Главная страница


ru.nethack

 
 - RU.NETHACK -------------------------------------------------------------------
 From : Martin Tichenko                      2:5030/362.24  09 Aug 2003  16:01:20
 To : All
 Subject : Hеобходимо долучить доступ к дискам
 -------------------------------------------------------------------------------- 
 
                       --== Приветствую тебя, All! ==--
 Тут недавно кто-то жаловался на маленький трафик. Попробую его поднять.
 Просьба сразу не 'пинать' чайника...
 
 Есть некая сетка, в ней сервак NT смотрящий в Inet.
 Inet раздает через авторизацию.
 
 Хотелось бы получить доступ к винту, и к паролям доступа на Inet.
 Hе хотелось бы при этом завалить сервак и также оставлять после сябя следов.
 
 Подскажите в какую сторону капать или где, что почитать можно...
 
 Hекоторая информация о серваке...
 - порт 80/tcp - http
   сервер HTTP  : <неопознан>
     состояние  : 400 (Bad Request ( The data is invalid.  ))
 
     определение следующей информации находится пока в тестовом режиме
     определить реальное имя http-сервера не удалось
     отпечатка этой конфигурации сервера нет в базе данных сканера
     пожалуйста сообщите об этом разработчикам программы (support@xspider.ru)
     с указанием деталей о http-сервере и об его конфигурации
 
     найдена уязвимость
      возможно межсайтовое выполнение скриптов (cross-site scripting)
 
      описание уязвимости:
       IIS allows universal CrossSiteScripting:
       Stealing cookies from any IIS site, cross-domain scripting
       to any IIS site, hijacking Hotmail and Passport accounts,
       elevating priveleges through ActiveX components, hijacking
       the MSN Messenger client, etc.
 
       Every time IIS encounters a HTTP 404 errorcode, it will display a "404 not
       found" page.
       This HTML file uses scripting to output a link to the SERVER.TLD part of
 the
       URL, and by crafting a specially formed URL it is possible to include
       arbitrary script commands on the 404 page, thereby enabling
       CrossSiteScripting on any IIS site.
       If we look at 404.htm we will notice a particular line of code:
       document.write( '<A HREF="' + escape(urlresult) + '">' + displayresult +
       "</a>");
       displayResult is derived from the first instance of :// in the URL until
 the
       next instance of /.
       This means that we will have to include our script code before the path
 part
       of the URL. To accomplish this we include our script code in the Basic
       Authentication part of the URL, but we first have to escape any special
       characters in the code. Any / character will end displayresult prematurely
       and any spaces will corrupt the DNS lookup, and we therefor replace any
       space with a TAB (%09) and any / with %5Cx2f (\x2f, as we will dynamically
       reference an external file).
 - порт 25/tcp - smtp
   сервер SMTP    - отправка почты   (не работает)
     <нет данных>
 - порт 110/tcp - pop-3
   сервер POP3    - получение почты  (работает)
     X1 NT-POP3 Server mx.XXX.ru (IMail 7.10      4744-1)
     подозрение на существование уязвимости
     возможна DOS-атака и проверка пользователей
 
      описание уязвимости:
       Ipswitch IMail Server 7.04 contains two vulnerabilities:
       Buffer overflow in username field and possible username checking.
 - порт 143/tcp - imap2
   сервис IMAP    - Internet Message Access Protocol
     IMAP4 Server (IMail 7.10)
     подозрение на существование уязвимости
     возможна DOS-атака в версии 5.0
      описание уязвимости:
       NT IMail Imapd Buffer Overflow DoS Vulnerability.
       The imapd login process is susceptible to
       a buffer overflow attack which will crash the service.
 - порт 53/tcp - domain
   сервер DNS (TCP)
     рекурсия не поддерживается сервером
     ошибка при трансфере зоны "microsoft.com"  (N 3)
     версию BIND определить не удалось
 - NetBIOS
     MAC-адрес: 00-A0-24-6A-3A-08
 
     Имя      : XXX
     Домен    : XXX
     список ресурсов:
      MsOLAPRepository$   -  пользовательский
      IPC$                -  pipe по умолчанию  (Remote IPC)
      print$              -  пользовательский   (Printer Drivers)
      USERS               -  пользовательский
      FILES               -  пользовательский
      mspclnt             -  пользовательский
      REPL$               -  пользовательский
 
 + еще некоторые аналогичные шары...
 Доступа к этим шарам нет.
 В домене я не авторизируюсь. Реально просто доступ к Inet'у через 8080 порт.
     список пользователей:
      Administrator
       привилегии  : Администратор
       комментарий : Built-in account for administering the computer/domain
       входов      : 760
 
      Guest
       пользователь заблокирован
       привилегии  : Гость
       комментарий : Built-in account for guest access to the computer/domain
       входов      : 0
 
      TsInternetUser
       привилегии  : Гость
       полное имя  : TsInternetUser
       комментарий : This user account is used by Terminal Services.
       входов      : 0
 
       XXX
       привилегии  : Гость
       входов      : 6
 
 Еще около 30 юзеров с гостевыми привилегиями и нулевыми входами
 - порт 7/tcp - echo
   сервис отвечает тем же запросом, который ему посылается
 - порт 9/tcp - discard
 - порт 13/tcp - daytime
   ответ сервиса:
     1:20:45 03.08.2003 #10
 - порт 17/tcp - qotd
   ответ сервиса:
     "Oh the nerves, the nerves; the mysteries of this machine called man! #13 
 #10  Oh the little that unhinges it, poor creatures that we are!" #13  #10 
 Charles Dickens (1812-70) #13  #10
 - порт 19/tcp - chargen
   ответ сервиса:
      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefg #13
 #10 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefgh #13
 #10 "#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi #13
 #10 #$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWX
 - порт 91/tcp - mit-dov
 - порт 135/tcp - loc-srv
   сервис стандарта Win RPC
     "Win32Services" - Generic Host Process for Win32 Services
 - порт 445/tcp - microsoft-ds
 - порт 1047/tcp - unknown
   сервис стандарта Win RPC
 - порт 1080/tcp - socks
   ответ сервиса на http запрос:
     $[T / HT
   ответ на RAdmin запрос:
      #0 [ #0  #0  #1  #0  #0  #0
   ответ на Ms SQL запрос:
      #0 [ #0 Ш #0  #0  #1  #0
 - порт 1745/tcp - remote-winsock
 - порт 3372/tcp - unknown
   ответ сервиса на http запрос:
      #8 ` #11 $x #1
   ответ на Ms SQL запрос:
      #8 ` #11  #0 x #1
 - порт 5800/tcp - vnc
 
     подозрение на существование уязвимости
     в WinVNC в версии 3.3.3r7 и ниже возможно переполнение буфера
 
      описание уязвимости:
       Multiple WinVNC vulnerabilities:
       (Buffer overflow, weak auth, weak pass encryption,
       default configuration)
 
       The authentication system used by VNC uses a weak encryption
       algorithm that can be easily brute-forced. A static key is used,
       and all passwords are truncated to 8 characters. If the encrypted
       passwords can be obtained, it would be trivial to decrypt them.
 
       During WinVNC's default install process, a registry key is created
       that could allow a remote attacker to modify the registry entry and
       allow un-authenticated access to the service. The registry key -
       HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3\ - contains the connection
       password, IP and query restrictions as well as other settings.
       By default, this key is created during install with "Administrator"
       and "SYSTEM" accounts having full control and the "Everybody"
       account having Special Access (read and modify). Please note
       that under Windows 2000, this key has "Standard User" privileges
       which can accomplish the same thing. While it is possible for
       a remote attacker to exploit this using regedit (blank the
       password value and set the "AuthRequired" key to 0) the machine
       needs to be a NT 4.0 system missing the registry permission patch.
       If the machine is patched or is Windows 2000, you must have
       administrator rights or equivalent to gain access from the network.
       If successful, a remote attacker could gain
       complete access to the system.
 
       A problem with the software package may allow unauthorized access
       to the desktop of machines using the service. It is a possible for
       a system in a position to control data between the client and server
       to gain unauthorized access to a VNC connection without using means
       such as TCP session hijacking by exploiting a weakness in the
       challenge and response system between the Client and Server.
 
       A malicious server can exploit a buffer overflow in the client by sending 
 a
       fake server version and instead of the challenge method and the challenge
       itself the following packet:
       A rfbConnFailed packet with a length of 'reason' greater than 1024 and a
       'reason string' of 1024 bytes. The client will try to log the reason
 string
       calling the Log::Print method (ClientConnection.cpp, class
       ClientConnection,
       method Authenticate, line 434).
       Log::Print (Log.h, line 61) calls Log::ReallyPrint (Log.cpp) which calls
       _vstprintf with a local buffer of fixed length (1024 bytes).
       Exploitation of the above problem will led to the execution of arbitrary
       code on the client machine with the privileges of the user running the
       VNC client.
 - порт 5900/tcp - vnc
   ответ сервиса:
     RFB 003.003 #10
 
     подозрение на существование уязвимости
     в WinVNC в версии 3.3.3r7 и ниже возможно переполнение буфера
 
      описание уязвимости:
       Multiple WinVNC vulnerabilities:
       (Buffer overflow, weak auth, weak pass encryption,
       default configuration)
 
       The authentication system used by VNC uses a weak encryption
       algorithm that can be easily brute-forced. A static key is used,
       and all passwords are truncated to 8 characters. If the encrypted
       passwords can be obtained, it would be trivial to decrypt them.
 
       During WinVNC's default install process, a registry key is created
       that could allow a remote attacker to modify the registry entry and
       allow un-authenticated access to the service. The registry key -
       HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3\ - contains the connection
       password, IP and query restrictions as well as other settings.
       By default, this key is created during install with "Administrator"
       and "SYSTEM" accounts having full control and the "Everybody"
       account having Special Access (read and modify). Please note
       that under Windows 2000, this key has "Standard User" privileges
       which can accomplish the same thing. While it is possible for
       a remote attacker to exploit this using regedit (blank the
       password value and set the "AuthRequired" key to 0) the machine
       needs to be a NT 4.0 system missing the registry permission patch.
       If the machine is patched or is Windows 2000, you must have
       administrator rights or equivalent to gain access from the network.
       If successful, a remote attacker could gain
       complete access to the system.
 
       A problem with the software package may allow unauthorized access
       to the desktop of machines using the service. It is a possible for
       a system in a position to control data between the client and server
       to gain unauthorized access to a VNC connection without using means
       such as TCP session hijacking by exploiting a weakness in the
       challenge and response system between the Client and Server.
 
       A malicious server can exploit a buffer overflow in the client by sending 
 a
       fake server version and instead of the challenge method and the challenge
       itself the following packet:
       A rfbConnFailed packet with a length of 'reason' greater than 1024 and a
       'reason string' of 1024 bytes. The client will try to log the reason
 string
       calling the Log::Print method (ClientConnection.cpp, class
       ClientConnection,
       method Authenticate, line 434).
       Log::Print (Log.h, line 61) calls Log::ReallyPrint (Log.cpp) which calls
       _vstprintf with a local buffer of fixed length (1024 bytes).
       Exploitation of the above problem will led to the execution of arbitrary
       code on the client machine with the privileges of the user running the
       VNC client.
 - порт 8080/tcp - http-proxy
   сервер HTTP  : webpc.rateinfo.ru<BR>
     состояние  : 407 (Proxy Authentication Required ( The ISA Server requires
 authorization to fulfill the request. Access to the Web Proxy service is denied.
 ))
     формат содержимого     :  (text/html)
 
     определение следующей информации находится пока в тестовом режиме
     определить реальное имя http-сервера не удалось
     отпечатка этой конфигурации сервера нет в базе данных сканера
     пожалуйста сообщите об этом разработчикам программы (support@xspider.ru)
     с указанием деталей о http-сервере и об его конфигурации
 
     найдена уязвимость
      возможно межсайтовое выполнение скриптов (cross-site scripting)
 
      описание уязвимости:
       IIS allows universal CrossSiteScripting:
       Stealing cookies from any IIS site, cross-domain scripting
       to any IIS site, hijacking Hotmail and Passport accounts,
       elevating priveleges through ActiveX components, hijacking
       the MSN Messenger client, etc.
 
       Every time IIS encounters a HTTP 404 errorcode, it will display a "404 not
       found" page.
       This HTML file uses scripting to output a link to the SERVER.TLD part of
 the
       URL, and by crafting a specially formed URL it is possible to include
       arbitrary script commands on the 404 page, thereby enabling
       CrossSiteScripting on any IIS site.
       If we look at 404.htm we will notice a particular line of code:
       document.write( '<A HREF="' + escape(urlresult) + '">' + displayresult +
       "</a>");
       displayResult is derived from the first instance of :// in the URL until
 the
       next instance of /.
       This means that we will have to include our script code before the path
 part
       of the URL. To accomplish this we include our script code in the Basic
       Authentication part of the URL, but we first have to escape any special
       characters in the code. Any / character will end displayresult prematurely
       and any spaces will corrupt the DNS lookup, and we therefor replace any
       space with a TAB (%09) and any / with %5Cx2f (\x2f, as we will dynamically
       reference an external file).
 - порт 53/udp - domain
   сервер DNS (UDP)
     рекурсия не поддерживается сервером
     версию BIND определить не удалось
 - порт 7/udp - echo
   сервис Echo (UDP)
     состояние  :  <работает>
 - порт 13/udp - daytime
   сервис DayTime (UDP)
     время и дата : [1:40:06 03.08.2003]
 - порт 17/udp - qotd
   сервис Quote of the day (UDP)
     состояние  :  <работает>
 - порт 19/udp - chargen
   сервис Chargen (UDP)
                Whish you Goodluck!
                Martin. >;-)
                                /09 Авг 03/
 
 ... незавершенные транзакции начинаются в голове ...
 --- GolDed+/W32 1.1.5-30120 ---
  * Origin: Write your letters to: (2:5030/362.24)
 
 

Вернуться к списку тем, сортированных по: возрастание даты  уменьшение даты  тема  автор 

 Тема:    Автор:    Дата:  
 Hеобходимо долучить доступ к дискам   Martin Tichenko   09 Aug 2003 16:01:20 
 Hеобходимо долучить доступ к дискам   Zaslavsky Andrew   10 Aug 2003 00:20:51 
Архивное /ru.nethack/39073f34ec20.html, оценка 3 из 5, голосов 10
Яндекс.Метрика
Valid HTML 4.01 Transitional