Read more: http://pelajaran-blog.blogspot.com/2012/03/cara-membuat-read-more-otomatis-di.html#ixzz1xfYNrBUz

Rabu, 17 Agustus 2011

Hacking Windows NT with IIS & FTP

 Untuk Bahasa Indonesia klik Disini

This is another selection from the ask, I like these as they tend to generate some good discussion and they are a good introduction to newcomers to hacking on the mindset and workflow of getting access to a box. The exact methods may not work, but we aren’t here to train script kiddies, we just want to make you think.

Johnny Hacker has a Windows NT Server at home. Why? Because he knows if he’s going to hack NT he’s best using the same type of computer…it gives him all the necessary tools. He has installed RAS and has a dial-up connection to the Internet. One morning, around 2:00am he dials into the Internet…his IP address is dynamically assigned to him. He opens up a Command Prompt window and gets down to work. He knows www.company.com’s web server is running IIS. How? Because he once did a search on “batch fil es as CGI” using Excites search engine. That phrase is in Chapter 8 of Internet Information Server’s on-line help….and unfortunately it’s been indexed by Excite’s spider…now Johnny has a list of around 600 web servers running IIS.

He ftps to www.company.com. He isn’t even sure yet if the server is running the ftp service. He knows if he gets a connection refused message it wont be…he’s in luck though…the following appears on the screen:

"C:\ftp www.company.com
Connected to www.company.com.
220 saturn Microsoft FTP Service (Version 3.0).
User (www.comapny.com:(none)):"
 
This connection message tells him something extremely important:The
NetBIOS name of the server : SATURN. From this he can deduce the name
of the anonymous internet account that is used by NT to allow people to
anonymously u se the WWW, FTP and Gopher services on the machine. If
the default account hasn’t been changed, and he knows that it is very
rare if it has been changed, the anonymous internet account will be
called IUSR_SATURN. This information will be needed later if he’s to
gain Administrator access to the machine. He enters “anonymous”as the
user and the following appears: 
"331 Anonymous access allowed, send identity (e-mail name)as password.
Password:"
 
Johnny often tries the “guest” account before using “anonymous” as the user. A fresh install of NT has the “guest” account disabled but some admins enable this account...and the funny thing is they usually put a weak password on it such as ‘guest’ or no password at all. If he manages to gain access to the ftp service with this account he has a valid NT user account….everything that the “guest” account has access to…so does Johnny, and sometimes that can be almost everything. He knows he can access their site now…but there is still a long way to go yet….even at this point he still might not get access. At this point he doesn’t even supply a password…he just presses enter and gets a message stating that the Anonymous user is logged in.

First off he types “cd /c” because some admins will make the the root of the drive a virtual ftp directory and leave the default alias name : “/c”. Next he sees whether he can actually “put” any files onto the site ie. is the write permission enabled for this f tp site. He’s in luck. Next he types “dir” to see what he has access to. He chuckles to himself when he sees a directory called “CGI-BIN”. Obviously the Webmaster of the NT machine has put this here with the rest of the WWW site so he can remotely make changes to it. Johnny knows that the CGI-BIN has the “Execute” permission so if he can manage to put any program in here he can run it from his web browser. He hopes that the Webmaster hasn’t, using NTFS file-level security, cut off write access to the anonymous internet account to this directory…even though he knows there are sometimes ways round this. He changes to the CGI-BIN directory and then changes the type to I by using the command “binary”. Then he types “put cmd.exe”. He’s in luck..he gets the following response :

"200 PORT command successful.
150 Opening BINARY mode data connection for CMD.EXE.
226 Transfer complete.
208144 bytes sent in 0.06 seconds(3469.07 Kbytes/sec)"
 
Next he puts getadmin.exe and gasys.dll into the same directory. With these three files in place he doesn’t even gracefully “close” the ftp session; he just closes the Command Prompt window. With a smile on his face he leans back and lights a smoke, savouring the moment…he knows he has them…. After crunching the cigarette out in an overflowing ashtray he connects to AOL. He does this because if logging is enabled on the NT machine the IP address of AOL’s proxy server will be left and not his own…not that it really matters because soon he’ll edit the logfile and wipe all traces of his presence. Opening up the web browser he enters the following URL:

http://www.company.com/cgi-bin/getadmin.exe?IUSR_SATURN

After about a fifteen second wait the following appears on his web browser:

"CGI Error
The specified CGI application misbehaved by not returning a 
complete set of
HTTP headers."
 
The headers it did return are:
"Congratulations , now account IUSR_SATURN have administrator rights!"
 
He has just made the anonymous internet account a local administrator and consequently using this account he can do pretty much what he wants to. Firstly though, he has to create an account for himself that he can use to connect to the NT server using NT Explorer and most of the Administrative tools. He can’t use the IUSR_SATURN account because he doesn’t know the randomly generated password. To create an account he enters the following URL:
cmd.exe?/c%20c:\winnt\system32\net.exe%20user%20cnn%20news%20/add
He has just created an account called “cnn” with the password “news”. To make the account a local administrator he enters the following URL:

http://www.company.com/cgi-bin/getadmin.exe?cnn

It has taken him less than ten minutes to do all of this. He disconnects from AOL and clicks on start, goes upto find and does a search for the computer www.company.com. After about a minute the computer is found, next he right clicks on the “computer” and then clicks on Explore. NT Explorer opens and after a little wait Johnny is prompted for a user-name and password. He enters “cnn” and “news”. Moments later he is connected. Admin rights for the computer www.company.com are appended to his own security access token…now he can do anything. Using User Manager for Domains he can retrieve all the account information; he can connect to the Internet Service Manager; he can view Server Manager…first though, using NT Explorer he maps a drive to the hidden system share C$. He changes to the Winnt\system32\logfiles directory and opens up the logfile for that day. He deletes all of the log entries pertaining to his “visit” and saves it. If he gets any message about sharing violations all he has to do is change the date on the computer with the following URL:

http://www.company.com/cgi-bin/cmd.exe?/c%20date%2002/02/98

Next, using the Registry Editor he connects to the registry on the remote computer. Then using L0phtcrack he dumps the SAM (the Security Accounts Manager – holds account info) on the NT server and begins cracking all the passwords on the machine. Using the Task Manager he sets the priority to Low because L0phtcrack is fairly processor intensive (NB L0phtcrack ver 2.0 sets the priority to Low anyway) and there is still a few thing he must do to hide the fact that that some-one has gained entry. He deletes cmd.exe, getadmin.exe and gasys.dll from the cgi-bin, then he checks the security event log for the remote NT server using Event Viewer to see if he’s left any traces there.

Finally using User Manager for Domains he removes admin rights from the IUSR_SATURN account and deletes the cnn account he created a few moments earlier. He doesn’t need this account anymore….L0phtcrack will be able to brute force all the accounts. Next time he connects to this machine it will be using the Administrator account. He breaks his connection to the Internet and sets L0phtcrack’s priority to High, leaves it running and heads to bed…Looking at his alarm clock : it’s just passed 2:30am….Sighing to himself, he mumbles, “Sheesh, I’m getting slow!” and falls asleep with a grin on his face.
 
thank's to : http://www.binushacker.net/
 

 
Read More..

Hacking Local Area Network

 Untuk Bahasa Indonesia Klik Disini

Hack Local Area Network – LAN Hack – LAN Hacking.

This technique will be taking advantage of Port 139.

Most of the time,Port 139 will be opened.

First of all,I will do a port scanning at the target computer which is 192.168.40.128.

This computer is inside my LAN network.

I will scan it using Nmap.

[Image: 1_13.jpg]

I get the result and it shows Port 139 is opened up for me.

Now you will need both of these tools:
** USER2SID & SID2USER, Click here to Download (wait 5 seconds and click the "SKIP AD")
** NetBios Auditing Tool, Click here to Download (wait 5 seconds and click the "SKIP AD")

You can get both of them on the Internet.

After you get both of them,put them in the C:\ directory.

[Image: 2_1.jpg]


You now need to create a null session to the target computer.

[Image: 3_3.jpg]


Now open the Command Prompt and browse to the USER2SID & SID2USER folder.There will be 2 tools inside it,one will be USER2SID and another one will be SID2USER.

We will first using USER2SID to get the ID.

[Image: 4_10.jpg]


We will test against the Guest account because Guest account is a built in account.

After we get the ID,we need to do some modification on the ID.

We take the ID we get from the guest account and modified it become
“5 21 861567501 1383384898 839522115 500″.

Please leave out the S-1-,leave out all the – too.

[Image: 5_8.jpg]


Now you will see that you get the username of the Administrator account.

In this case,the Administrator account is Administrator.

Create a text file called user.txt and the content will be the username of the Admin account.

[Image: 6.jpg]

Prepare yourself a good wordlist.

[Image: 7.jpg]

Now put both of them in the same directory with the NetBios Auditing Tool.

[Image: 8.jpg]
Now we are going to crack the Admin account for the password in order to access to the target computer.
Browse to the NetBios Auditing Tool directory.

[Image: 9_1.jpg]

Press on enter and the tool will run through the passlist.

[Image: 10.jpg]


In this case,I have get the password.

In order to proof that I can get access to the target computer using this password.

[Image: 11.jpg]

After you press enter,it will prompt you for the username and password.

[Image: 12_6.jpg]

Therefore,just input them inside the prompt and continue.

[Image: 13.jpg]

Target C drive will be on your screen.

[Image: 14.jpg]


In order to prevent from this attack,close down port that you do not want to use such as Port 135,Port 136,Port 137,Port 138 and Port 139.

thank's to http://www.binushacker.net/
Read More..

Selasa, 16 Agustus 2011

Hacking with PRORAT

Untuk Bahasa Indonesia Klik Disini

This time let's play with one of the hacking tools, namely ProRat.
Tools made of Turkey is very unusual, this tool serves to infiltrate other people's computers. The trick is very simple and easy, we live to know the IP and Port victim's computer, then we can direct it infects. 

Download ProRat Here (
wait 5 seconds and click the "SKIP AD"). Before download, turn off your Anti-Virus, Please


A. How to use ProRat
1. First we must know in advance the IP and Port of victims that are open. We can do it the manual way or also with the help of Ports Scanner. 





 From the picture above we know all the active computer's IP and Port where it is exposed. That will be the victims in our experiments this time is a computer with the IP 192.162.10.233.
2. The next step is we run ProRat,. Previously turn off your Anti Virus (disable), because ProRat will be detected as a virus. Though he is not harmful to our computer. After that fill the victim's IP in the form of IP and port (default 5110). 




If we click the Connect button will connect to a victim's computer can not, because we have not been victims of computer infections. To infect a victim's computer we first create a server that will run on the victim's computer. I click the Create button - Create ProRat Server. Then came the appearance of Notifications: 




Check the option Use Proconnective Notifications and contents of the IP (DNS) IP addresses with us. On the General Settings tab we fill Server Port (default 5110), Server Password and Victim Name. 


On the Bind  withtab file we can smuggle a file that will run along Server. Free file extension. 

 
Next is the Server Extensions tab, there are several options the server extension. We choose an extension. Exe. 





To create a server icon we click the Servers tab icon, select the icon whatever you want. 


The final step of making this server is click Create Server. 


Once successful, it will appear: 


3. We just run these servers dikomputer victims. The trick is up to you ... want to secretly infiltrated or using Social Engineering techniques and also can you infeksikan directly on the computer (if biased sihh).
4. Once the server is successfully running on the victim's computer, then we immediately try to connect to it with our computers.
5. For connection we can use ProConnective or directly typing the IP address and port the victim's computer. ProConnective are innate tools of ProRat that serves as a Bridge (bridge connection) between server computers and client computers (the victim). IP would seem the victim when he was on. 



6. After successfully connecting to the victim's computer then the status of ProRat will change from Disconnected to Connected 


7. Well ... it's time we play. There are many things we can do on a victim's computer as the information of your PC, send an error message, turn off the computer, lock mouse, open the CD-ROM or even photographing the victim's face.
8. Now we will see the victim's PC info: 



From the picture above we can see the information held by the victim's computer.
9. We can also send a fake error message to the victim's computer: 



10. Install Keylogger. 


11. And most exciting is to see the faces of the victims we hack. 


How exciting right? That's still a fraction of the usefulness ProRat many more other functions, such as formatting the hard drive belongs to victims, disrupting the registry, steal important data and so forth. However, in our discussion this time we both ends meet so yes. Ok!
Use with either yes ...
B. Preventive measures
1. Update your Anti Virus is always to be able to detect any infection from ProRat. ProRat server usually detected as Trojan.Dropper.Prorat.DZ.29, Dropped: Backdoor.Prorat.DZ. 2. Install Anti ProRat, you can download it at www.softpedia.com / get / Antivirus / Anti-prorat.shtml.

Thank's to http://www.binushacker.net/
Read More..

Minggu, 14 Agustus 2011

Internet Network

Posts today, I will discuss a bit about the Internet.
hopefully useful to you.

Untuk Bahasa Indonesia Klik Disini

The Internet is a network of computers that could be categorized as a WAN, connecting millions of computers around the world, without borders, where every person who has a computer can join the network by simply connecting to the internet service provider (internet service provider / ISP) such as Telkom Speedy , or Indosatnet. The Internet can be translated as an international networking (international network), for connecting computers internationally, or as internetworking (networking between networks) for network connecting millions around the world.

The Internet started when the U.S. Department of Defense (Department of Defense, USA) built a computer network in 1969, which was named ARPANET (Advanced Research Project Agency Network) in order to connect multiple computers within its universities doing military research, especially to build a network computer communication that is able to withstand nuclear attack. These networks continue to grow, more and more computers are involved, and the research side of software development is also growing. In May 1974, Vinton G. Cerf of Stanford University and Robert E. Kahn of the Department of Defense, USA, published a paper in IEEE Transaction on Communication entitled "A Protocol for Packet Network Intercommunication", the concept was later popular as a TCP / IP , when the ARPANET had adopted the protocol into standard protocols for ARPANET in 1983. The university, especially the University of California at Berkeley and then build the operating system of the Berkeley Software Distribution Unix) or BSD UNIX (known as Free BSD Unix) and the department of defense finance Bolt Baranek and Newman (BBN) for the implementation of the protocol to TCP / IP in BSD Unix to be implemented on the ARPANET, the forerunner of the Internet thus formed.

At the end of 1983, the ARPANET network divided into DARPANET (Defence ARPANET) and MILNET (Military Network). In 1985 the network was formed NFSNET (National Science Foundation Network) to connect the existing supercomputer in various universities in America and is connected to the ARPANET. NSFNET network developed by researchers continue to college. In 1988 the Internet backbone network is only a capacity of 56 Kbps. Although in 1990 the ARPANET officially closed, but the Internet network that has formed forwarded by the university in the United States and enter the university network in the Americas (Canada and South America) and networks in Europe to be part of the Internet. In 1992 the network backbone upgraded to T3 with a speed of 45 Mbps, and around 1995, increased again to OC-3 at a speed of 155 Mbps. Now the high-speed Internet backbone in order Gbps.

Internet topology is basically a mesh-topology, linking many types of networks via packet-switching systems, even if it can be said that the center of its are some of the NAP (Network Access Point) in San Francisco (Pacific Bell), Chicago (Ameritech) , New Jersey (Sprint), and Merit Access Exchange (MAE) in San Francisco (MAE West) and Washington, DC (MAE East) is handled by MFS Datanet.

Although no organization has the internet, but there are many organizations that maintain these networks through the establishment of standardization of protocols, rules, and access methods. Internet Engineering Task Force (IETF) to handle the technical problems that arise on the Internet, such as problems in the protocol, the architecture and operation of the Internet. Internet Research Task Force (IRTF) to handle the technical research, such as the addressing system and other engineering. Internet Assigned Numbers Authority (IANA) controls the distribution of IP address (IP #) to various countries and organizations. Internet Society (ISOC) to handle administrative and organizational structure of the Internet.

Commercial entity then provides access services to provide connections from the user's computer to the Internet, and the agency is called Internet access provider or ISP. Some well-known ISP in the world is America On Line (AOL), Australia OnLine, CompuServe, Genie, and Prodigy. In Indonesia there are TelkomNet, Indosatnet, Wasantara Net, InterNux, and so on. ISPs provide dial-up connection via a modem-telephone, wireless connection through WLAN antenna, or ADSL connection via the telephone. Connection protocol used is SLIP (Serial Line Interface Protocol) or PPP (Point-to-Point Protocol), where the SLIP connection is usually slower than the PPP.


Logically Internet network is divided into several domains, according to the standard IPv4 (Internet Protocol version 4) were identified through the IP number of 32 bits or 4 binary digits separated by dots (eg 192.168.10.25). Standard domain types include:
     
     *. Com = commercial organization
     *. Edu = educational institution in the United
     *. Ac = academic institutions
     *. Gov = government agency
     *. Mil = military organization
     *. Net = network access providers
     *. Org = non-profit organization

Besides domain is also divided by country, for example:

     *. Au = Australia
     *. Ca = Canada
     *. Id = Indonesia
     *. Jp = Japan
     *. My = Malaysia
     *. Sw = Sweden
     *. Th = Thailand 
For example Alauddin State Islamic University to have addresses uin-alauddin.ac.id as one of the academic institutions in Indonesia, as the network access provider, Indosat has indosat.net.id address code, and so on.

Apologize if there are flaws in my post.
thank's to http://teknik-informatika.com

Read More..

Sabtu, 13 Agustus 2011

Install Windows XP

Untuk Bahasa Indonesia Klik Disini

This procedure demonstrates how to install Windows XP Professional. The procedure to install Windows XP home edition is very similar to the professional edition. Since Windows XP Pro is more advanced operating system, it will be used to demonstrate the installation procedure.
The best way install Windows XP is to do a clean install. It is not difficult to perform a clean installation. Before you perform the installation I recommend that you check Windows XP Compatibility List to ensure that your hardware is supported by XP. If your hardware is not on the compatibility list you can check your hardware manufactures website to download the drivers for Windows XP. Save all the necessary drivers onto floppy disks or CD before you start the installation.
All versions of Windows XP CD are bootable. In order to boot from CD/DVD-ROM you need to set the boot sequence. Look for the boot sequence under your BIOS setup and make sure that the first boot device is set to CD/DVD-ROM. You can then perform the following steps to install Windows XP:

Step 1 - Start your PC and place your Windows XP CD in your CD/DVD-ROM drive. Your PC should automatically detect the CD and you will get a message saying "Press any key to boot from CD". Soon as computer starts booting from the CD your will get the following screen:

Windows XP Screenshot - Click to enlarge

Step 2 - At this stage it will ask you to press F6 if you want to install a third party Raid or SCSI driver. If you are using a an IDE Hard Drive then you do not need to press F6. If you are using a SCSI or SATA Hard drive then you must press F6 otherwise Windows will not detect your Hard Drive during the installation. Please make sure you have the Raid drivers on a floppy disk. Normally the drivers are supplied on a CD which you can copy to a floppy disk ready to be installed. If you are not sure how to do this then please read your motherboard manuals for more information. 

Windows XP Screenshot - Click to enlarge

Step 3 - Press S to Specify that you want to install additional device.

Windows XP Screenshot - Click to enlarge

Step 4 - You will be asked to insert the floppy disk with the Raid or SCSI drivers. Press enter after you have inserted the disk.
Windows XP Screenshot - Click to enlarge

Step 5 - You will see a list of Raid drivers for your HDD. Select the correct driver for your device and press enter.
Windows XP Screenshot - Click to enlarge

Step 6 - You will then get a Windows XP Professional Setup screen. You have the option to do a new Windows install, Repair previous install or quit. Since we are doing a new install we just press Enter to continue.

Windows XP Screenshot - Click to enlarge 

Step 7 - You will be presented with the End User Licensing Agreement. Press F8 to accept and continue

Windows XP Screenshot - Click to enlarge

Step 8 - This step is very important. Here we will create the partition where Windows will be installed. If you have a brand new unformatted drive you will get a screen similar to below. In our case the drive size is 8190MB. We can choose to install Windows in this drive without creating a partition, hence use the entire size of the drive. If you wish to do this you can just press enter and Windows will automatically partition and format the drive as one large drive.
However for this demonstration I will create two partition. The first partition will be 6000MB (C: drive) and second partition would be 2180MB (E: drive). By creating two partition we can have one which stores Windows and Applications and the other which stores our data. So in the future if anything goes wrong with our Windows install such as virus or spyware we can re-install Windows on C: drive and our data on E: drive will not be touched. Please note you can choose whatever size partition your like. For example if you have 500GB hard drive you can have two partition of 250GB each.
Press C to create a partition.

Windows XP Screenshot - Click to enlarge

Step 9 - Windows will show the total size of the hard drive and ask you how much you want to allocate for the partition you are about to create. I will choose 6000MB. You will then get the screen below. Notice it shows C: Partition 1 followed by the size 6000 MB. This indicates the partition has been created. We still have an unpartitioned space of 2189MB. Next highlight the unpartitioned space by pressing down the arrow key. Then press C to create another partition. You will see the total space available for the new partition. Just choose all the space left over, in our case 2180MB. 

Windows XP Screenshot - Click to enlarge

Step 10 - Now you will see both partition listed. Partition 1 (C: Drive) 6000MB and Partition 2 (E: Drive) 2180MB. You will also have 8MB of unpartitioned space. Don't worry about that. Just leave it how its is. Windows normally has some unpartitioned space. You might wonder what happened to D: drive. Windows has automatically allocated D: drive to CD/DVD-ROM.
Select Partition 1 (C: Drive) and press Enter.

Windows XP Screenshot - Click to enlarge

Step 11 - Choose format the partition using NTFS file system.This is the recommended file system. If the hard drive has been formatted before then you can choose quick NTFS format. We chose NTFS because it offers many security features, supports larger drive size, and bigger size files.

Windows XP Screenshot - Click to enlarge

Windows will now start formatting drive C: and start copying setup files as shown on the two images below :

Windows XP Screenshot - Click to enlarge
Windows XP Screenshot - Click to enlarge

Step 12 - After the setup has completed copying the files the computer will restart. Leave the XP CD in the drive but this time DO NOT press any key when the message "Press any key to boot from CD" is displayed. In few seconds setup will continue. Windows XP Setup wizard will guide you through the setup process of gathering information about your computer.

Windows XP Screenshot - Click to enlarge

Step 13 - Choose your region and language.

Windows XP Screenshot - Click to enlarge

Step 14 - Type in your name and organization.

Windows XP Screenshot - Click to enlarge

Step 15. Enter your product key.

Windows XP Screenshot - Click to enlarge

Step 16 - Name the computer, and enter an Administrator password. Don't forget to write down your Administrator password.

Windows XP Screenshot - Click to enlarge

Step 17 - Enter the correct date, time and choose your time zone.

Windows XP Screenshot - Click to enlarge

Step 18 - For the network setting choose typical and press next.

Windows XP Screenshot - Click to enlarge

Step 19 - Choose workgroup or domain name. If you are not a member of a domain then leave the default settings and press next. Windows will restart again and adjust the display.

Windows XP Screenshot - Click to enlarge


Step 20 - Finally Windows will start and present you with a Welcome screen. Click next to continue.

Windows XP Screenshot - Click to enlarge

Step 21 - Choose 'help protect my PC by turning on automatic updates now' and press next.

Windows XP Screenshot - Click to enlarge

Step 22 - Will this computer connect to the internet directly, or through a network? If you are connected to a router or LAN then choose: 'Yes, this computer will connect through a local area network or home network'. If you have dial up modem choose: 'No, this computer will connect directly to the internet'. Then click Next.

Windows XP Screenshot - Click to enlarge

Step 23 - Ready to activate Windows? Choose yes if you wish to active Windows over the internet now. Choose no if you want to activate Windows at a later stage.

Windows XP Screenshot - Click to enlarge

Step 24 - Add users that will sign on to this computer and click next.

Windows XP Screenshot - Click to enlarge

Step 25 - You will get a Thank you screen to confirm setup is complete. Click finish.

Windows XP Screenshot - Click to enlarge

Step 26. Log in, to your PC for the first time.

Windows XP Screenshot - Click to enlarge

Step 27 - You now need to check the device manager to confirm that all the drivers has been loaded or if there are any conflicts. From the start menu select Start -> Settings -> Control Panel. Click on the System icon and then from the System Properties window select the Hardware tab, then click on Device Manager.

Windows XP Screenshot - Click to enlarge

If there are any yellow exclamation mark "!" next to any of the listed device, it means that no drivers or incorrect drivers has been loaded for that device. In our case we have a Video Controller (VGA card) which has no drivers installed.
Your hardware should come with manufacturer supplied drivers. You need to install these drivers using the automatic setup program provided by the manufacturer or you need to manually install these drivers. If you do not have the drivers, check the manufacturers website to download them.
To install a driver manually use the following procedure:
(a) From the device manager double click on the device containing the exclamation mark.
(b) This would open a device properties window.
(c) Click on the Driver tab.
(d) Click Update Driver button. The Wizard for updating device driver pops up as shown below:

Windows XP Screenshot - Click to enlarge

You now get two options. The first option provides an automatic search for the required driver. The second option allows you to specify the location of the driver. If you don't know the location of the driver choose the automatic search which would find the required driver from the manufacturer supplied CD or Floppy disk. Windows would install the required driver and may ask you to restart the system for the changes to take affect. Use this procedure to install drivers for all the devices that contain an exclamation mark. Windows is completely setup when there are no more exclamation marks in the device manager.
Read More..