|
|
ru.nethack- RU.NETHACK ------------------------------------------------------------------- From : Martin Tichenko 2:5030/362.24 09 Aug 2003 16:01:20 To : All Subject : Hеобходимо долучить доступ к дискам --------------------------------------------------------------------------------
--== Приветствую тебя, All! ==--
Тут недавно кто-то жаловался на маленький трафик. Попробую его поднять.
Просьба сразу не 'пинать' чайника...
Есть некая сетка, в ней сервак NT смотрящий в Inet.
Inet раздает через авторизацию.
Хотелось бы получить доступ к винту, и к паролям доступа на Inet.
Hе хотелось бы при этом завалить сервак и также оставлять после сябя следов.
Подскажите в какую сторону капать или где, что почитать можно...
Hекоторая информация о серваке...
- порт 80/tcp - http
сервер HTTP : <неопознан>
состояние : 400 (Bad Request ( The data is invalid. ))
определение следующей информации находится пока в тестовом режиме
определить реальное имя http-сервера не удалось
отпечатка этой конфигурации сервера нет в базе данных сканера
пожалуйста сообщите об этом разработчикам программы (support@xspider.ru)
с указанием деталей о http-сервере и об его конфигурации
найдена уязвимость
возможно межсайтовое выполнение скриптов (cross-site scripting)
описание уязвимости:
IIS allows universal CrossSiteScripting:
Stealing cookies from any IIS site, cross-domain scripting
to any IIS site, hijacking Hotmail and Passport accounts,
elevating priveleges through ActiveX components, hijacking
the MSN Messenger client, etc.
Every time IIS encounters a HTTP 404 errorcode, it will display a "404 not
found" page.
This HTML file uses scripting to output a link to the SERVER.TLD part of
the
URL, and by crafting a specially formed URL it is possible to include
arbitrary script commands on the 404 page, thereby enabling
CrossSiteScripting on any IIS site.
If we look at 404.htm we will notice a particular line of code:
document.write( '<A HREF="' + escape(urlresult) + '">' + displayresult +
"</a>");
displayResult is derived from the first instance of :// in the URL until
the
next instance of /.
This means that we will have to include our script code before the path
part
of the URL. To accomplish this we include our script code in the Basic
Authentication part of the URL, but we first have to escape any special
characters in the code. Any / character will end displayresult prematurely
and any spaces will corrupt the DNS lookup, and we therefor replace any
space with a TAB (%09) and any / with %5Cx2f (\x2f, as we will dynamically
reference an external file).
- порт 25/tcp - smtp
сервер SMTP - отправка почты (не работает)
<нет данных>
- порт 110/tcp - pop-3
сервер POP3 - получение почты (работает)
X1 NT-POP3 Server mx.XXX.ru (IMail 7.10 4744-1)
подозрение на существование уязвимости
возможна DOS-атака и проверка пользователей
описание уязвимости:
Ipswitch IMail Server 7.04 contains two vulnerabilities:
Buffer overflow in username field and possible username checking.
- порт 143/tcp - imap2
сервис IMAP - Internet Message Access Protocol
IMAP4 Server (IMail 7.10)
подозрение на существование уязвимости
возможна DOS-атака в версии 5.0
описание уязвимости:
NT IMail Imapd Buffer Overflow DoS Vulnerability.
The imapd login process is susceptible to
a buffer overflow attack which will crash the service.
- порт 53/tcp - domain
сервер DNS (TCP)
рекурсия не поддерживается сервером
ошибка при трансфере зоны "microsoft.com" (N 3)
версию BIND определить не удалось
- NetBIOS
MAC-адрес: 00-A0-24-6A-3A-08
Имя : XXX
Домен : XXX
список ресурсов:
MsOLAPRepository$ - пользовательский
IPC$ - pipe по умолчанию (Remote IPC)
print$ - пользовательский (Printer Drivers)
USERS - пользовательский
FILES - пользовательский
mspclnt - пользовательский
REPL$ - пользовательский
+ еще некоторые аналогичные шары...
Доступа к этим шарам нет.
В домене я не авторизируюсь. Реально просто доступ к Inet'у через 8080 порт.
список пользователей:
Administrator
привилегии : Администратор
комментарий : Built-in account for administering the computer/domain
входов : 760
Guest
пользователь заблокирован
привилегии : Гость
комментарий : Built-in account for guest access to the computer/domain
входов : 0
TsInternetUser
привилегии : Гость
полное имя : TsInternetUser
комментарий : This user account is used by Terminal Services.
входов : 0
XXX
привилегии : Гость
входов : 6
Еще около 30 юзеров с гостевыми привилегиями и нулевыми входами
- порт 7/tcp - echo
сервис отвечает тем же запросом, который ему посылается
- порт 9/tcp - discard
- порт 13/tcp - daytime
ответ сервиса:
1:20:45 03.08.2003 #10
- порт 17/tcp - qotd
ответ сервиса:
"Oh the nerves, the nerves; the mysteries of this machine called man! #13
#10 Oh the little that unhinges it, poor creatures that we are!" #13 #10
Charles Dickens (1812-70) #13 #10
- порт 19/tcp - chargen
ответ сервиса:
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefg #13
#10 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefgh #13
#10 "#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi #13
#10 #$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWX
- порт 91/tcp - mit-dov
- порт 135/tcp - loc-srv
сервис стандарта Win RPC
"Win32Services" - Generic Host Process for Win32 Services
- порт 445/tcp - microsoft-ds
- порт 1047/tcp - unknown
сервис стандарта Win RPC
- порт 1080/tcp - socks
ответ сервиса на http запрос:
$[T / HT
ответ на RAdmin запрос:
#0 [ #0 #0 #1 #0 #0 #0
ответ на Ms SQL запрос:
#0 [ #0 Ш #0 #0 #1 #0
- порт 1745/tcp - remote-winsock
- порт 3372/tcp - unknown
ответ сервиса на http запрос:
#8 ` #11 $x #1
ответ на Ms SQL запрос:
#8 ` #11 #0 x #1
- порт 5800/tcp - vnc
подозрение на существование уязвимости
в WinVNC в версии 3.3.3r7 и ниже возможно переполнение буфера
описание уязвимости:
Multiple WinVNC vulnerabilities:
(Buffer overflow, weak auth, weak pass encryption,
default configuration)
The authentication system used by VNC uses a weak encryption
algorithm that can be easily brute-forced. A static key is used,
and all passwords are truncated to 8 characters. If the encrypted
passwords can be obtained, it would be trivial to decrypt them.
During WinVNC's default install process, a registry key is created
that could allow a remote attacker to modify the registry entry and
allow un-authenticated access to the service. The registry key -
HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3\ - contains the connection
password, IP and query restrictions as well as other settings.
By default, this key is created during install with "Administrator"
and "SYSTEM" accounts having full control and the "Everybody"
account having Special Access (read and modify). Please note
that under Windows 2000, this key has "Standard User" privileges
which can accomplish the same thing. While it is possible for
a remote attacker to exploit this using regedit (blank the
password value and set the "AuthRequired" key to 0) the machine
needs to be a NT 4.0 system missing the registry permission patch.
If the machine is patched or is Windows 2000, you must have
administrator rights or equivalent to gain access from the network.
If successful, a remote attacker could gain
complete access to the system.
A problem with the software package may allow unauthorized access
to the desktop of machines using the service. It is a possible for
a system in a position to control data between the client and server
to gain unauthorized access to a VNC connection without using means
such as TCP session hijacking by exploiting a weakness in the
challenge and response system between the Client and Server.
A malicious server can exploit a buffer overflow in the client by sending
a
fake server version and instead of the challenge method and the challenge
itself the following packet:
A rfbConnFailed packet with a length of 'reason' greater than 1024 and a
'reason string' of 1024 bytes. The client will try to log the reason
string
calling the Log::Print method (ClientConnection.cpp, class
ClientConnection,
method Authenticate, line 434).
Log::Print (Log.h, line 61) calls Log::ReallyPrint (Log.cpp) which calls
_vstprintf with a local buffer of fixed length (1024 bytes).
Exploitation of the above problem will led to the execution of arbitrary
code on the client machine with the privileges of the user running the
VNC client.
- порт 5900/tcp - vnc
ответ сервиса:
RFB 003.003 #10
подозрение на существование уязвимости
в WinVNC в версии 3.3.3r7 и ниже возможно переполнение буфера
описание уязвимости:
Multiple WinVNC vulnerabilities:
(Buffer overflow, weak auth, weak pass encryption,
default configuration)
The authentication system used by VNC uses a weak encryption
algorithm that can be easily brute-forced. A static key is used,
and all passwords are truncated to 8 characters. If the encrypted
passwords can be obtained, it would be trivial to decrypt them.
During WinVNC's default install process, a registry key is created
that could allow a remote attacker to modify the registry entry and
allow un-authenticated access to the service. The registry key -
HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3\ - contains the connection
password, IP and query restrictions as well as other settings.
By default, this key is created during install with "Administrator"
and "SYSTEM" accounts having full control and the "Everybody"
account having Special Access (read and modify). Please note
that under Windows 2000, this key has "Standard User" privileges
which can accomplish the same thing. While it is possible for
a remote attacker to exploit this using regedit (blank the
password value and set the "AuthRequired" key to 0) the machine
needs to be a NT 4.0 system missing the registry permission patch.
If the machine is patched or is Windows 2000, you must have
administrator rights or equivalent to gain access from the network.
If successful, a remote attacker could gain
complete access to the system.
A problem with the software package may allow unauthorized access
to the desktop of machines using the service. It is a possible for
a system in a position to control data between the client and server
to gain unauthorized access to a VNC connection without using means
such as TCP session hijacking by exploiting a weakness in the
challenge and response system between the Client and Server.
A malicious server can exploit a buffer overflow in the client by sending
a
fake server version and instead of the challenge method and the challenge
itself the following packet:
A rfbConnFailed packet with a length of 'reason' greater than 1024 and a
'reason string' of 1024 bytes. The client will try to log the reason
string
calling the Log::Print method (ClientConnection.cpp, class
ClientConnection,
method Authenticate, line 434).
Log::Print (Log.h, line 61) calls Log::ReallyPrint (Log.cpp) which calls
_vstprintf with a local buffer of fixed length (1024 bytes).
Exploitation of the above problem will led to the execution of arbitrary
code on the client machine with the privileges of the user running the
VNC client.
- порт 8080/tcp - http-proxy
сервер HTTP : webpc.rateinfo.ru<BR>
состояние : 407 (Proxy Authentication Required ( The ISA Server requires
authorization to fulfill the request. Access to the Web Proxy service is denied.
))
формат содержимого : (text/html)
определение следующей информации находится пока в тестовом режиме
определить реальное имя http-сервера не удалось
отпечатка этой конфигурации сервера нет в базе данных сканера
пожалуйста сообщите об этом разработчикам программы (support@xspider.ru)
с указанием деталей о http-сервере и об его конфигурации
найдена уязвимость
возможно межсайтовое выполнение скриптов (cross-site scripting)
описание уязвимости:
IIS allows universal CrossSiteScripting:
Stealing cookies from any IIS site, cross-domain scripting
to any IIS site, hijacking Hotmail and Passport accounts,
elevating priveleges through ActiveX components, hijacking
the MSN Messenger client, etc.
Every time IIS encounters a HTTP 404 errorcode, it will display a "404 not
found" page.
This HTML file uses scripting to output a link to the SERVER.TLD part of
the
URL, and by crafting a specially formed URL it is possible to include
arbitrary script commands on the 404 page, thereby enabling
CrossSiteScripting on any IIS site.
If we look at 404.htm we will notice a particular line of code:
document.write( '<A HREF="' + escape(urlresult) + '">' + displayresult +
"</a>");
displayResult is derived from the first instance of :// in the URL until
the
next instance of /.
This means that we will have to include our script code before the path
part
of the URL. To accomplish this we include our script code in the Basic
Authentication part of the URL, but we first have to escape any special
characters in the code. Any / character will end displayresult prematurely
and any spaces will corrupt the DNS lookup, and we therefor replace any
space with a TAB (%09) and any / with %5Cx2f (\x2f, as we will dynamically
reference an external file).
- порт 53/udp - domain
сервер DNS (UDP)
рекурсия не поддерживается сервером
версию BIND определить не удалось
- порт 7/udp - echo
сервис Echo (UDP)
состояние : <работает>
- порт 13/udp - daytime
сервис DayTime (UDP)
время и дата : [1:40:06 03.08.2003]
- порт 17/udp - qotd
сервис Quote of the day (UDP)
состояние : <работает>
- порт 19/udp - chargen
сервис Chargen (UDP)
Whish you Goodluck!
Martin. >;-)
/09 Авг 03/
... незавершенные транзакции начинаются в голове ...
--- GolDed+/W32 1.1.5-30120 ---
* Origin: Write your letters to: (2:5030/362.24)
Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.nethack/39073f34ec20.html, оценка из 5, голосов 10
|