thavirus
Aug 11 2003, 11:40 PM
hello
if connected to a comp while using the iis media service bug. If tftpd all my stuff to the comp. But how can i execute the files? Because i get an acces dinied warning when is try to execute! Anyone who's got the answer?
thankzzs in advance
spawn543
Aug 13 2003, 04:18 AM
what folder are the files in?
thavirus
Aug 15 2003, 11:47 AM
i'v tftp the file to C:\inetpub\scripts adn wanted to install my server using /i en /h command but that gives an error!
Maybe you can answer this?
Kenshin
Aug 15 2003, 12:03 PM
If you use the same exploit that i use , my exploit is named asd.exe thann you ha´ve very often when you´re dropping to a shell only IUSR execute rights .
SO you dont´ can install a service because you need admin privilleges . Sometimes if you are lucky yoou have admin rights but its not often .
You can do only find a good user>admin exploit or only hack with user rights and Serv-U 2.5 .
flap
Aug 15 2003, 01:59 PM
| QUOTE (Kenshin @ Aug 15 2003, 12:03 PM) |
If you use the same exploit that i use , my exploit is named asd.exe thann you ha´ve very often when you´re dropping to a shell only IUSR execute rights . SO you dont´ can install a service because you need admin privilleges . Sometimes if you are lucky yoou have admin rights but its not often . You can do only find a good user>admin exploit or only hack with user rights and Serv-U 2.5 . |
"You can do only find a good user>admin exploit" ... yeah.. would be great... u know one??? i don't
T3cHn0b0y
Aug 21 2003, 08:03 PM
It's goto be the program! A DOS attack is a DOS attack. If kralor's IIS 5.0 + WebDAV exploit can spawn an shell with root privilages every single time then why can't this iismedia.exe or ads.exe? It's goto be using the wrong shellcode! I'm not a programmer, and I don't exactly know how these exploits work, but isn't it logical to think that both executables, once they have exploited the server, can run exactly the same arbitrary code?
Another thing, why is it that both the RPC/DCOM and WebDAV exploits execute a reverse telnet to you, which upon connecting, executes a shell so that you dont even have to connect to it, and the media exploit doesn't?
Maybe im getting a bit ahead of myself here and I don't exactly know what the f I'm on about but think about it. Can someone maybe try altering the source for this and adding in reverse telnet shellcode?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.