hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Alexander01
Anyone knows how you get an admin shell with the media hack.. i'm currently exploiting my scans with asd.exe but that one only creates a normal shell so i can't create a user or start/stop a service.. i think it MUST be possible to get an admin shell so you can do everything but i can't find the right tools for it.. help help help ... tnx in advance smile.gif
studnikov
Ive heard you can .. but with some kinda admindll. There was a tutorial for it a while back but i cant seem to find it again. Its possible to get a shell with admin rights i know forsure.
Alexander01
a cople days ago i've seen a shell on port #34817 and that shell has admin rights, when you connect to it, it starts in a temp folder from a user or windows temp itself.. don't know that anymore... but my shell was on port 34816 and that admin on 34817 so it's possible yes, but how wink.gif
Alexander01
nobody that knows it?
isaiah
has something to do with that admin.dll crap
illwill
what exploit are you guys using... some sploits give you a shell in the conext of the currently signed on user.. and some give you NT_AUTHORITY/SYSTEM permissions.. so depending on the exploit you gotta figure it out.. or tftp yourself some priviledge escalation tools i started to write a paper on things to do from a NT shell its not finished yet but it should give u some pointers... http://illmob.org/rootNT.html
Trio
damn, I exploitd two boxes, but the permission is not enough to add a user...damn mad.gif
ducky
why do you need admin account for? you can start serv-u and other with regular account
spawn543
QUOTE (isaiah @ Aug 25 2003, 11:04 PM)
has something to do with that admin.dll crap

u mean admdll.dll?
enlightnr
You could try putting somethign like
QUOTE
iiscrack.dll
on the box to escalate your priveleges. But from what Ive found when you get a shell with the Media exploit it will only give you the context of nsiislog.dll which is lower than IUSR_host.
dRf
but ... hmmm - there must be any possibilty to get admin accs - i tried alot, but nothing works ;(
crackie
most servers u cannot write in most folders ! but i think c:\temp or c:\winnt\temp is working fine ! u can execute and remove files in there smile.gif
Alexander01
we dont want that, we want full axx, we want to start a service stop a service make a user enz enz the full rights
CraZy_A
QUOTE (enlightnr @ Aug 29 2003, 05:28 AM)
You could try putting somethign like
QUOTE
iiscrack.dll
on the box to escalate your priveleges. But from what Ive found when you get a shell with the Media exploit it will only give you the context of nsiislog.dll which is lower than IUSR_host.

iiscrack work on nt machines that are lower from win2k sp2 it includes nt 4
but the media bug is in the sp4 or in hotfix update i seen a win2k sp2 with media but not lower versions and iiscrack works on some sp2's....
skydance
use a local exploit, like the one for named pipes.
ssj4conejo
Can you start a batch file as a service?
CraZy_A
whats the difference???
you cant add any service
MpR
The Shell type you get all depends on the admin in front of the computer and the way that the comp its self is setup .. not on the exploit nor the port . You'll hit very few but you will hit the odd Admin acount where you can start / stop services, Best thing I could suggest is use tlist.exe Mircrosoft version seems to work better then a generic runs under the guest accounts easier and kill what processes yah want . Instead of installing the services using firedaemon etc .. Take a snap shot of your reg entries then install the service on your comp servu-u etc then edit those entries to a .reg. Start your FTP as per normal then execute the .reg wont usually add through the shell but will on FTP.
ZakOpath
OFF TOPIC

QUOTE (illwill @ Aug 26 2003, 01:36 AM)
http://illmob.org/rootNT.html

404!!!
hey *.*.*.43 , coming from http://forums.governmentsecurity.org/index...st=0&#entry6589
The file illmob.org/rootNT.html isn't here because i'm too lazy to fix it..
hey looks its your browser and ip !!! i r leet hax0r
*.*.*.43
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
PING!

Im Shaking biggrin.gif laugh.gif
Kynroxes
yes really cool :

but the HTTP banner is really easy to change ...
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.