User manual

63
Penetrate (
): PhoneSweep attempts bruteforce (guess) username/password combinations on
systems it was able to Identify. If successful, PhoneSweep will immediately hang up and go no
further.
Control what PhoneSweep will scan for (All Levels of Effort):
Both Modems and Fax Machines where Phone Sweep will call twice to search for Fax/Modem lines
(Voice and other lines called once).
Modems only where PhoneSweep will call each line just once as it searches for just modems.
Fax Machines only where PhoneSweep will call each line just once as it searches for just fax
machines.
Fine-Tune Penetrate Level of Effort (Penetrate sub- options), telling PhoneSweep to:
Recycle username/password combinations (Try to use every username/password at every modem it
encounters).
Find Modems First, where PhoneSweep will first sweep all phone lines in its search for modems
before returning (going back) to brute-force the modems it found. Otherwise, PhoneSweep will
attempt to brute-force each modem as it finds them.
Limit guesses or calls in a given day, to avoid being locked out of systems.
View and edit the username/password list.
See Section 10.1 “Expected Sweep Result Charts”, for additional details on PhoneSweep results when
scanning with and without Single Call Detect at various Levels of Effort, and when scanning for both fax
and modems, modems only and fax machines only.
4.6.1 What does PhoneSweep do at each level of effort?
Connect: PhoneSweep identifies each device by sound or tone alone so that no exchange of
data occurs: As PhoneSweep makes each call it listens and classifies each line, according to the
sounds it hears, including if an answering device and whether or not it is a Carrier or Fax, and
then, PhoneSweep immediately hangs up.
Identify: If PhoneSweep finds a modem, it attempts to determine the type of system that
modem is attached to. An actual exchange of information occurs at this level (electronic
handshake). This may involve sending some information to the remote device, most likely
carriage returns.
Penetrate: PhoneSweep returns to each modem it has found and attempt to break into the
remote system with a brute-force username/password guessing attack. At this level,
PhoneSweep not only performs the initial electronic handshake with each fax or modem, but also
attempts to exchange logon information with any system it encounters, providing bruteforcing
information is known by Sandstorm about that system.
Each successively more invasive “level of effort,” includes all less invasive levels by default. So, when
you identify remote systems, PhoneSweep must first connect to them. If you set PhoneSweep to
Penetrate, it will also connect and attempt to identify before attempting to break into the system.
Please note, that with regards to PhoneSweep and System Identification, PhoneSweep should not affect
systems. In rare instances; however, some systems cause PhoneSweep to freeze. In even rarer instances,
the box PhoneSweep is on will freeze.