IIS : access to cmd.exe and multiple commands on one line

From: Daniel Polombo (polombo@cartel-info.fr)
Date: 10/23/01


Message-ID: <3BD53160.5060800@cartel-info.fr>
Date: Tue, 23 Oct 2001 10:59:12 +0200
From: Daniel Polombo <polombo@cartel-info.fr>
To: pen-test@securityfocus.com
Subject: IIS : access to cmd.exe and multiple commands on one line

Hello,

   as you all know, it's possible to exploit a number of IIS bugs to gain
access to \winnt\system32\cmd.exe and execute arbitrary commands on the
server. I've been trying to convince it to execute several commands on one
line (as one would separate commands with a ';' under any decent shell), with
limited success : on a number of NT/2k boxes, the syntax :

    command1 & command2 (eg, cd .. & dir)

works fine. On some other boxes, though, it only returns 'The parameter is
incorrect'.

It is unclear to me whether this problem happens only because of the way the
request is made (http://path/to/cmd.exe?/c+command1&command2), or if there are
really different versions of cmd.exe.

I would assume the former, but I fail to see why it would work on some boxes
and not others, given the same commands and commands separator.

I've tried unicode-encoding the '&', with simple and double encoding (%26 and
%2526, respectively), but on the boxes which refuse plain '&', it doesn't work
either.

I'd like to get this to work in order to execute several commands on a remote
box in the same context (as opposed to several different connections), w/o
uploading anything to the box (yet :).

Any ideas would be welcome.

Regards,

   Daniel

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: invisible text box in Word 2007
    ... but if not here's another weapon to use in the battle... ... Click the Office button & select Word Options at the bottom of the menu. ... Select Customize from the left list, then All Commands from the Choose ... Special" as do two other text boxes in my documents (the two other text boxes ...
    (microsoft.public.word.pagelayout)
  • Re: Inserting Photo into Word Document
    ... Text boxes, by default are inserted with their layout property set to 'in ... commands on the down arrows adjacent to the bring to front/send to back ... Word MVP web site http://word.mvps.org ... There is no flexibility of moving these photos around ...
    (microsoft.public.word.docmanagement)
  • /etc/auto_master
    ... We hit a snag with a recent patch cluster upgrade on our Solaris 8 ... boxes. ... My co-worker did some research and found that several commands ...
    (SunManagers)
  • Re: Inserting MS Word 2007 file in MS Word 2007 document looses gr
    ... Insert tab - Object dropdown arrow - Text from File. ... Microsoft MVP (Word) ... > keyboard commands is still supported. ... > text boxes in the inserted file are no longer the correct size and text> is ...
    (microsoft.public.word.application.errors)
  • Re: Bad TOC alignment on the right (before the page number)
    ... the space is not entirely filled with boxes. ... (ignoring the grid entirely) ... So, to have the last dot at the right, I need to: ... change some of its commands. ...
    (comp.text.tex)