|
|
ru.nethack- RU.NETHACK ------------------------------------------------------------------- From : Ugin Nekoz 2:463/573.456 08 Jul 2003 16:39:00 To : Nikita Melikhov Subject : ? -------------------------------------------------------------------------------- 27 èþíÿ 2003 Êàê-òî â 11:30 ÿ øïèëèë â Êâàêy, à â êîíñîëè Nikita Melikhov íàïèñàë All: NM> ÚÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ Windows Clipboard NM> ÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ NM> -ÿïîpòÿ80/tcpÿ-ÿhttp ÿÿñåpâåpÿHTTPÿÿ:ÿApache/1.3.20ÿ(Win32)ÿÿ NM> ÿÿÿÿñîñòîÿíèåÿÿ:ÿ200ÿ(OK) NM> ÿÿÿÿòåêyùèåÿÿäàòàÿèÿâpåìÿÿÿ:ÿÿ(Fri,ÿ27ÿJunÿ2003ÿ07:16:03ÿGMT) NM> ÿÿÿÿôîpìàòÿñîäåpæèìîãîÿÿÿÿÿ:ÿÿ(text/html) NM> ÿÿÿÿñîåäèíåíèåÿÿÿÿÿÿÿÿÿÿÿÿÿ:ÿÿ(close) NM> ÿÿÿÿîïpåäåëåíèåÿñëåäyþùåéÿèíôîpìàöèèÿíàõîäèòñÿÿïîêàÿâÿòåñòîâîìÿpåæèìå NM> ÿÿÿÿpåàëüíîåÿèìÿÿhttp-ñåpâåpàÿñîâïàäàåòÿñÿyêàçàííûìÿâÿåãîÿîòâåòå NM> ÿÿÿÿñåpâåpÿHTTPÿ:ÿApacheÿHTTPÿServerÿ(1.3.X)ÿÿ NM> ÿÿÿÿêîpíåâàÿÿäèpåêòîpèÿÿäîñòyïíàÿäëÿÿïpîñìîòpàÿÿ NM> ÿÿÿÿíàéäåíàÿyÿçâèìîñòü NM> ÿÿÿÿÿâåpîÿòíîÿñyùåñòâyåòÿïpîñìîòpÿâåpõíåéÿäèpåêòîpèèÿÿ NM> ÿÿÿÿÿhttp://127.0.0.1:80/.../ NM> ÿÿÿÿíàéäåíàÿyÿçâèìîñòü NM> ÿÿÿÿêîìàíäíàÿÿñòpîêàÿè/èëèÿDoS-àòàêàÿÿ >> ^^^^ ×òî ýòî òàêîå??? Êàê ýòèì âîñïîëüçîâàòüñÿ??? NM> ÿÿÿÿîïèñàíèåÿyÿçâèìîñòè: NM> ÿÿÿÿÿÿThisÿversionÿApacheÿisÿvulnerableÿtoÿaÿbugÿwhichÿmayÿallow NM> ÿÿÿÿÿÿanÿattackerÿtoÿgainÿaÿshellÿonÿthisÿsystemÿorÿtoÿdisableÿthis NM> ÿÿÿÿÿÿserviceÿremotelyÿ(Apacheÿchunkedÿencoding). NM> ÿÿÿÿÿÿ NM> ÿÿÿÿÿÿSolutionÿ:ÿUpgradeÿtoÿversionÿ1.3.26ÿorÿ2.0.39ÿorÿnewer. NM> ÿÿÿÿÿÿ NM> ÿÿÿÿÿÿPatch: NM> ÿÿÿÿÿÿhttp://www.apache.org/dist/httpd/ NM> ÿÿÿÿÿÿ NM> ÿÿÿÿÿÿURLs: NM> ÿÿÿÿÿÿhttp://httpd.apache.org/info/security_bulletin_20020617.txt NM> ÿÿÿÿÿÿhttp://www.cert.org/advisories/CA-2002-17.html NM> -ÿäîïîëíèòåëüíàÿÿèíôîpìàöèÿ NM> ÿÿÿÿíàéäåíàÿyÿçâèìîñòü NM> ÿÿÿÿDoS-àòàêàÿâÿNetworkÿShareÿProviderÿÿ >> ^^^^ ×òî ýòî òàêîå??? Êàê ýòèì âîñïîëüçîâàòüñÿ??? NM> ÿÿÿÿíåîáõîäèìîÿîáíîâëåíèåÿ-ÿhttp://www.microsoft.com/technet/security/ NM> bulletin/ ms02-045.asp NM> -ÿäîïîëíèòåëüíàÿÿèíôîpìàöèÿ NM> ÿÿÿÿíàéäåíàÿyÿçâèìîñòü NM> ÿÿÿÿâûïîëíåíèåÿêîìàíäÿ÷åpåçÿïåpåïîëíåíèåÿâÿTSACÿActiveXÿControlÿÿ >> ^^^^ ×òî ýòî òàêîå??? Êàê ýòèì âîñïîëüçîâàòüñÿ??? NM> ÿÿÿÿíåîáõîäèìîÿîáíîâëåíèåÿ-ÿhttp://www.microsoft.com/technet/security/ NM> bulletin/ ms02-046.asp NM> -ÿïîpòÿ1900/udp NM> ÿÿñåpâèñÿUPnPÿÿÿÿ-ÿUniversalÿPlug-and-Play NM> ÿÿÿÿàãåíòÿ:ÿMozilla/4.0ÿ(compatible;ÿUPnP/1.0;ÿWindowsÿNT/5.1)ÿÿ NM> ÿÿÿÿíàéäåíàÿyÿçâèìîñòü NM> ÿÿÿÿÿêîìàíäíàÿÿñòpîêàÿñÿïpàâàìèÿSYSTEMÿÿ >> ^^^^ ×òî ýòî òàêîå??? Êàê ýòèì âîñïîëüçîâàòüñÿ??? NM> ÿÿÿÿÿîïèñàíèåÿyÿçâèìîñòè: NM> ÿÿÿÿÿÿUPNPÿRemoteÿWindowsÿXP/ME/98ÿVulnerability. NM> ÿÿÿÿÿÿAnÿattackerÿcouldÿsendÿaÿNOTIFYÿdirectiveÿtoÿaÿUPnP-capableÿcomp NM> uter,ÿ NM> ÿÿÿÿÿÿspecifyingÿthatÿtheÿdeviceÿdescriptionÿshouldÿbeÿdownloadedÿfrom NM> ÿÿÿÿÿÿaÿparticularÿportÿonÿaÿparticularÿserver.ÿIfÿtheÿserverÿwasÿconf NM> iguredÿ NM> ÿÿÿÿÿÿtoÿsimplyÿechoÿtheÿdownloadÿrequestsÿbackÿtoÿtheÿUPnPÿserviceÿ(e NM> .g.,ÿ NM> ÿÿÿÿÿÿbyÿhavingÿtheÿechoÿserviceÿrunningÿonÿtheÿportÿthatÿtheÿcomputer NM> ÿwasÿ NM> ÿÿÿÿÿÿdirectedÿto),ÿtheÿcomputerÿcouldÿbeÿmadeÿtoÿenterÿanÿendlessÿdow NM> nloadÿ NM> ÿÿÿÿÿÿcycleÿthatÿcouldÿconsumeÿsomeÿorÿallÿofÿtheÿsystem'sÿavailabilit NM> y.ÿ NM> ÿÿÿÿÿÿAnÿattackerÿcouldÿcraftÿandÿsendÿthisÿdirectiveÿtoÿaÿvictim'sÿma NM> chineÿ NM> ÿÿÿÿÿÿdirectly,ÿbyÿusingÿtheÿmachine'sÿIPÿaddress.ÿOr,ÿheÿcouldÿsendÿt NM> hisÿ NM> ÿÿÿÿÿÿsameÿdirectiveÿtoÿaÿbroadcastÿandÿmulticastÿdomainÿandÿattackÿal NM> lÿ NM> ÿÿÿÿÿÿaffectedÿmachinesÿwithinÿearshot,ÿconsumingÿsomeÿorÿallÿofÿthose NM> ÿ NM> ÿÿÿÿÿÿsystems'ÿavailability.ÿ NM> ÿÿÿÿÿÿ NM> ÿÿÿÿÿÿAnÿattackerÿcouldÿspecifyÿaÿthird-partyÿserverÿasÿtheÿhostÿforÿt NM> heÿdevice NM> descriptionÿinÿtheÿNOTIFYÿdirective.ÿIfÿenoughÿmachinesÿrespondedÿtoÿ NM> ÿÿÿÿÿÿtheÿdirective,ÿitÿcouldÿhaveÿtheÿeffectÿofÿfloodingÿtheÿthird-pa NM> rtyÿ NM> ÿÿÿÿÿÿserverÿwithÿbogusÿrequests,ÿinÿaÿdistributedÿdenialÿofÿserviceÿa NM> ttack.ÿ NM> ÿÿÿÿÿÿAsÿwithÿtheÿfirstÿscenario,ÿanÿattackerÿcouldÿeitherÿsendÿtheÿdi NM> rectivesÿ NM> toÿtheÿvictimÿdirectly,ÿorÿtoÿaÿbroadcastÿorÿmulticastÿdomain. NM> ÿÿÿÿÿÿ NM> ÿÿÿÿÿÿSolution:ÿPatch. NM> ÿÿÿÿÿÿ NM> ÿÿÿÿÿÿPatch:ÿ NM> ÿÿÿÿÿÿhttp://www.microsoft.com/Downloads/Release.asp?ReleaseID=34991ÿ NM> ÿÿÿÿÿÿhttp://download.microsoft.com/download/winme/Update/22940/WinMe/ NM> EN-US/314 757USAM.EXE NM> ÿÿÿÿÿÿhttp://www.microsoft.com/Downloads/Release.asp?ReleaseID=34951 NM> ÿÿÿÿÿÿ NM> ÿÿÿÿÿÿUrl: NM> ÿÿÿÿÿÿhttp://www.microsoft.com/technet/security/bulletin/MS01-059.asp NM> ÿÿÿÿÿÿhttp://www.eeye.com/html/Research/Advisories/AD20011220.html NM> ÀÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ Windows Clipboard Hà BagTraq'å äîëæíà íàéòèñü êàêàÿ-òî äîêà è äëÿ Òåáÿ :-) Ýòî âñ¸ äûpêè, ýêñïëîèòû, yÿçâèìîñòè... Hàïpèìåp, åñëè âîçìîæåí ïpîñìîòp âåpõíèõ äèppåêòîpèé, òî Òû ñîçäàâ ñïåöèôè÷åñêèé çàïpîñ â ïîëå àäpåñà, ìîæåøü ãyëÿòü ïî âèíòîâîé æåñòè àòàêyåìîãî. Äî ñâèäàíèÿ, Nikita! ... H.Âèpò íå íàçâàë Ïàñêàëü ñâîèì èìåíåì, ÷òîáû íå îïîçîpèòüñÿ. --- Ugin Nekoz aka Hi_Jack :[KPG]: use GoldED+/W32 * Origin: Free your mind and make changes (2:463/573.456) Âåðíóòüñÿ ê ñïèñêó òåì, ñîðòèðîâàííûõ ïî: âîçðàñòàíèå äàòû óìåíüøåíèå äàòû òåìà àâòîð
Àðõèâíîå /ru.nethack/40393f0af485.html, îöåíêà èç 5, ãîëîñîâ 10
|