Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 60 guests and 4 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Idea on how to hack the index.html
EH-Net
May 24, 2012, 10:43:18 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Idea on how to hack the index.html  (Read 34492 times)
0 Members and 1 Guest are viewing this topic.
jggozum
Newbie
*
Offline Offline

Posts: 5


View Profile
« on: February 02, 2008, 02:12:36 AM »

Hi fellas, im new here. can i have your ideas on how to hack html pages? mostly likely breaking the index.html page. the server is Windows Server 2000 and using IIS 5. thank you so much. its good to be here.
Logged
_Marshel_
Jr. Member
**
Offline Offline

Posts: 61

Life Is too short to be someone else.


View Profile
« Reply #1 on: February 02, 2008, 03:04:59 AM »

can you elaborate more ?
Logged
jggozum
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #2 on: February 02, 2008, 03:41:25 AM »

hi mashel. i want some ideas on how to change the index.html page of the target. thanks
Logged
xXxKrisxXx
Sr. Member
****
Offline Offline

Posts: 491



View Profile
« Reply #3 on: February 02, 2008, 04:40:39 AM »

You could attempt to penetrate the box running an IIS 5 exploit. Hope your not asking the members of this forum to help you aid in an unethical attack on a site.
Logged

OSCP, OWSP, eCPPT
jggozum
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #4 on: February 02, 2008, 06:38:53 AM »

im just asking the idea on how to.. the tactics on how to do it.
Logged
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 204



View Profile
« Reply #5 on: February 02, 2008, 09:52:03 AM »

I think the members are a bit confused because of the lack of details. For example, what is contained within the index page?  What kind of functionality does it have?  More importantly, why are you trying to break it?  As for a general strategy, when you are doing web pen testing you need to think in layers.  If the target page has fields where you can input data then you can try to attack the actual functionality via sql/ldap/crlf/etc injection.  If you have a local proxy such as paros you can try to attack some of the actual HTML/HTTP header traffic by manipulating session, authentication, etc data or even some more advanced injection attacks.  Locally on your system you can mess with the cookies or even save a copy of the site and try client side attacks by breaking the code.  If none of the application level attacks work then move down to the actual web service.  If you know it is IIS then research attacks specifically meant for that web server.  Many of the attacks that you performed against the web page will result in error messages that might even give you version or patch level.  If those attacks don't work then try to figure out if there are supporting apps you can attack.  Does the webpage have an Oracle back-end?  Is there some type of authentication framework that they use? Go for those next.  When all else fails drop down to the OS level.  If you know it is Win2K then you have a massive amount of exploits available.  If all that fails... there is always email and trojans.
Logged

CISSP, CISM, CISA, GCIH, CEH, HMFIC, KTHXBIROFLCOPTER
jggozum
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #6 on: February 02, 2008, 12:32:07 PM »

thank you so much pseud0.. lots of ideas.. i already break it thru ftp.. *cheers*
« Last Edit: February 02, 2008, 12:42:18 PM by jggozum » Logged
Kev
Sr. Member
****
Offline Offline

Posts: 428


View Profile
« Reply #7 on: February 02, 2008, 03:23:49 PM »

i already break it thru ftp..

LoL, and there is that.
Logged
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 204



View Profile
« Reply #8 on: February 03, 2008, 07:36:51 AM »

Yeah, I guess I left out the ole' index.html.ftp.banyan.ext3  buffer smurf underflow.
Logged

CISSP, CISM, CISA, GCIH, CEH, HMFIC, KTHXBIROFLCOPTER
jggozum
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #9 on: February 05, 2008, 07:08:06 AM »

hi again fellas..

psued0 what do you mean?
Logged
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 204



View Profile
« Reply #10 on: February 05, 2008, 07:33:21 AM »

Nothing at all. Too much coffee, to little sleep, and poor control over the voices in my head.  ie. I was being stupid.
Logged

CISSP, CISM, CISA, GCIH, CEH, HMFIC, KTHXBIROFLCOPTER
Kev
Sr. Member
****
Offline Offline

Posts: 428


View Profile
« Reply #11 on: February 05, 2008, 05:33:40 PM »

Ah crap! You mean the buffer smurf underflow doesn't really exist?
 Grin
Logged
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 204



View Profile
« Reply #12 on: February 05, 2008, 09:05:07 PM »

Yes, it does, but Smurfette only did it a couple of times.  She was young and needed the money.
Logged

CISSP, CISM, CISA, GCIH, CEH, HMFIC, KTHXBIROFLCOPTER
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.439 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.