Stunnel / Unitools / IIS Question

From: Steven Kieffer (skieffer@ebiz-tech.com)
Date: 12/13/01


From: "Steven Kieffer" <skieffer@ebiz-tech.com>
To: <pen-test@securityfocus.com>
Date: Thu, 13 Dec 2001 10:17:57 -0700

I've got a problem. I've used the handy dandy unitools (by Roelof
Temmingh), Unicodeloader.pl script to upload its upload.asp and upload.inc
files to the victim IIS server with the various IIS folder traversal
vulnerabilities. This worked like a charm every time via port 80.

I now have a client with an IIS server on port 443 with the msadc.dll
vulnerability. I was able to take advantage of the vulnerability to copy
cmd.exe into the /scripts directory. We modified the Unicodeloader.pl
script to use the now available cmd.exe.

In order to run the utility, I attach via Stunnel. The upload works and
both the upload.asp and the upload.inc get up the IIS servers webroot. The
only problem is that in the transferred upload.inc script, every instance of
+ is replaced with a space.

Not sure why this is happening. All I know is that when I upload the
upload.inc file via straight port 80 it's fine and going through Stunnel the
+ is replaced with a space.

My goal is to get Netcat up there (of course).

Does anybody know what Is going on here and what I can do to get around it?

Steven Kieffer, CISSP

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Troubleshooting: HTTP/1.1 New session failed
    ... I'm running into an issue on my IIS server. ... that we have a script with an unclosed database ... connection or some bad code causing a memory leak. ...
    (microsoft.public.inetserver.misc)
  • Re: Active Directory Isolation
    ... Where do you run this script from the AD server or the IIS server. ... > Set it via iisftp.vbs script - refer ... >> cant find where to set the FTPRoot and FTPDir properties. ...
    (microsoft.public.inetserver.iis.ftp)
  • uploading and processing a password protected word document with asp
    ... An ASP page on my IIS server converts an uploaded word document to ... requesting password on server!) ... refuse to upload it, until the user has removed the protection. ...
    (microsoft.public.scripting.vbscript)
  • Mime type?
    ... I have a customer who is trying to upload to their FTP on my Windows 2000 ... IIS server, the problem is they are using McIntosh/Apple computer and they ... have no File Extensions and they seem to be having problems... ... MIME TYPE that I should add to the server so they can upload this type of ...
    (microsoft.public.inetserver.iis)
  • Re: Please Help!Error loading Microsoft ActiveX Media Player
    ... > I am using IIS Server and when user loading this page from the Internet ... If you use script then you usually get a line number with the error ... Permission denied occurs mostly when a script in one window or frame ...
    (microsoft.public.scripting.jscript)