blackP0ster
Dec 10 2003, 07:47 PM
hiho!
does anybody know something bout a new (maybe bit older) frontpage vuln?
if yes, does anybody has an exploit for this vuln?
scans look like that "Frontpage enable"
thx
black
cyrixx
Dec 10 2003, 08:06 PM
do you mean
http://www.k-otik.com/exploits/11.13.fp30reg.c.php ?
cgi-scanner: /_vti_bin/_vti_aut/fp30reg.dll
blackP0ster
Dec 10 2003, 08:30 PM
nize!
big thx..but..
does anyone has a compiled version?
black
cyrixx
Dec 10 2003, 08:48 PM
hxxp://www.securitylab.ru/_exploits/fp30reg.exe
Hellraiseruk
Dec 10 2003, 09:00 PM
u don't get admin wrights and when it trys to drop shell freezes with both versions of this exploit
liquidSilver
Dec 10 2003, 09:10 PM
No request allowed.
Divx_dude
Dec 10 2003, 09:50 PM
well u DO get admin rights only on pefici dirs dude
try c:\
or c:\inetpub

worked for me so
blackP0ster
Dec 10 2003, 10:12 PM
normaly u only get write and execute rights in c:\ or c:\inetpub\
but not in the system-root (e.g. c:\winnt\)
so you don't have "real" admin-rights
thx for the prog + x-ploit!black
temptation
Dec 11 2003, 05:47 PM
Hi,
Does anyone know which scanner i have to user to scan 4 this exploit?
thx
cyrixx
Dec 11 2003, 06:18 PM
*klick*sorry, but i have already written it in my posting
blackP0ster
Dec 11 2003, 07:54 PM
simply add "/_vti_bin/_vti_aut/fp30reg.dll" to your cgi-scanner-list and start scannin'

black
Divx_dude
Dec 12 2003, 09:57 AM
there's a Sfind for it that does it remotly

when i am home from school il put it into downloads topic
cya mates
temptation
Dec 14 2003, 04:42 PM
sry bt i really dunno how 2 scan 4 it ...
i don't find a cgi scanner where i add custom scans ..
Can i scan with xscan?
do i have to add it to "cgi.lst"?
Which item do i have to check to scan for it?
Can I remove all the other items, because i just want to scan 4 Frontpage?
Thx
SkyRaVeR
Dec 14 2003, 10:47 PM
You just need 2 scan for IIS... just use (e.g. dsns or your favourite scanner) and scan 4 port 80 with get banner function on.. if you're ready you gotta export results like ping $i or so,,,
but well, let me tell you that i had the experience that only every 1000th ip is vuln. suXX ass - bad results!
320X
Dec 15 2003, 12:09 AM
only the Windows 2000 Professional SP3 English version (fp30reg.dll ver 4.0.2.5526) is affected ?
teest
Dec 15 2003, 02:44 PM
I try many servers on Win2000 and no one work :/ Have anyone another offset?
limbox
Dec 15 2003, 02:45 PM
yes, only sp 3
Xion
Dec 15 2003, 04:05 PM
yes for Sp3 ...
blackP0ster
Dec 15 2003, 06:01 PM
hm..fuckin' bad results

does somebody has a scan-checking tool?? or can code on

black
predx
Dec 15 2003, 07:23 PM
Yeah thanks for the exploit and scan context.
Cyrus
Dec 15 2003, 08:14 PM
guys, the exploit doesnt works. sometimes it says: Dropping to Shell
But then it hangs ups...
blackP0ster
Dec 15 2003, 08:54 PM
one time it worked..aftr trying bout 50scans (manual)
so i search (again and again) a scan-checker
SkyRaVeR
Dec 16 2003, 01:07 PM
hmm - scanchecker? just user a simple .bat file ! But as I said before.. too few servers are vuln (ony sp3).
if shell freezes you might have connected 2 another app running on that port.. had several mistakes - even .html code returned.. maybe patched?!
blackP0ster
Dec 16 2003, 01:59 PM
i've already thought bout a batch file..
but don't know how to go on!
my problems:
- to give the batch file the ips
- to go on checkin' when a host doesn't answer
- to log vuln servers in a file..
SkyRaVeR
Dec 16 2003, 05:25 PM
| CODE |
cls echo ############################### echo * frontpage autohaXXor * echo * (c) 2003 bySkyRaVeR * echo ############################### for /f "eol=; tokens=1*" %%i in (scan.txt) do fp30reg %%i
|
just make sure scan.txt contains only ips and is in same folder...
enjoy, sky
blackP0ster
Dec 16 2003, 07:43 PM
big thx!
worked out quit well

black
rastis_monkey
Dec 19 2003, 05:05 AM
ty
gunknown
Sep 26 2004, 01:00 PM
| QUOTE (SkyRaVeR @ Dec 16 2003, 05:25 PM) |
| CODE | cls echo ############################### echo * frontpage autohaXXor * echo * (c) 2003 bySkyRaVeR * echo ############################### for /f "eol=; tokens=1*" %%i in (scan.txt) do fp30reg %%i
|
|
nice.....I'm very gradefull for this kind of autohaxxor. I often thaugt about such a batch, but didn't know how to write it!
Thanks alot.......
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.