

Now return to the "local area network setup"
choose install > protocol > tcp/ip and try again

sexta-feira, 30 de novembro de 2012

PSEXEC on Windows 7: Access is denied

PSEXEC is a sysinternals tool that can be very useful for system administrators to inject commands into a remote machine, needless to say, this opens an interesting possibility for the hacking enthusiasts out there hehe

To run the command line on a target XP machine on which you have the user and password for the Administrator account, this would be the code:

psexec \\TargetMachine-u Administrator -p Password CMD

Voila, i'm in as simple as 123, now i can send any kind of commands, start, stop services etc.


PSEXEC on Windows 7: Access is denied.


PSEXEC in Windows 7 requires elevation, so before running the command, make sure you are running CMD as Administrator and then enter this command to run CMD on the TargetMachine:

psexec -h -s \\TargetMachine -u Administrator -p Password CMD


Domain users can run CMD as Administrator by pressing SHIFT + RIGHT mouse button (RMB) over CMD so you can "Run  as a different user":


Authenticate:





And now run the command:

psexec -h -s \\TargetMachine -u Administrator -p Password CMD

This will run the remote command on the SYSTEM account. Note that admin$ must be available.


Congrats, you just learned an interesting thing today.