hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: IIS Hacking
Jay
I have a basic understanding of how to secure/attack a windows 2000/XP network and would like to learn about the IIS web server.Should i start with learning about the essentials of HTTP ? Bit of a loss where to start.
dissolutions
Reading the RPC wouldn't harm smile.gif. But learning the basics of the HTTP would allow you to understand the more "advanced" stuff easier than if you were to jump right in.

I have a few links at home but I am currently away from it however when I do get home I'll post some links.

Microsoft has a few IIS Security Guides as well which you may want to take into consideration of reading.
Also GSecur posted a nice article at http://www.governmentsecurity.org/forum/in...ct=ST&f=13&t=67 if you haven't read this you may want to take a look over it.
Jay
Thank's for that.What do you mean by the RPC ?
dissolutions
o sorry RFC I wasn't thinking, working on Remote Call Procedures in class at the time and thinking about something and doing something else doesn't work sometimes. tongue.gif

Some Links:
http://www.wittys.com/files/mab/iis-hacking.html
http://www.techrepublic.com/trsignup/tr_sh..._requestid=2057
http://support.microsoft.com/default.aspx?...&NoWebContent=1
http://www.jsiinc.com/subi/tip4000/rh4036.htm
http://www.astalavista.com/library/hardening/iis/
http://www.astalavista.com/library/auditing/webcode/
http://www.astalavista.com/library/os/iis/

Not much but interesting reading smile.gif
Sorry about the RFC and the delay school is hell.
zip
sorry..delete this post please...better read up on the sites policy first smile.gif
GSecur
Thanks for trying to keep the site clean zip, But I actually have no problem with the post. Especially when it is posted in the newbies section. When I said, try to refrain from "How do I hack' I literally meant that phrase.

If dissolutions thought it was within bounds I have no problem with it.
dissolutions
Thanks Zip keeping on my feet smile.gif

QUOTE
I have a basic understanding of how to secure/attack a windows 2000/XP network and would like to learn about the IIS web server.Should i start with learning about the essentials of HTTP ? Bit of a loss where to start.


What i decided upon reading this post was simply that, they wanted information smile.gif And being around script kiddie newsgroups I have been accustomed to the "Can you tell me how to hack hotmail" and things just as blunt as that smile.gif, So I didn't think twice, my apologies.
Jay
I thought i had read most things on the site but i can't seem to find the sites policy. sad.gif
Zip i am interested in why you think my post should be deleted ?Isn't this a valid question ?
dissolutions
QUOTE (Jay @ May 24 2003, 04:08 AM)
I thought i had read most things on the site but i can't seem to find the sites policy. sad.gif
Zip i am interested in why you think my post should be deleted ?Isn't this a valid question ?

Yes, Jay it is a valid question...

But in the Forum Index page where it says Beginners Section It says
QUOTE

Beginners Section
If you are a Beginner to Network Security, then post your questions here. Anything goes but try to refrain from "How do I learn to Hack?" This forum is about security.
Forum Led by: dissolutions


The question you asked can be taken a number of different ways... Like myself, I saw it as a valid question, whereas some other people didn't.

I'll be talking with GSecur and working things out completely and smoothening this subject down smile.gif
Kross
Nice Links!

Alot to learn! ohmy.gif
zero-maitimax
rpc is something diffrent then iis... exploit i think..
babbacool
Thanks for all the links dissolutions.....

Interesting with that we can learn instead of asking how can I do to hack... ?
AdmiralB
to hack learn the basics smile.gif
randalizm
your gonna try telling a moderater to delete his own post!!

sorry dude you should take a look at the left of the page especially at the post count!

And thats something I havent seen on the site" remote procedure calls"!

maybe a tutorial Dissolution tongue.gif ???? or at least a Link or two
Jay
QUOTE
your gonna try telling a moderater to delete his own post!!

This was written well before i was a made a moderator.
I really don't mind people having different views to mine as long as it's disscussed in a proffesional manner.


QUOTE
sorry dude you should take a look at the left of the page especially at the post count!


Post count really means just how long you've been around.It should always be quality rather than quantity but thank's for the concern randalizm wink.gif
randalizm
hehe sorry didnt realize that at that time you werent a mod untill i checked the dates on the posts and stuff<_< the post just looked really funny
wink.gif apologies for buttin in! wink.gif

also ive been hearing an IIs exploit replacing the "h" in "http://" with its hex equivalent to run remote commands?????? can any one point me in a direction
hottzo
thx 4 the tut m8
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.