privelege escalation with .bat files



Hi. I'm pen-testing an IIS 5.0 server that is insecurely set up to allow write-access to it as a web folder. However, its also set up to deny copying (or renaming to) of the following file extensions .asp, .com, .cmd, .exe, and .dll. Interestingly, it does allow .bat files to be written onto the server. Is there a way to escalate privelleges (and possibly get a command prompt) through a .bat file? Thank you,

--ben



------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request@xxxxxxxxxx for details.
------------------------------------------------------------------------------



Relevant Pages

  • Re: bypassing employers proxy to surf anonymously
    ... This mentions an internal server that allows recursion. ... And even if it does, its the NS that does the recursion, not the local resolver. ... You have an option to go with a managed service or an enterprise software. ... Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. ...
    (Pen-Test)
  • Re: SMTP over HTTP traffic, looks fishy.
    ... Also make sure that u have high alert on SMTP and HTTP ... for the SMTP server and crashing it eventually. ... a managed service can ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)
  • Re: sniffing plaintext protocols
    ... Take a look a stunnel to use your old pop3s server without any ... I guess PGP/GPG are your friends if you want to protect your mail ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)
  • RE: VmWare and Pen-test Learning
    ... Setup a tftp server on your client machine. ... Use John the Ripper to crack the passwords. ... (dictionary attacks, brute force, single mode). ... Download FREE whitepaper on how a managed service can help ...
    (Pen-Test)
  • Re: httpd fingerprinting
    ... I normally use banner grabbing, nmap, and httprint for fingerprinting httpd servers. ... you need to proactively protect your applications from hackers. ... Download FREE whitepaper on how a managed service can ... Netscape Enterprise Server ...
    (Pen-Test)