Alexander01
Aug 21 2003, 12:34 AM
Anyone knows how you get an admin shell with the media hack.. i'm currently exploiting my scans with asd.exe but that one only creates a normal shell so i can't create a user or start/stop a service.. i think it MUST be possible to get an admin shell so you can do everything but i can't find the right tools for it.. help help help ... tnx in advance
studnikov
Aug 21 2003, 02:27 AM
Ive heard you can .. but with some kinda admindll. There was a tutorial for it a while back but i cant seem to find it again. Its possible to get a shell with admin rights i know forsure.
Alexander01
Aug 21 2003, 05:22 PM
a cople days ago i've seen a shell on port #34817 and that shell has admin rights, when you connect to it, it starts in a temp folder from a user or windows temp itself.. don't know that anymore... but my shell was on port 34816 and that admin on 34817 so it's possible yes, but how
Alexander01
Aug 24 2003, 08:34 AM
nobody that knows it?
isaiah
Aug 25 2003, 11:04 PM
has something to do with that admin.dll crap
illwill
Aug 26 2003, 01:36 AM
what exploit are you guys using... some sploits give you a shell in the conext of the currently signed on user.. and some give you NT_AUTHORITY/SYSTEM permissions.. so depending on the exploit you gotta figure it out.. or tftp yourself some priviledge escalation tools i started to write a paper on things to do from a NT shell its not finished yet but it should give u some pointers...
http://illmob.org/rootNT.html
Trio
Aug 26 2003, 02:06 AM
damn, I exploitd two boxes, but the permission is not enough to add a user...damn
ducky
Aug 27 2003, 02:58 PM
why do you need admin account for? you can start serv-u and other with regular account
spawn543
Aug 27 2003, 03:24 PM
| QUOTE (isaiah @ Aug 25 2003, 11:04 PM) |
| has something to do with that admin.dll crap |
u mean admdll.dll?
enlightnr
Aug 29 2003, 05:28 AM
You could try putting somethign like
on the box to escalate your priveleges. But from what Ive found when you get a shell with the Media exploit it will only give you the context of nsiislog.dll which is lower than IUSR_host.
dRf
Aug 29 2003, 10:56 AM
but ... hmmm - there must be any possibilty to get admin accs - i tried alot, but nothing works ;(
crackie
Aug 30 2003, 12:48 PM
most servers u cannot write in most folders ! but i think c:\temp or c:\winnt\temp is working fine ! u can execute and remove files in there
Alexander01
Aug 30 2003, 09:29 PM
we dont want that, we want full axx, we want to start a service stop a service make a user enz enz the full rights
CraZy_A
Sep 22 2003, 10:47 PM
| QUOTE (enlightnr @ Aug 29 2003, 05:28 AM) |
| You could try putting somethign like on the box to escalate your priveleges. But from what Ive found when you get a shell with the Media exploit it will only give you the context of nsiislog.dll which is lower than IUSR_host. |
iiscrack work on nt machines that are lower from win2k sp2 it includes nt 4
but the media bug is in the sp4 or in hotfix update i seen a win2k sp2 with media but not lower versions and iiscrack works on some sp2's....
skydance
Sep 23 2003, 07:02 AM
use a local exploit, like the one for named pipes.
ssj4conejo
Sep 24 2003, 04:00 AM
Can you start a batch file as a service?
CraZy_A
Sep 26 2003, 09:30 PM
whats the difference???
you cant add any service
MpR
Sep 27 2003, 08:59 AM
The Shell type you get all depends on the admin in front of the computer and the way that the comp its self is setup .. not on the exploit nor the port . You'll hit very few but you will hit the odd Admin acount where you can start / stop services, Best thing I could suggest is use tlist.exe Mircrosoft version seems to work better then a generic runs under the guest accounts easier and kill what processes yah want . Instead of installing the services using firedaemon etc .. Take a snap shot of your reg entries then install the service on your comp servu-u etc then edit those entries to a .reg. Start your FTP as per normal then execute the .reg wont usually add through the shell but will on FTP.
ZakOpath
Nov 1 2003, 05:05 PM
OFF TOPIC
404!!!
hey *.*.*.43 , coming from
http://forums.governmentsecurity.org/index...st=0entry6589 The file illmob.org/rootNT.html isn't here because i'm too lazy to fix it..
hey looks its your browser and ip !!! i r leet hax0r
*.*.*.43
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
PING!
Im Shaking
Kynroxes
Nov 1 2003, 06:16 PM
yes really cool :
but the HTTP banner is really easy to change ...
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.