Re: Pwdump2 with UNICODE?

From: Tony Lambiris (methodic@libpcap.net)
Date: 08/09/01


Date: Thu, 9 Aug 2001 13:35:27 -0400
From: Tony Lambiris <methodic@libpcap.net>
To: "Sapiro, Benjamin R" <bsapiro@kpmg.ca>
Subject: Re: Pwdump2 with UNICODE?
Message-ID: <20010809133527.A15920@clotch.libpcap.net>

Ahh.. so you can basically echo a bunch of ftp commands to a file, run
the ftp client -s:filename.txt to have the box download cmdasp.asp, and
then you can just have that page execute commands?

Nice.

On 08.09.01, "Sapiro, Benjamin R" <bsapiro@kpmg.ca> wrote:
> Tony
>
> Under IIS4, CMDASP.asp executes in system level context so you are able to
> do that (CMDASP.asp has nothing to do with the unicode vuln. itself, we just
> use unicode attacks to get script up onto the box). You are right though, a
> unicode executed command by itself runs under IUSR context
>
> Ben Sapiro
> Information Risk Management
> (416) 777-8025
> www.kpmg.ca/irm
>
>
> -----Original Message-----
> From: Tony Lambiris [mailto:methodic@libpcap.net]
> Sent: Wednesday, August 08, 2001 1:46 PM
> To: Penetration Testers
> Subject: Re: Pwdump2 with UNICODE?
>
>
> I thought under UNICODE, you arent able to run such commands as rdisk
> and pwdump, because IIS runs as IUSR?
>
> On 08.07.01, Kevin Lam <kevinlam@packet-works.com> wrote:
> > Hi Allen,
> >
> > If you have UNICODE working, you could upload cmdasp.asp which will let
> > you execute commands on that server.
> >
> > If this is NT then what you can do is run "rdisk /s-" to silently update
> > the repair sam._ file (this is a little trick that I used to use when I
> > did pen-testing for Deloitte). Then go to c:\winnt\repair and copy
> > sam._ to say a public internet folder like c:\inetpub\wwwroot and then
> > go to your browser and just download the file.
>
>
> ******************************************************************************
> The information in this email is confidential and may be legally privileged.
> It is intended solely for the addressee. Access to this email by anyone else
> is unauthorized.
>
> If you are not the intended recipient, any disclosure, copying, distribution
> or any action taken or omitted to be taken in reliance on it, is prohibited
> and may be unlawful. When addressed to our clients any opinions or advice
> contained in this email are subject to the terms and conditions expressed in
> the governing KPMG client engagement contract.
> ******************************************************************************

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: Math (Greek) in XeLaTeX
    ... I'm having a problem getting Greek characters to display in XeLaTeX ... etc. normal LaTeX commands. ... fixltx2e.sty 2006/09/13 v1.1m fixes to LaTeX ... eu1enc.def 2010/05/27 v0.1h Experimental Unicode font encodings ...
    (comp.text.tex)
  • Re: mathit and mathbf dont go together
    ... different Unicode characters. ... later and it will be confusing to have commands with similar names ... I see no other chance than to take care for all of these packages ... OTF Math is very different from legacy math. ...
    (comp.text.tex)
  • Re: atof() and _tstof() in VC6.0
    ... The application is made with visual studio 6.0 and i want to be able to ... compile it with and without the _UNICODE preprocessor definition. ... atoicommands in _ttoicommands so it will suport both _UNICODE and ... > Do i need to upgrade to Visual Studio 7.x or can i download some package ...
    (microsoft.public.vc.mfc)
  • Re: atof() and _tstof() in VC6.0
    ... The application is made with visual studio 6.0 and i want to be able to ... compile it with and without the _UNICODE preprocessor definition. ... atoicommands in _ttoicommands so it will suport both _UNICODE and ... > Do i need to upgrade to Visual Studio 7.x or can i download some package ...
    (comp.lang.cpp)
  • Re: Converting data into Unicode
    ... I tried with windows being the client and it did work, that is I got the file transfered down and it was in Unicode, big endian. ... However write/wordpad had a problem reading the file with the file, it seem to know that it was Unicode, but I think it assumed little endian. ... If the ftp software (either the client or the server) on the HP-UX box does not support it, ... When you an ASCII file transfer this tells both the server and client that the data will be in "virtual telnet ASCII". ...
    (bit.listserv.ibm-main)