hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Iis 4 Help!
sattete
Hi I have a server to hack , the only two high vulnerabilities after scanned with retina are those:


Web Servers: TCP:80 - Malformed HTR Request - NT4
Description: A vulnerability in IIS involves an unchecked buffer in the filter DLLs for the following file types: .HTR, .STM and .IDC files. The .htr, .STM and .IDC extensions are used by ISAPI filters so an attacker can therefore overflow those ISAPI filters and remotely execute code as SYSTEM.


Web Servers: TCP:80 - IIS HTR ISAPI chunking buffer overflow
Description: A vulnerability in IIS involving the processing of chunked HTTP data and its use by the HTR ISAPI, can be exploited by an attacker to remotely execute code of his choice.
Risk Level: High


I try to use iishack.exe with ncx but dont success sad.gif

anyone know other exploit for have a command shell?
CraZy_A
nope but i know hot to get system level on iis 4
loads of exploits work on it
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.