📄 ntsec.html
字号:
<b><Cypher></b> (command prompt)<br>
<b><Cypher></b> so a malicious hax0r could<br>
<b><The_Duke247></b> lol@hax0r<br>
<b><Cypher></b> execute something by using the following string:<br>
<b><Cypher></b> domain/scripts/yadayadayada.bat?&command1+?&command2+?&..........<br>
<b><Cypher></b> and it will be executed as batch commands<br>
<font color="#ff0000">*** Cypher sets mode: -m</font><br>
<b><Cypher></b> go go go :)<br>
<b><m0ded></b> hehe<br>
<b><Slayer></b> yeah<br>
<b><snider></b> lol<br>
<b><dr3x></b> It would run in system context (root)?<br>
<font color="#ff0000">*** Cypher sets mode: +v snider</font><br>
<b><m0ded></b> plx devoice The_Duke when u have +m<br>
<b><Slayer></b> cypher u are the man<br>
<b><Cypher></b> m0ded, fine<br>
<b><The_Duke247></b> whhhy ?<br>
<b><m0ded></b> he keeps talking<br>
<b><The_Duke247></b> what ?<br>
<b><Cypher></b> any questions/comments/corrections/suggestion/yada_yada_yada?<br>
<b><Cypher></b> The_Duke247, nm it now<br>
<b><dr3x></b> Would the batch run with root privs?<br>
<b><Cypher></b> dr3x, it will run with system privs<br>
<b><The_Duke247></b> shouldn't the question be would it run without ?<br>
<b><Cypher></b> no, it wouldn't<br>
<b><Cypher></b> the ? delivers the params<br>
<b><dr3x></b> k<br>
<b><m0ded></b> its something like phf<br>
<b><The_Duke247></b> no, ? was part of my own question<br>
<font color="#ff0000">*** syfilis84 has joined #bsrf</font><br>
<b><The_Duke247></b> not syntax lol<br>
<b><Cypher></b> but (hate to disappoint ya) it was fixed and patched by Billy
:)<br>
<font color="#ff0000">*** syfilis84 has left #bsrf</font><br>
<b><snider></b> ouch, nice nick.. syfilis<br>
<b><Slayer></b> grr<br>
<b><Cypher></b> let me now explain what exactly happens and why<br>
<b><Cypher></b> (in that issue)<br>
<b><Cypher></b> so it goes like das: /scripts/lalala.bat?&dir+c:\+?&time<br>
<b><Noon_Ghunna></b> cypher u reading some book? :)<br>
<b><QX-Mat></b> hey, keep him away!<br>
<b><Cypher></b> then the following occurs<br>
<b><Cypher></b> Noon_Ghunna, i made notes to myself earlier :)<br>
<b><Cypher></b> i can't remember everything :)<br>
<b><QX-Mat></b> I hear that syfilis.... oh god I had sex ed only last week!<br>
<b><Cypher></b> so<br>
<b><The_Duke247></b> gotta run... my errr bath is overflowing?<br>
<b><The_Duke247></b> :)<br>
<b><The_Duke247></b> ciao boys and girls<br>
<b><Cypher></b> later<br>
<b><m0ded></b> bye<br>
<b><m0ded></b> go on<br>
<b><Cypher></b> i'm continuing<br>
<font color="#ff0000">*** Cypher sets mode: -v The_Duke247</font><br>
<font color="#ff0000">*** aragorn has quit IRC (Quit: Leaving)</font><br>
<font color="#ff0000">*** The_Duke247 has quit IRC (Quit: Leaving)</font><br>
<b><Cypher></b> the first thing is the browser asks u to save the doc or view
it with a viewer<br>
<font color="#ff0000">*** head__ has joined #bsrf</font><br>
<b><Cypher></b> then it starts a download session<br>
<b><m0ded></b> downloading what?<br>
<b><Cypher></b> the file<br>
<b><Cypher></b> e.g. "Save or Open"<br>
<b><Cypher></b> u know<br>
<b><Cypher></b> lalalal.bat<br>
<b><m0ded></b> yeah<br>
<b><QX-Mat></b> I can type with my nose! Look. .s<br>
<b><Cypher></b> u click "cancel" but it never termintes cause u used
the "time" command :)<br>
<b><QX-Mat></b> h;lkl:<br>
<b><snider></b> hmm, maybe +m would help<br>
<font color="#ff0000">*** Cypher sets mode: +m</font><br>
<b><Cypher></b> oh, and _nothing_ is logged on the server<br>
<b><Cypher></b> cause it was never terminated<br>
<b><Cypher></b> the only way is to check ALL the security logs<br>
<b><Cypher></b> which is a veeery long thing on a large network<br>
<b><Cypher></b> and we know, that admins hate logs ;-)<br>
<b><Cypher></b> that's their default state of mind<br>
<b><Cypher></b> so, in conclution, the hax0r (e.g. script kiddie) could excute
his milicions code like das<br>
<font color="#ff0000">*** zzorro has joined #bsrf</font><br>
<b><Cypher></b> and of course there is no *.bat files in the /scripts dir, but
windows mapped it<br>
<font color="#ff0000">*** Rockin_lad has quit IRC (Ping timeout)</font><br>
<b><Cypher></b> so it "gotta" use it :)<br>
<font color="#ff0000">*** zzorro has left #bsrf</font><br>
<b><Cypher></b> that ends it for this exploit<br>
<font color="#ff0000">*** Cypher sets mode: -m</font><br>
<b><Cypher></b> q?<br>
<b><m0ded></b> nope<br>
<b><snider></b> yes<br>
<font color="#ff0000">*** drednought has joined #bsrf</font><br>
<b><Cypher></b> shoot snid<br>
<b><snider></b> is input validation and wrong file permissions all there is to
ISS vulns?<br>
<b><snider></b> IIS*<br>
<b><Cypher></b> hey drednought. we're having a lecture here, you're welcome to
join in<br>
<font color="#ff0000">*** zzorro has joined #bsrf</font><br>
<b><zzorro></b> olá<br>
<b><Cypher></b> snider, nah, its just plain old stupidity also :)<br>
<b><Cypher></b> hey zzorro<br>
<b><zzorro></b> io<br>
<b><zzorro></b> dd tc?<br>
<b><drednought></b> thanks<br>
<b><snider></b> what about bufferoverflows in IIS?<br>
<b><snider></b> or other stuff alike<br>
<b><Cypher></b> but we don't want that now, do we?<br>
<b><Slayer></b> yes<br>
<b><snider></b> okay<br>
<b><Slayer></b> lol<br>
<b><Cypher></b> next thing on the chapter - FrontPage-Server Extentions-based
IIS holes<br>
<b><snider></b> wee<br>
<b><snider></b> :)<br>
<b><Cypher></b> Frontpage is one hell of a program when it comes to security....
;-)<br>
<head__> Cypher: sure is true ;)<br>
<b><Cypher></b> it has something like ZERO security features<br>
<b><Cypher></b> not to mention, its a lousy editor :)<br>
<b><m0ded></b> yup<br>
<b><snider></b> and Frontpage-server is also an IIS webserver app?<br>
<b><Noon_Ghunna></b> Frontpage is one hell of a program when it comes to security
<--- and web page making too :)<br>
<b><Cypher></b> its a server extention<br>
<b><Cypher></b> <b>[Cypher]</b> not to mention, its a lousy editor :)<br>
<font color="#ff0000">*** zzorro has quit IRC (Quit: Leaving)</font><br>
<b><Cypher></b> FP has caused many problems to IIS<br>
<font color="#ff0000">*** Rockin_lad has joined #bsrf</font><br>
<b><Noon_Ghunna></b> Cypher! is FP a webserver too?<br>
<b><m0ded></b> yeah<br>
<b><Cypher></b> no, an extention (add-on)<br>
<b><m0ded></b> no<br>
<b><snider></b> no, he just said that<br>
<b><m0ded></b> heh<br>
<b><Cypher></b> lol@m0ded<br>
<b><QX-Mat></b> FP Exploits..... we gonna be here for ever!<br>
<b><snider></b> cypher, please go on :)'<br>
<b><Cypher></b> FP "throws" all kind of dirs to your web, in the form
of: _vti_xxx<br>
<b><drednought></b> are you taking about local security problems or remote?<br>
<b><Cypher></b> QX-Mat, just the basics<br>
<b><Cypher></b> remote<br>
<b><QX-Mat></b> ah<br>
<b><Cypher></b> (now)<br>
<b><Cypher></b> FP sometimes get so stupid it actually _shows_ you its _own_
password file... imagine that....<br>
<b><snider></b> passwords to do what=<br>
<b><zar></b> Did i make it for the lecture??????<br>
<b><snider></b> ?<br>
<b><Rockin_lad></b> hey zar , wuz up ?<br>
<b><Cypher></b> for example, if directory browsing is allowed, and proper permission
not set (not NTFS for example)<br>
<b><zar></b> just woke up :)<br>
<b><Cypher></b> the user could get the file list of the dir<br>
<b><Cypher></b> a known password file: domain/_vti_pvt/service.pwd<br>
<b><Cypher></b> it is encrypted of course<br>
<font color="#ff0000">*** QX-Mat is now known as QX</font><br>
<b><zar></b> @#$%ing daylight savings time<br>
<b><Cypher></b> (FP is not _that_ dumb)<br>
<b><Cypher></b> but with standard DES<br>
<b><snider></b> hehe<br>
<b><snider></b> what are the passwords used for?<br>
<b><Cypher></b> which will make no prob usually<br>
<b><Cypher></b> snider, u don't know what to do with passwords?? man..... :-)<br>
<font color="#ff0000">*** han has joined #bsrf</font><br>
<b><QX></b> the passwords are creted using the crypt() command<br>
<b><snider></b> no i mean, are they access passwords for the NT system?<br>
<b><QX></b> no<br>
<b><Cypher></b> no<br>
<b><Cypher></b> web ones<br>
<b><Cypher></b> another exploit (in case u find anony ftp writable and fp extentions,
of course)<br>
<b><Cypher></b> u could upload a file to the _vti_bin dir<br>
<b><QX></b> cos it's public!<br>
<b><Cypher></b> and issue the following: domain/_vti_bin/your_file<br>
<b><snider></b> im still baffled about this "web passwords" thing..<br>
<b><Cypher></b> and the server will be glad to execute your malicious file :)<br>
<font color="#ff0000">*** han has quit IRC (Quit: Leaving)</font><br>
<b><Rockin_lad></b> wow , what a bug unfortunatley I'm still learnin ASP <br>
<b><m0ded></b> Cypher the dir _vti_bin always exist through ftp?<br>
<b><Rockin_lad></b> :)<br>
<b><Cypher></b> snider, FP extentions has a password protection system for your
web (FP is also a web manager)<br>
<b><QX></b> mkfs_dos....<br>
<b><dr3x></b> what kind of files can be executed in _vti_bin?<br>
<b><Cypher></b> m0ded, depends on the permissions<br>
<b><Cypher></b> we are not talking on how to get it ther<br>
<b><Cypher></b> e<br>
<b><Cypher></b> i'm saying that it'll be executed<br>
<b><snider></b> okay, and by web manager you mean that you can upload through
it?<br>
<b><Cypher></b> dr3x, executable ones :)<br>
<b><QX></b> Simple mime post<br>
<b><Cypher></b> snider, it manages your site. the permissions, uploads, safety,
passwords (e.g. permissions), etc.<br>
<b><Cypher></b> when u have the password<br>
<b><m0ded></b> u can deface it<br>
<b><Cypher></b> u just go to your local (argh)<br>
<b><Cypher></b> copy of FP<br>
<b><Cypher></b> and logon<br>
<b><Cypher></b> to the remote site<br>
<font color="#ff0000">*** SteeLe has joined #bsrf</font><br>
<b><QX></b> SAVE THIS MAN: http://www.elfqrin.com/elfcam.jpg<br>
<b><m0ded></b> hehe<br>
<b><snider></b> ahh i see..<br>
<b><Cypher></b> hey SteeLe<br>
<b><Cypher></b> you're a bit late for the lecture<br>
<b><SteeLe></b> hi<br>
<b><SteeLe></b> what lecture?<br>
<b><Cypher></b> but no biggy, just two hours :)<br>
<b><m0ded></b> heh<br>
<b><m0ded></b> NT Security<br>
<b><zar></b> lol<br>
<b><SteeLe></b> aaahh the NT Security lecture<br>
<b><SteeLe></b> I just remembered about it<br>
<b><m0ded></b> yeah, remember?<br>
<b><m0ded></b> ;p<br>
<font color="#ff0000">*** SteeLe has quit IRC (Quit: 7th Sphere v3.0 © 1997 7th Sphere Enterprises)</font><br>
<b><Cypher></b> hehe<br>
<b><Cypher></b> he went to his time machine :)<br>
<b><m0ded></b> he left us<br>
<font color="#ff0000">*** Megram has joined #bsrf</font><br>
<b><m0ded></b> go on Cypher<br>
<b><Cypher></b> i wanted to have a little war game at the end, but unfortunatly
i had
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -