Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 24 guests and 1 member online
You are here:
Home
Resources
Tutorials
how to exploit iis 6
EH-Net
May 26, 2013, 01:43:27 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Tutorials
(Moderator:
don
) >
how to exploit iis 6
Pages:
1
[
2
]
3
Go Down
« previous
next »
Print
Author
Topic: how to exploit iis 6 (Read 24286 times)
0 Members and 2 Guests are viewing this topic.
White ghost
Newbie
Offline
Posts: 36
Im a ghost from paradise
Re: how to exploit iis 6
«
Reply #15 on:
November 01, 2011, 11:14:14 AM »
i have permission for pentest
Logged
MCITP CCENT
White ghost
Newbie
Offline
Posts: 36
Im a ghost from paradise
Re: how to exploit iis 6
«
Reply #16 on:
November 01, 2011, 12:06:21 PM »
and i made this topic for iis 6 hacking not for some thing around my permissionss or credentials!
and thank 3xban for MSBA i dwonloaded it
its amazing
Logged
MCITP CCENT
3xban
Hero Member
Offline
Posts: 608
Re: how to exploit iis 6
«
Reply #17 on:
November 01, 2011, 01:03:16 PM »
No problem. As for IIS 6 well sometimes you just need to realize that it may not be exploitable based on what is in use. Not to say that IIS 6 is not vulnerable to other attacks, but if the network is configured properly it is very difficult to use things like reverse TCP shells. So you need to say "Well this particular server does not make a viable attack vector because..." and state that it is possible that proper firewall rules are in place as well as IDS/IPS systems preventing the attack from happening.
IIS 6 is still currently supported by MS so there are regular updates available and there are hardening processes available. So if the person who configured the server originally new his stuff, then that server might be locked down tight. If you review the last few big breaches you will see that it wasn't necessarily the version of software that was a problem but the configuration in the particular application. So it wasn't necessarily because IIS had ASP configured but an application configured with ASP.NET may have not been properly coded and XSS was allowed or the code to the SQL backend wasn't secured and SQLi was allowed.
Now if your MBSA report of that server came back green then there may not be any easily exploitable vulnerabilities on the Microsoft end of town. You then have to look at the specific web apps and try there. If it is custom written code then there very well could be some user created vulnerabilities. If there are no apps and its just a regular old web server well you might not have too many options.
Logged
Certs: GCWN
(@)Dewser
hayabusa
Hero Member
Offline
Posts: 1633
Re: how to exploit iis 6
«
Reply #18 on:
November 01, 2011, 03:29:23 PM »
Quote from: White ghost on November 01, 2011, 12:06:21 PM
and i made this topic for iis 6 hacking not for some thing around my permissionss or credentials!
and thank 3xban for MSBA i dwonloaded it
its amazing
Easy there, White ghost... I know what you started this thread for.
I understood your reasoning, but for a moment, it just seemed that your motives might've been ill-mannered, or at the least, misguided. And, if you come with attitude, because I simply asked the question, I don't rightly care what your thread was posted about...
For all we'd known, you could just as easily have been a malicious kid, trying to learn the topics for the wrong reason, and feeding us a line.
Look at it from my perspective, and what would you have ascertained? It's relatively rare (at least around these parts) for a Helpdesk person to have anything to do with pentesting in their company, and when your post inferred lack of permissions, when you aren't in the office...
So ease up with the defensive attitude...
I'm glad to see 3xban's info was worthwhile for you.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
White ghost
Newbie
Offline
Posts: 36
Im a ghost from paradise
Re: how to exploit iis 6
«
Reply #19 on:
November 02, 2011, 02:20:26 AM »
hey you hayabusa listen to me
i dont have to explian you andDon't slander to me without a valid reason i study CEH and im beginner in hackers world if and i just spoke with 3xban not yes im a help desk in a small company as i said i wanna act like malicious hacker because my boss knows i can gain access to the web server with my cerdential in the office
and you if you dont wanna help my dont post to this topic again
Logged
MCITP CCENT
White ghost
Newbie
Offline
Posts: 36
Im a ghost from paradise
Re: how to exploit iis 6
«
Reply #20 on:
November 02, 2011, 02:34:27 AM »
Thank you 3xban
you surprised me with you useful info i start scanning our web server
and i will tell about the result later thanx again and
GOOOOOOOD LUUUUUUUUCCCKKKK
Logged
MCITP CCENT
hayabusa
Hero Member
Offline
Posts: 1633
Re: how to exploit iis 6
«
Reply #21 on:
November 02, 2011, 06:02:12 AM »
Ok... You win. You'll get no more response (or help) from me, after this post - on this thread, or any other, because your attitude is shining through. You're taking this way too seriously. I asked you a question, because things seemed fishy. You fired back, guns blazing. Simply clarifying would have been enough. Period. And then we'd be getting along, wonderfully.
I even - nicely - responded at the end of my previous post, saying that I was glad 3xban's post was helpful to you.
Anyway... Good luck in your efforts. Whether or not you choose to believe me, I wish you well. But until you want to realize otherwise, that my intentions were justified, you've burned a bridge. Take care.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
White ghost
Newbie
Offline
Posts: 36
Im a ghost from paradise
Re: how to exploit iis 6
«
Reply #22 on:
November 02, 2011, 08:32:02 AM »
hello and sorry for my attitude
im so sorry for that but your attitude was not good too you never helped me about my problem look at your posts in my topic when you told me
( For all we'd known, you could just as easily have been a malicious kid, trying to learn the topics for the wrong reason, and feeding us a line. ) i was very upset because
i didnt notthing wrong im from Turkey and i cant speak english very well. by the i like to continue this conversation with you in the topic if you like it
Logged
MCITP CCENT
3xban
Hero Member
Offline
Posts: 608
Re: how to exploit iis 6
«
Reply #23 on:
November 02, 2011, 11:00:58 AM »
I'm glad my information was helpful. Though I will side with Hayabusa on the attitude adjustment. I tend to try and help where I can here since these guys are full of awesome information and are always helpful when the need is legitimate.
My rule of thumb is that if you are new to a group such as this, you need to observe a bit. Understand the group better and who the top players are. If you jump right in and start off with asking questions for help, usually that is a red flag. I am sorry that I didn't question your motives sooner but as I said, I tend to be a helpful guy. When you get overly defensive on something, it leads us to believe your motives may be more on the UN-ethical side of things.
As you mentioned you are from Turkey and the language barrier may have you coming off a bit more defensive than expected. And that is fine. From our standpoint there is at least one post a day that is someone asking for help or looking to hire someone to perform some unsavory tasks. We tend to probe the individual before answering any questions. I figured my suggestions were nothing you cannot find on google so I didn't see any threat in answering your questions. If you truly mean to get educated here and use your powers for good instead of evil, then please continue being part of the community. If not, well then like Hayabusa said, you will not get any additional help from us.
Good luck.
Logged
Certs: GCWN
(@)Dewser
White ghost
Newbie
Offline
Posts: 36
Im a ghost from paradise
Re: how to exploit iis 6
«
Reply #24 on:
November 02, 2011, 11:23:37 AM »
yes you are right
Logged
MCITP CCENT
White ghost
Newbie
Offline
Posts: 36
Im a ghost from paradise
Re: how to exploit iis 6
«
Reply #25 on:
November 02, 2011, 11:32:18 AM »
and what do you wanna know?!
Logged
MCITP CCENT
hayabusa
Hero Member
Offline
Posts: 1633
Re: how to exploit iis 6
«
Reply #26 on:
November 02, 2011, 12:15:58 PM »
@White_ghost -
No harm, no foul. So long as you're understanding of WHY I asked what I did, initially, and we're past any hostilities, I'm happy to meet / know you. As 3xban noted we generally 'feel out' the new person / situation, before simply replying. Thus, my initial questioning.
That said, if you have further questions, post away, and we'll see about helping.
Again, I / we don't mean to offend you, and if I did, you have my apologies. As 3xban noted, I think the language barrier didn't help you to follow my meanings, and as he noted, if you dig around a bit, here, you'll see I don't generally respond with an attitude, but rather, one of caution, if I have any initial doubts. I just ask that you consider it from our perspective, and I think you'll understand why I asked what I did, in the context of 'ethical hacking.'
Take care, and again, good luck!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
White ghost
Newbie
Offline
Posts: 36
Im a ghost from paradise
Re: how to exploit iis 6
«
Reply #27 on:
November 03, 2011, 01:30:41 AM »
hello 3xban and hayabusa
and whats up?!
i have a problem with MBSA i can scan computers in my local subnet
but about our web server i cant scan it from internet it gives me this error:
Could not resolve the computer name: . Please specify computer name, domain\cemputer, or an IP address.
and then when i user the server IP address its gives me this message
again.
my internet connectivity is well the dns server are working properly
i can ping our server i can run a port scanner like nmap on it
and every thing is great except MBSA program
i have backtrack linux can i use nikto to scan our server or whats your recommended
and again thank you for your helping
and good luck
Logged
MCITP CCENT
3xban
Hero Member
Offline
Posts: 608
Re: how to exploit iis 6
«
Reply #28 on:
November 03, 2011, 08:11:59 AM »
MBSA can only be used on the internal network and you need rights to the system you are scanning. It is a Sys Admin tool, not a penetration testing tool. It requires a number of ports open that are typically opened to local network resources. WMI is one of the main components it utilizes.
Logged
Certs: GCWN
(@)Dewser
White ghost
Newbie
Offline
Posts: 36
Im a ghost from paradise
Re: how to exploit iis 6
«
Reply #29 on:
November 03, 2011, 10:09:04 AM »
all right what about nikto and other web scanners on backtrack linux
Logged
MCITP CCENT
Pages:
1
[
2
]
3
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(95) by
zeebee
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.