hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Webdav Errors?
RizL4
i keep getting this when i'm trying too hax webdav

Checking ntdll.dll buffer overflow .....CONNECTED
send evil buffer ........ VULNERABLE
Connecting to <ip address> .........CONNECTED
trying ret addr 0x00d000d0 .........DONE
Waiting for IIS to restart .........CONNECTED

and it keeps saying Waiting for IIS to restart
Waiting for IIS to restart
Waiting for IIS to restart
Waiting for IIS to restart
Waiting for IIS to restart

..................ERROR
The server hasn't been restarted in 120sec
There is a problem.
Aborting...

can anyone exsplain what iam doing wrong or does it take long too restart thanxs

Riz
3plx
in my opinion about webdav and all iis stop scaning that the chances that u find some thing is very low io once scanned whole range for media found 1000 res 1 give me shell
so i think it useless to scan it
RizL4
how can u say that i get VULNERABLE
servers
willywutz
The error means that the IIS after you tried to exploit donīt restart.
It died. And need a reboot.
Cyrus
Yes, IIS is crashed u got to wait until the admin reboots it.
U'll need much time to get a shell via webdav. Maybe there are a few server vulnerable, but the exploit isnt the best, u need much luck to brute the correct padding.
andydis
that erros on the old version of webdav exploit, get Kaht, its better than the one u r using (morning wood's one possibly?)
Masterace
HI I tried out the webdav exploit and the exploit was buisy for 45 min and then it said Sorry....Host not vulnerable!My question is where can i find a tool like ptwebdav with one difference,the tool should be able to scann a hostfile for vulnerabilitys?You know,like wingate verifyer but only for webdav exploits?(I used the search function but only found Ptwebdav)
The Doom Master
QUOTE

HI I tried out the webdav exploit and the exploit was buisy for 45 min and then it said Sorry....Host not vulnerable!My question is where can i find a tool like ptwebdav with one difference,the tool should be able to scann a hostfile for vulnerabilitys?You know,like wingate verifyer but only for webdav exploits?(I used the search function but only found Ptwebdav)



check out this site it explains about the appz for Exploiting Webdav Servers

http://www.lurhq.com/webdav.html
PL3X59
RizL4 I have the same in the Exploit sad.gif
I think it is very difficult to find a server who can be hacked now.

So u can scan ... but i think u'll not have good results dry.gif
If u find some one ... you R a lucky boy hihi rolleyes.gif

Pl3X
The Doom Master
PL3X59 is right most of the Webdav Servers are secured today... blink.gif
Too Bad! sad.gif
PL3X59
Hi there ... :-p

I think that most of people like me would like to do a pub stro with this hole.
I is possible, yes.

There is a lot of stromaker here.

But there is a lot of holes ...

U can try the dameware exploit, mydoom exploit for example, this Radmin holes ...
U can also try to find the netsky source code ...

I don't try to use this hole. I have not enough knowledge in programmation and in network. but I think this is not very difficult with the good toolZ rolleyes.gif

I'll try and try :-p


sorry for my bad english [ : : I'm french : : ]


But if you want to use this hole ... why not install a server at home in your network to test it :-p


byebye
see U :-)
Masterace
@Doom Master thx 4 the link but i'm only searching for an webdav scanner
right now i'm using webdavscan.exe but you have to recheck every single ip if it's hackable.You need to put every f..... ip for it's own into Ptwebdav,click on check wait a moment type the next ip.That sucks.I need a programm to check a complete host list.Something like the functions of exploitmanager!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.