IIS HTR Exploit ?

From: r00t@online.ie
Date: 06/18/02


From: <r00t@online.ie>
Date: Tue, 18 Jun 2002 18:08:26 +0100
To: pen-test@securityfocus.com

Hi All,

Does anyone know of a working exploit for the IIS 5.0 HTR vulnerability.

I am pen-testing some hosts at present, they all seem vulnerable, based on the
eeye sample code.

Any help what-so-ever very much appreciated.

Thanks in advance.

Mark

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • SecurityFocus Microsoft Newsletter #196
    ... SecurityFocus ... MPlayer GUI File Name Buffer Overflow Vulnerability ... Relevant URL: http://www.securityfocus.com/bid/10612 ... Netegrity IdentityMinder is a tool designed for the Microsoft Windows platform to manage and maintain users and user accounts. ...
    (Focus-Microsoft)
  • Re: Medium Scale Scanning Best Practices
    ... network, ... > vulnerability rather than having to scan the entire network each time. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • SecurityFocus Microsoft Newsletter #191
    ... SecurityFocus ... MiniShare Server Remote Denial Of Service Vulnerability ... Relevant URL: http://www.securityfocus.com/bid/10409 ... Platforms: Windows 95/98, Windows NT ...
    (Focus-Microsoft)
  • RE: Scanners and unpublished vulnerabilities - Full Disclosure
    ... >> vulnerability. ... released with most of the other advisories. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: Vulnebrability level definition
    ... > vulnerability to it will have maximum impact," even though ... >> This list is provided by the SecurityFocus Security ... >> Intelligence Alert Service. ... >> SecurityFocus' SIA service which automatically alerts you to ...
    (Pen-Test)