XMCO : We deliver security expertise

  IMA


   all-in-one tool to audit accounts and passwords !


What is IMA ?

IMA (Identity Management Auditor) is a GUI tool that provides an all-in-one tool to audit accounts, authorization and passwords

Features

  • Assess and crack Microsoft Windows passwords (LM, NTLM, Microsoft SQL Server), ORACLE and Lotus Domino (and others...)
  • John-The-Ripper pot import capabilities
  • Able to evaluate passwords strength : trival, weak or strong.
  • Excel export


      IMA is written in C#, so the .NET framework 2.0 Service Pack 1 and the Oracle Data Access Components (ODAC) are needed.

      The IMA public release only contains theMS Windows, MS SQL Server and Oracle Database modules.


      > Download      (.NET Framework 2.0 SP1 needed)

      Beta Release (v0.4.7) - January 11 : Adding IMA Unleashed, Shares Auditor, Windows Credentials Editor (Ampli Security), Many Bugs Fixed...

      Download IMA

      Please, fill the following form :                                                                                     (*): Mandatory fields








      IMA Full : John The Ripper & PwDump embedded may be detected/blocked by some antivirus as "Hacking Tools"

      IMA Lite : Without John The Ripper & PwDump


      IMA Full
      (John the Ripper, PwDump & WCE Embedded)
      IMA Lite
      (Without John the Ripper, PwDump & WCE)
      Windows / Active Directory
      Microsof SQL Server
      Oracle Database
      Windows / Active Directory
      Microsof SQL Server
      Oracle Database
      System Auditor
         ●    Detailled Version
      [FULL] Windows / Active Directory : YES
      [FULL] Microsof SQL Server : YES
      [FULL] Oracle Database : YES
      [LITE] Windows / Active Directory : YES
      [LITE] Microsof SQL Server : YES
      [LITE] Oracle Database : YES
         ●    Users
      [FULL] Windows / Active Directory : YES
      [FULL] Microsof SQL Server : YES
      [FULL] Oracle Database : YES
      [LITE] Windows / Active Directory : YES
      [LITE] Microsof SQL Server : YES
      [LITE] Oracle Database : YES
         ●    Groups / Roles / Permissions
      [FULL] Windows / Active Directory : YES
      [FULL] Microsof SQL Server : YES
      [FULL] Oracle Database : YES
      [LITE] Windows / Active Directory : YES
      [LITE] Microsof SQL Server : YES
      [LITE] Oracle Database : YES
         ●    Services / Shares / Databases
      [FULL] Windows / Active Directory : YES
      [FULL] Microsof SQL Server : YES
      [FULL] Oracle Database : YES
      [LITE] Windows / Active Directory : YES
      [LITE] Microsof SQL Server : YES
      [LITE] Oracle Database : YES
         ●    Password Hashes
      [FULL] Windows / Active Directory : YES
      [FULL] Microsof SQL Server : YES
      [FULL] Oracle Database : YES
      [LITE] Windows / Active Directory : NO
      [LITE] Microsof SQL Server : YES
      [LITE] Oracle Database : YES
      Password Auditor
         ●    Full password assessment
      [FULL] Windows / Active Directory : YES
      [FULL] Microsof SQL Server : YES
      [FULL] Oracle Database : YES
      [LITE] Windows / Active Directory : NO
      [LITE] Microsof SQL Server : NO
      [LITE] Oracle Database : NO
         ●    Quick assessment
      (NULL or trivial passwords)
      [FULL] Windows / Active Directory : YES
      [FULL] Microsof SQL Server : YES
      [FULL] Oracle Database : YES
      [LITE] Windows / Active Directory : NO*
      [LITE] Microsof SQL Server : YES
      [LITE] Oracle Database : YES
      Extra Tools
         ●    Password Generator
      (LM, NT, SQL2000 & SQL2005)
      [FULL] Windows / Active Directory : YES
      [FULL] Microsof SQL Server : YES
      [FULL] Oracle Database : NO
      [LITE] Windows / Active Directory : YES
      [LITE] Microsof SQL Server : YES
      [LITE] Oracle Database : YES
         ●    John Pot Generator
      (LM, NT, SQL2000 & SQL2005)
      [FULL] Windows / Active Directory : YES
      [FULL] Microsof SQL Server : YES
      [FULL] Oracle Database : YES
      [LITE] Windows / Active Directory : YES
      [LITE] Microsof SQL Server : YES
      [LITE] Oracle Database : NO
         ●    LM2NTCRACK GUI
      [FULL] Windows / Active Directory : YES
      [FULL] Microsof SQL Server : N/A
      [FULL] Oracle Database : N/A
      [LITE] Windows / Active Directory : YES
      [LITE] Microsof SQL Server : N/A
      [LITE] Oracle Database : N/A
         ●    SQL2KTO2005CRACK GUI
      [FULL] Windows / Active Directory : N/A
      [FULL] Microsof SQL Server : YES
      [FULL] Oracle Database : N/A
      [LITE] Windows / Active Directory : N/A
      [LITE] Microsof SQL Server : YES
      [LITE] Oracle Database : N/A
         ●    ORACLEDES2SHA1CRACK GUI
      [FULL] Windows / Active Directory : N/A
      [FULL] Microsof SQL Server : N/A
      [FULL] Oracle Database : YES
      [LITE] Windows / Active Directory : N/A
      [LITE] Microsof SQL Server : N/A
      [LITE] Oracle Database : YES

      * : Imported Hashes only


      Presentation:



      > Introduction

      Most of our customers are sensibilized about Identity Management : "Can I have the member list of each group ?" "Can I have the list of Administrators profiles ?" "Did they embedded strong password ?"...

      However, when you perform an audit/penetration test, you still found trivial administrative accounts (backup/backup, sa/NULL...), which for some Odd/Business reasons are "Domain Administrators" or members of the group "root".

      The big deal is even if you give to the IT teams all the commands/tools with the good parameters, they cannot easily exploit these information on each server.


      So, IT teams need a tool to perform automatically these tasks and gathering data... That's why I have launched the IMA project.

      MS Windows/Active Directory Screenshots :


      MS SQL Server Screenshots :


      Extra Tools Screenshots :


      > Optional Resources

      This software embedded compiled version of :



      > History

      Each releases fixed some/lot of bugs, but add a major functionality :

      • Beta Release (v0.4.7) - January 11 : IMA Unleashed, Shares Auditor, WCE & many bugs fixed
      • Beta Release (v0.3.1) - December 09 : Multi-Threading optimisation & many bugs fixed
      • Beta Release (v0.3) - November 09 : Oracle Database support added
      • Beta Release (v0.2) - October 09 : MS SQL Server support added
      • Beta Release (v0.1) - June 09 : MS Windows support only


      > Bugs / Comments

      Please report bug and/or comments to :

      • Yannick Hamon <yannick.hamon@xmco.fr>

> Greetings

For debugging and testing :

  • Adrien Guinault <adrien.guinault@xmco.fr>
  • Frederic Charpentier <fcharpentier@xmco.fr>
  • François Legué <francois.legue@xmco.fr>
  • Lin Miang Jin <linmiang.jin@xmco.fr>

> Copyright and Licence

THIS SOFTWARE IS MADE AVAILABLE "AS IS", AND THE AUTHOR DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, WITH REGARD TO THIS SOFTWARE, INCLUDING WITHOUT LIMITATION ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE, AND IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, INDIRECT OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, TORT (INCLUDING NEGLIGENCE) OR STRICT LIABILITY, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.

--
Copyright (C) 2009 Yannick Hamon <yannick.hamon@xmco.fr>
XMCO | Security Research Labs