Re: [Full-Disclosure] Unusual request

From: Ivan Susanin (ivan@susanin.org)
Date: 02/13/03

  • Next message: Laurent LEVIER: "Re: [Full-Disclosure] Unusual request"
    From: Ivan Susanin <ivan@susanin.org>
    To: Paul Schmehl <pauls@utdallas.edu>
    Date: Thu, 13 Feb 2003 11:04:13 +0200
    

    IIS Storm 2.0 by m0sad team

    no idea where to download

    Have fun,
    Ivan

    Paul Schmehl wrote:
    > The net is filled with so much junk now, it's getting harder to find
    > what you need. I am looking for an exploit that will give you "root" on
    > an unpatched IIS box by simply typing a string in the address line in
    > your browser. I know I've seen it before, but I can't seem to find it
    > amongst all the vulns for IIS and all the web logs that show up when you
    > google.
    >
    > I need this for a "security roadshow" that we're putting together, so I
    > can demonstrate how easy it is to break in to an unpatched box. Can
    > anybody point me in the right direction?
    >
    > I don't want exploit code. This is just a simple string that you enter
    > into the URL box in a browser. It's at least two or three years old, I
    > know.
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



    Relevant Pages

    • Re: Active Directory Authentication in IIS 6
      ... Dim obj As Object = entry.NativeObject. ... NMOWeb.FormsAuth.LdapAuthentication.IsAuthenticated(String domain, String ... need to keep it on 2000 with IIS 5.1 until we can figure it out. ... I generally recommend people just bind ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: Active Directory Authentication in IIS 6
      ... Dim obj As Object = entry.NativeObject. ... String username, String pwd) ... need to keep it on 2000 with IIS 5.1 until we can figure it out. ... bind against the RootDSE object on the domain controller: ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: Object reference not set to an instance of an object.
      ... > (running Windows XP, MSSQL2000, IIS) and it has been tested and ready ... > string username = person.Identity.Name.ToString; ... > Line 65: LdapConnection conn = ldUser.doConnect( ... > public LdapConnection doConnect(string username, string password, ...
      (microsoft.public.dotnet.framework)
    • RE: [Full-Disclosure] Unusual request
      ... > an unpatched IIS box by simply typing a string in the address line in ... I don't know about "root"ing an IIS system but the NIMDA method of ...
      (Full-Disclosure)
    • Re: Administrator rights issue with HTTP connectivity
      ... Dave - can you elaborate on item 2A - passing username a ... >1) You can run IIS and AS on the same machine, ... >string a domain username and pwd to impersonate on the ... >> I've defined a few permission groups to a cube. ...
      (microsoft.public.sqlserver.olap)