How to hack ISA server: ISA SERVER As far as i could find there are two ways to bypass the ISA server one is to fool the server into thinking that you are visiting a "non-blocked" site and the other is to hack into their server machine and create an explicit filter to give your user id permissions certain site/port access. The latter can land you in trouble and get you thrown out of college/office so don't blame me :)

Here are a few steps that you can try for the former:

1. Use a proxy : There are plenty of free working public proxy servers, you can google them up and use them. eg. http://www.publicproxyservers.com/page1.html Chances are many of these sites are blocked too so you might have to try a few to get a working one.

2. Use anonymizers : You will find plenty of anonymizer sites which you can use, you need to serach for a site that is not blocked by your proxy.

3. Use alternate web urls : Like if yahoo mail is blocked, you can use the wap portal http://wap.oa.yahoo.com If nothing works and if you deem it worth to hack into the server machine then :

1. Get network admin rights (this comes handy for many other things too, not jus etting into isa server ;) ) I am not going to give you all the steps (too lazy to type all that, so as long as they come up with a perfect voice recognize engin) i can give you hints and you can google the rest up,

a. You need local admin rights on a pc on the n/w ( am assuming u are on a win2k m/c , domain based newtork) You can achieve this by : there are linux based tools that can boot your pc and reset the ram, or boot with win98 and remove ram or brute force the password with l0pht, there are plenty of other ways too.

b. now that u have local admin rights, install admin pack on the m/c , you will find this on a win2k/2k3 server cd or u can download it from the net

c. now login to the machine without a username! easiest way is edit the registry to display cmd.exe instead of the logon screensaver and run explorer.exe and you should be in without a username login.

d. run the domain users control from control panel and promote ur self to network admin or isa admin (if there is one), tip : if u find a user group with urestricted access to inet add urself to it (better still create a dummy user that u can login as this would save u from going through the rest of the steps

2. Once u have network/isa admin rights use terminal server or any remote desktop client to connect to the isa server m/c, if you dont know which m/c is your isa server its the ip u see on ie when you try to access a blocked web page.

3. Once your in the server open the isa admin console, you will find plenty of pre defined and user defined filters that block sites , domains and ports and you will find a default filter that lets u access all. Add this filter to your username(only!!) and activate it. You can also create a user defined filter based on what site or ports you want open eg., Now your good to go !


Like it on Facebook, Tweet it or share this article on other bookmarking websites.

No comments