IE/Outlook/Pcanywhere

From: Gary O'leary-Steele (GaryO@sec-1.com)
Date: 09/24/01


From: "Gary O'leary-Steele" <GaryO@sec-1.com>
To: <PEN-TEST@securityfocus.com>
Subject: IE/Outlook/Pcanywhere
Date: Mon, 24 Sep 2001 10:44:26 +0100
Message-ID: <NFBBIPHNOKLPCLPGKOBHEECACBAA.GaryO@sec-1.com>

Hi,

Is there a brute force cracker available for Pcanyware? I have identified a
PCanywhere server using Nmap but many of the commercial scanners have not
recognized the pcanywhere server and therefore I need a specific tool for
the job.

I am also putting together a archive of useful IE/Outlook exploits which
execute Netcat or similar to demonstrate "hacking the internet user" as part
of our security auditing services. The security focus search engine seems to
be experiencing problems at the mo so as anyone got detailed information on
the new(ish) IE exploit as used by the nimda worm so I can implement it in a
non-viral way.

Many of our clients are SME's and they generally don't host many services
(in the uk anyway) and the day of misconfigured IIS servers are dwindling
due the wake up call issued from code red etc. In our opinion the use of
executing an inside-out shell exploited using client side IE exploits (such
as nc target 80 -e cmd.exe) will be the first attack attempted (against
smaller sme's) by script kiddies / ex-employees than port scanning the
firewall/router to find a vulnerable proxy with iis enabled etc (and all the
usual vulnerabilities left by an overworked IT admin). therefore I want to
put an archive together of code to exploit these weaknesses to expose these
vulnerabilities from a remote audit perspective rather than taking a box
with ISS on site to find the misconfigured workstations.

Thanx in advance for your assistance

Kind Regards
Gary O'leary-Steele
Sec-1

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • [Full-Disclosure] Disclosure Debate FW: [ISN] When to Shed Light
    ... Information security, in particular, cannot exist. ... full disclosure results in FEWER hands at work in this process, ... Microsoft because of how dependent publishers are on access to beta software ... > I think actively seeking vulnerabilities is just plain destructive. ...
    (Full-Disclosure)
  • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
    ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
    (microsoft.public.security)
  • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
    ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
    (microsoft.public.inetserver.iis.security)
  • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
    ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Can we prevent IE exploits a priori?
    ... Most all of the IE vulnerabilities that are being ... and the download sites should bring it offline shortly. ... Qwik-Fix Pro is a lot more than simple hardening of the My Computer zone in IE. ... It's an agent based distribution platform for security logic and is inching its ...
    (Bugtraq)