Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Security practice (contest)

Options
1246789

Comments

  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    there is a few different encodings i seen used, like %255
    You can see more examples at:
    http://www.johnshepp.org/security/23/iis-hacks-continued


  • Closed Accounts Posts: 891 ✭✭✭conceited


    I was reading about them earlier on alright.I was wondering why i kept getting errors as i couldn't understand >> was causing a problem because a url is all encoded the same.

    It's an interesting bug all the same.I might put up a box at 6 if anyones interested.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    I'd be interested. What are you planning?


  • Closed Accounts Posts: 891 ✭✭✭conceited


    I unistalled ISS .
    Default install of windows 2000 sp0.
    Objective is root the box and leave no traces behind other than a txt file on the administrators desktop with your name and time etc.
    I set up the router for ip passthrough for the lan box 192.168.1.3 only.
    The usual rules apply.

    What you think?


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    sounds good, the logs will be the hardest part.


    note: some isp's block windows ports like 136-139 and 445.


  • Advertisement
  • Closed Accounts Posts: 891 ✭✭✭conceited


    If thats the case let me know as i can set a few pinholes in my nat for you instead.
    Let me know if your scans are getting through.
    Logs files are important, most people aren't used to taking care of that part.
    83.71.83.18


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    it reported nothing went through, i have to pop out now for a bit anyway


  • Closed Accounts Posts: 891 ✭✭✭conceited


    Ok no bother.I'll set the pinholes so.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    i did a quick scan again last night and it reported that nothing was open.


  • Closed Accounts Posts: 41 acidstorm


    hello Everyone, I actually want to confirm that the web server is not accessible from the internet..
    NMAP SCAN RESULTS AT 2008-07-09 16:25 IST SHOWS >>

    Host ... appears to be up ... good.
    All 1714 scanned ports on ... are filtered
    Too many fingerprints match this host to give specific OS details


  • Advertisement
  • Closed Accounts Posts: 891 ✭✭✭conceited


    All ports have been forwarded.
    Hadn't much time today sorry about that lads.
    83.71.83.18


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    cheers, lets hope spyware scanners dont get to the server before us


  • Closed Accounts Posts: 891 ✭✭✭conceited


    I made an image, so no hassle to restore it.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    I put my name in a file called Damo.txt on the Administrators desktop lastnight. It was getting late so I went to bed.

    I tried to connect this morning to upload and execute a special tool to clear out the event logs but I couldnt connect. Maybe spyware has fecked it already? There is a lot of different holes in this system :-)

    Is the server still up?

    I can try that again this evening.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    Is anyone else participating in this?


  • Closed Accounts Posts: 891 ✭✭✭conceited


    Afternoon Damo2k

    Got it damo you arrive with style :) Ya there's alot of holes in it plenty of choice.
    When i started this thread 7-8 people sounded interested.
    Your the only one so far to try this one.
    I think you and livewire are the only ones that have managed to do anything.
    I'll leave it up so you can try the logs, and others can try put the txt file onto the desktop, like you have .


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    I think this is a good challenge, and there is a good variety of different hacks that can be applied here.

    just hope scanner bots dont hit your ip and cripple the server.

    I have a method of clearing the logs, I just need to send across an executable and execute it. For some reason, I couldnt connect this morning. The server might need to be rebooted as the ***** service might have crashed.


  • Closed Accounts Posts: 891 ✭✭✭conceited


    I hope they don't scan me either.I have an image of the 2 gig partition made, so it won't be too bad.

    You couldn't connect as it was rebooted around 1am i think.I have a password set on the admin account.If the computer is rebooted it won't auto login.
    I hope a few more join in as there was plenty of talk in the begining .


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    conceited wrote: »
    I hope they don't scan me either.I have an image of the 2 gig partition made, so it won't be too bad.

    You couldn't connect as it was rebooted around 1am i think.I have a password set on the admin account.If the computer is rebooted it won't auto login.
    I hope a few more join in as there was plenty of talk in the begining .

    I was getting in under the SYSTEM account so it won't matter if you are logged in or not, as the necessary services are already running when you see the login screen. By the way I seen 1 or 2 accounts with no password set. I'll not name the accounts here, but is that a false positive, as I didn't see home directories for them?


  • Closed Accounts Posts: 891 ✭✭✭conceited


    The only account which has a password is the admin account.The profiles are not there as I never logged in, forgot about it.Forgot about services.:pac:


  • Advertisement
  • Closed Accounts Posts: 41 acidstorm


    yeah sure, I am interested in this, however, you can only hack what you can see so.. until then its back to PHP coding!.. I'll keep "Nmapping" tho..


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    the server can be see since last night, if you cant see it, then your doing something wrong


  • Closed Accounts Posts: 891 ✭✭✭conceited


    Damo was that you? :pac:


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    yeah sorry, didnt mean to do that intentionally


  • Closed Accounts Posts: 891 ✭✭✭conceited


    The server has gone spastic:rolleyes:
    Now it's looking like the MS Blast worm on viagra .


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    that service has just crashed again. im trying to set up a tftp or ftp server here for your server collect files from, its giving me trouble tho!


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    oh i only executed the exploit again, if your seeing crazy stuff, you might have gotten hit with a ms-blaster or sasser type worm


  • Closed Accounts Posts: 891 ✭✭✭conceited


    Haha 3 reboots it's fine now at the moment, ms blast is well gone.
    I captured it with nc before was a good laugh.
    So your trying to get something more permanent thats a good idea.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    server might need to be rebooted, certain things are not connectable


  • Advertisement
  • Registered Users Posts: 1,726 ✭✭✭gerryk


    Might have been me... I was trying RPC exploit around then


Advertisement