Re: cmd.exe / root.exe question

From: Matt Andreko (mandreko@ori.net)
Date: 08/27/01


Message-ID: <004101c12f13$24672c70$2101a8c0@mandreko>
From: "Matt Andreko" <mandreko@ori.net>
To: <karl_napp3@gmx.li>, <focus-ms@securityfocus.com>
Subject: Re: cmd.exe / root.exe question
Date: Mon, 27 Aug 2001 11:12:59 -0500

You may have to have the folder as "Executable" instead of "Scriptable". I
know that when i wanted to run some .exe cgi scripts (bad me...) i had to
make it executable or the files wouldn't execute

----- Original Message -----
From: <karl_napp3@gmx.li>
To: <focus-ms@securityfocus.com>
Sent: Saturday, August 25, 2001 2:29 PM
Subject: cmd.exe / root.exe question

> Where exactly is the risk a cmd.exe (under what name ever) is placed in a
> scriptable directory? I've put cmd.exe into wwwroot under iis5 and gave
> scripting to the file.
> Now tried to remotely execute it. I didn't succeed to get a remoteshell.
Via
> IE5 I could exceute the file but got a local shell, only. Netcat with 'nc
> <ip> 80 -v' and 'GET /cmd.exe HTTP/1.0\n' gave my soundchip a ride to hell
when
> interpreting all the beeps ;-)
>
> If cmd were boud to any port and listening I'd see security implications.
> But with only a file lying around?
>
>
> --
> Karl
>
> --
> GMX - Die Kommunikationsplattform im Internet.
> http://www.gmx.net
>
>
>



Relevant Pages

  • Re: Problem with IIS 6.0 serving .NET applications
    ... It's working now because you need to have "scripts and executable" ... > to "None" and I'd get the content of the exe shown in the browser, ... >> Did you set Application & Scripts execute permissions? ... >>> execute permission on that Virutal Directory, ...
    (microsoft.public.inetserver.iis.security)
  • Re: HTTP 403.1 Forbidden: Execute Access Forbidden
    ... This sounds like an Visual InterDev behavior/requirement -- I really have no ... execute ASP script, you MUST have the "Scripts" execute permission [so ... scripts and executables is not necessary to run the default.asp page]). ... IIS is merely doing what you configured. ...
    (microsoft.public.inetserver.iis)
  • [UNIX] cPanel mod_php suexec Taint Vulnerability
    ... Get your security news from a reliable source. ... There exists a security issue in cPanel installed systems due to how ... a user is able to execute arbitrary code ... all PHP scripts are executed as the same user ...
    (Securiteam)
  • Re: Nearly undocumented NT security feature - the solution to executable attachments?
    ... Windows NT users cannot defend from e-mail borne malware, ... KH> Instead of boring you with a lesson on Windows NT security, ... execute access, like in Unix, is distinct from read ... KH> please note that, as I said earlier, this won't stop scripts (except batch ...
    (Bugtraq)
  • Re: There is a new GPS on the block
    ... about how Apache decides which files to serve as text and which to ... scripts, too, because their names match the same pattern. ... why I wouldn't want to execute scripts, ... If the Israelis are to lay down their arms ...
    (rec.motorcycles)