IMA
all-in-one tool to audit accounts and passwords !
What is IMA ?
IMA (Identity Management Auditor) is a GUI tool that provides an all-in-one tool to audit accounts, authorization and passwords
Features
- Assess and crack Microsoft Windows passwords (LM, NTLM, Microsoft SQL Server), ORACLE and Lotus Domino (and others...)
- John-The-Ripper pot import capabilities
- Able to evaluate passwords strength : trival, weak or strong.
- Excel export
- SSTIC 09 (Rump Session): Slides PPT
- Demonstration: Video (9.1 MB) (Compatible QuickTime/VLC)
- John the Ripper (Password Auditor)
- PwDump 6 (Microsoft Windows Password Dumper)
- Oracle Default Password List (Pete Finnigan)
- Oracle Data Access Components (ODAC)
- Oracle Data Access Components (ODAC)
- WCE
- Beta Release (v0.4.7) - January 11 : IMA Unleashed, Shares Auditor, WCE & many bugs fixed
- Beta Release (v0.3.1) - December 09 : Multi-Threading optimisation & many bugs fixed
- Beta Release (v0.3) - November 09 : Oracle Database support added
- Beta Release (v0.2) - October 09 : MS SQL Server support added
- Beta Release (v0.1) - June 09 : MS Windows support only
- Yannick Hamon <yannick.hamon@xmco.fr>
- Adrien Guinault <adrien.guinault@xmco.fr>
- Frederic Charpentier <fcharpentier@xmco.fr>
- François Legué <francois.legue@xmco.fr>
- Lin Miang Jin <linmiang.jin@xmco.fr>
IMA is written in C#, so the .NET framework 2.0 Service Pack 1 and the Oracle Data Access Components (ODAC) are needed.
The IMA public release only contains theMS Windows, MS SQL Server and Oracle Database modules.
Download (.NET Framework 2.0 SP1 needed)
Beta Release (v0.4.7) - January 11 : Adding IMA Unleashed, Shares Auditor, Windows Credentials Editor (Ampli Security), Many Bugs Fixed...
IMA Full : John The Ripper & PwDump embedded may be detected/blocked by some antivirus as "Hacking Tools"
IMA Lite : Without John The Ripper & PwDump
IMA Full
(John the Ripper, PwDump & WCE Embedded)IMA Lite
(Without John the Ripper, PwDump & WCE)





System Auditor ● Detailled Version ![[FULL] Windows / Active Directory : YES [FULL] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Microsof SQL Server : YES [FULL] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Oracle Database : YES [FULL] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Windows / Active Directory : YES [LITE] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Microsof SQL Server : YES [LITE] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Oracle Database : YES [LITE] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
● Users ![[FULL] Windows / Active Directory : YES [FULL] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Microsof SQL Server : YES [FULL] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Oracle Database : YES [FULL] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Windows / Active Directory : YES [LITE] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Microsof SQL Server : YES [LITE] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Oracle Database : YES [LITE] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
● Groups / Roles / Permissions ![[FULL] Windows / Active Directory : YES [FULL] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Microsof SQL Server : YES [FULL] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Oracle Database : YES [FULL] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Windows / Active Directory : YES [LITE] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Microsof SQL Server : YES [LITE] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Oracle Database : YES [LITE] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
● Services / Shares / Databases ![[FULL] Windows / Active Directory : YES [FULL] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Microsof SQL Server : YES [FULL] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Oracle Database : YES [FULL] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Windows / Active Directory : YES [LITE] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Microsof SQL Server : YES [LITE] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Oracle Database : YES [LITE] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
● Password Hashes ![[FULL] Windows / Active Directory : YES [FULL] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Microsof SQL Server : YES [FULL] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Oracle Database : YES [FULL] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Windows / Active Directory : NO [LITE] Windows / Active Directory : NO](http://www.xmco.fr/ima/images/cancel.png)
![[LITE] Microsof SQL Server : YES [LITE] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Oracle Database : YES [LITE] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
Password Auditor ● Full password assessment ![[FULL] Windows / Active Directory : YES [FULL] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Microsof SQL Server : YES [FULL] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Oracle Database : YES [FULL] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Windows / Active Directory : NO [LITE] Windows / Active Directory : NO](http://www.xmco.fr/ima/images/cancel.png)
![[LITE] Microsof SQL Server : NO [LITE] Microsof SQL Server : NO](http://www.xmco.fr/ima/images/cancel.png)
![[LITE] Oracle Database : NO [LITE] Oracle Database : NO](http://www.xmco.fr/ima/images/cancel.png)
● Quick assessment
(NULL or trivial passwords)![[FULL] Windows / Active Directory : YES [FULL] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Microsof SQL Server : YES [FULL] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Oracle Database : YES [FULL] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
*![[LITE] Microsof SQL Server : YES [LITE] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Oracle Database : YES [LITE] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
Extra Tools ● Password Generator
(LM, NT, SQL2000 & SQL2005)![[FULL] Windows / Active Directory : YES [FULL] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Microsof SQL Server : YES [FULL] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Oracle Database : NO [FULL] Oracle Database : NO](http://www.xmco.fr/ima/images/cancel.png)
![[LITE] Windows / Active Directory : YES [LITE] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Microsof SQL Server : YES [LITE] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Oracle Database [LITE] Oracle Database : YES](http://www.xmco.fr/ima/images/cancel.png)
● John Pot Generator
(LM, NT, SQL2000 & SQL2005)![[FULL] Windows / Active Directory : YES [FULL] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Microsof SQL Server : YES [FULL] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Oracle Database [FULL] Oracle Database : YES](http://www.xmco.fr/ima/images/cancel.png)
![[LITE] Windows / Active Directory : YES [LITE] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Microsof SQL Server : YES [LITE] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Oracle Database : NO [LITE] Oracle Database : NO](http://www.xmco.fr/ima/images/cancel.png)
● LM2NTCRACK GUI ![[FULL] Windows / Active Directory : YES [FULL] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Microsof SQL Server : N/A [FULL] Microsof SQL Server : N/A](http://www.xmco.fr/ima/images/NA.png)
![[FULL] Oracle Database : N/A [FULL] Oracle Database : N/A](http://www.xmco.fr/ima/images/NA.png)
![[LITE] Windows / Active Directory : YES [LITE] Windows / Active Directory : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Microsof SQL Server : N/A [LITE] Microsof SQL Server : N/A](http://www.xmco.fr/ima/images/NA.png)
![[LITE] Oracle Database : N/A [LITE] Oracle Database : N/A](http://www.xmco.fr/ima/images/NA.png)
● SQL2KTO2005CRACK GUI ![[FULL] Windows / Active Directory : N/A [FULL] Windows / Active Directory : N/A](http://www.xmco.fr/ima/images/NA.png)
![[FULL] Microsof SQL Server : YES [FULL] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[FULL] Oracle Database : N/A [FULL] Oracle Database : N/A](http://www.xmco.fr/ima/images/NA.png)
![[LITE] Windows / Active Directory : N/A [LITE] Windows / Active Directory : N/A](http://www.xmco.fr/ima/images/NA.png)
![[LITE] Microsof SQL Server : YES [LITE] Microsof SQL Server : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Oracle Database : N/A [LITE] Oracle Database : N/A](http://www.xmco.fr/ima/images/NA.png)
● ORACLEDES2SHA1CRACK GUI ![[FULL] Windows / Active Directory : N/A [FULL] Windows / Active Directory : N/A](http://www.xmco.fr/ima/images/NA.png)
![[FULL] Microsof SQL Server : N/A [FULL] Microsof SQL Server : N/A](http://www.xmco.fr/ima/images/NA.png)
![[FULL] Oracle Database : YES [FULL] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
![[LITE] Windows / Active Directory : N/A [LITE] Windows / Active Directory : N/A](http://www.xmco.fr/ima/images/NA.png)
![[LITE] Microsof SQL Server : N/A [LITE] Microsof SQL Server : N/A](http://www.xmco.fr/ima/images/NA.png)
![[LITE] Oracle Database : YES [LITE] Oracle Database : YES](http://www.xmco.fr/ima/images/check.png)
* : Imported Hashes only
Presentation:
Introduction
Most of our customers are sensibilized about Identity Management : "Can I have the member list of each group ?" "Can I have the list of Administrators profiles ?" "Did they embedded strong password ?"...
However, when you perform an audit/penetration test, you still found trivial administrative accounts (backup/backup, sa/NULL...), which for some Odd/Business reasons are "Domain Administrators" or members of the group "root".
The big deal is even if you give to the IT teams all the commands/tools with the good parameters, they cannot easily exploit these information on each server.
So, IT teams need a tool to perform automatically these tasks and gathering data... That's why I have launched the IMA project.
MS Windows/Active Directory Screenshots :
MS SQL Server Screenshots :
Extra Tools Screenshots :
Optional Resources
This software embedded compiled version of :
History
Each releases fixed some/lot of bugs, but add a major functionality :
Bugs / Comments
Please report bug and/or comments to :
Greetings
For debugging and testing :
Copyright and Licence
THIS SOFTWARE IS MADE AVAILABLE "AS IS", AND THE AUTHOR DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, WITH REGARD TO THIS SOFTWARE, INCLUDING WITHOUT LIMITATION ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE, AND IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, INDIRECT OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, TORT (INCLUDING NEGLIGENCE) OR STRICT LIABILITY, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
--
Copyright (C) 2009 Yannick Hamon <yannick.hamon@xmco.fr>
XMCO | Security Research Labs













