Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 43 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow reliable remote code execution for IIS on Server 2008?
EH-Net
May 19, 2013, 12:40:16 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: reliable remote code execution for IIS on Server 2008?  (Read 5865 times)
0 Members and 1 Guest are viewing this topic.
camelCase
Newbie
*
Offline Offline

Posts: 12


View Profile
« on: June 05, 2012, 03:50:19 PM »

Hello,

I am having trouble finding any reliable exploits for Server 2008. So I figured I would ask you guys. Do you know of any? Thanks!
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #1 on: June 05, 2012, 04:21:33 PM »

I would look through the Exploit DB, maintained by Offensive Security. Might also try some of the ones known to work for Wk2, see if they still work.
Logged

OSWP, Sec+
impelse
Hero Member
*****
Offline Offline

Posts: 563


View Profile WWW
« Reply #2 on: June 05, 2012, 10:18:56 PM »

Try to look for different way to log in, some exploits require a lot of work before make it work
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #3 on: June 06, 2012, 07:42:55 AM »

There are no publicly disclosed rce exploits for iis 7. However, if your just looking for a 2008 exploit, there are options.

You're better off going after the app on that webserver.
« Last Edit: June 06, 2012, 08:34:53 AM by cd1zz » Logged

impelse
Hero Member
*****
Offline Offline

Posts: 563


View Profile WWW
« Reply #4 on: June 06, 2012, 08:22:20 AM »

Yep, the web app will give you a good access doesn't matter if the machine is well updated.
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
camelCase
Newbie
*
Offline Offline

Posts: 12


View Profile
« Reply #5 on: June 06, 2012, 05:11:57 PM »

cd1zz, this is what I thought. Oh well. FYI these are in a highly specialized deployment and have no web applications and very limited HTTP methods.
Logged
Attack-Secure
Jr. Member
**
Offline Offline

Posts: 54


attack-secure.com


View Profile WWW
« Reply #6 on: June 06, 2012, 11:28:28 PM »

try this one

http://www.phrack.org/issues.html?issue=68&id=12#article
Logged

http://attack-secure.com - CODENAME: Samurai Skills Course
jimbob
Newbie
*
Offline Offline

Posts: 14


View Profile
« Reply #7 on: June 07, 2012, 04:03:22 AM »

Don't forget to think out a deeper solution. If you can get file upload on the server you can upload arbitrary binaries and ASP content to achieve this. Don't think of pen testing as, "I have one exposed service, is there a remote exploit?" Can you find SQLi and execute code that way?

Regards,
Jimbob
Logged
camelCase
Newbie
*
Offline Offline

Posts: 12


View Profile
« Reply #8 on: June 18, 2012, 01:22:22 PM »

Again, they do not run any web applications. This is why I asked about IIS specifically. The PHRACK issue I would say does not indeed point to any reliable exploit. Thank you for your time but I pwnd this shit on my own.
Logged
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #9 on: June 19, 2012, 07:47:47 AM »

Thank you for your time but I pwnd this shit on my own.

Perhaps you'd care to share and help us increase the community knowledge?
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #10 on: June 19, 2012, 08:18:46 AM »

Thank you for your time but I pwnd this shit on my own.

Perhaps you'd care to share and help us increase the community knowledge?

Yeah, that line didn't exactly sit well with me.  I'm certain it didn't carry the attitude that I interpreted, when I read it.  (At least, I'd hope not.   Wink)  And yes, I'm with tturner.  If you pwned it, please share, if for no other reason than to increase everyone's knowledge and abilities.

Oh, and assuming you did pwn it... Congrats!
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
camelCase
Newbie
*
Offline Offline

Posts: 12


View Profile
« Reply #11 on: June 20, 2012, 09:53:54 AM »

It had to do it by sending syn packets with scapy and backing off TTL until the firewall responded with an error packet containing its IP, finding out that the firewall was misconfigured and had its config interface in front of me, guessing the correct password, dumping its config, ssh tunneling through the firewall and proxy scanning the server, enumerating some users, discovering a user with pass as user, looking in the sysvol, finding a bat script with domain admin permissions and rdp. So still not just IIS or web app but just pure luck. I think that is vague enough to not give up any confidential data but informative enough to "share". :-) 
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #12 on: June 20, 2012, 11:54:04 AM »

Yep.  Gives enough for those of us who understand, and not so much as to get you into trouble.   Wink

Thanks.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
camelCase
Newbie
*
Offline Offline

Posts: 12


View Profile
« Reply #13 on: June 20, 2012, 03:45:33 PM »

Np homie, sorry if I come off as quippy or arrogant I just do not have a lot of time for long posts. Nothing personal.
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #14 on: June 20, 2012, 03:54:12 PM »

It's all good.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.07 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.