Security Basics mailing list archives
Re: Suspicious IIS Log entry
From: Tomas Wolf <tomas () skip cz>
Date: Wed, 10 Sep 2003 06:51:16 -0400
Hi, I was trying the second one on my system but in a differnet matter. Again it has been a year, but I have used translation for almost all the "symbols" beyond the /scrpits folder. It was old volnurability that was using logical path to the "cmd.exe" file on C:\Winnt\system32 directory. It won't give you your cmd on the remote machine, but if you specify a little more it will do things (ie. .....cmd.exe+dir) should return to the browser list of current dir... so "cmd.exe+echo+"You%20Were%20Hacked"+&20+>>+&20+C:\Inetpub\WWW\index.html" (the path would be in hex values of the characters, but I'm too lazy to look it up :-) or something near this would add (or if we would have used only ">" ot would replace everything) to index.html text "You Were Hacked"... But by crafting nicer arguments to the cmd.exe+ will of course lead to more serious results... The explanation is easy: when you are on a localhost, you can use "logical paths" -- which are ../ ci ./ to switch from one to another folder... Well and this does the same... Assumed that WWW root is localy in: C:\InetPub\WWW\, then if we remotely specify to ../../ then we are on C:\. And I believe that more explanation is not necessary :-). Only that it was done through a simple browser.
That was one of the features of IIS :-)I hope it was at least a little informative, but some information doesn't have to be exact, it's been a while since I have "work-researched" this url string.
Tomas Toby Schau wrote:
I found the following suspicious entries in my IIS log files. Does anyonerecognize the specific vulnerabilities that are attempted to be exploited? [ex030809.log (20)] : 2003-08-09 05:14:10 xxx.xx.xx.xx- xx.xx.xx.xx 80 GET/default.ida XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u90 90%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a 404 -[ex030908.log (201)] : 2003-09-08 06:31:02 xx.xxxxx.xxx - xxx.xx.xxx.xx 80 GET /<Rejected-By-UrlScan> ~/scripts/..%255c%255c../winnt/system32/cmd.exe404 - Thanks---------------------------------------------------------------------------Captus Networks Are you prepared for the next Sobig & Blaster? - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans - Precisely Define and Implement Network Security - Automatically Control P2P, IM and Spam Traffic FIND OUT NOW - FREE Vulnerability Assessment Toolkit http://www.captusnetworks.com/ads/42.htm----------------------------------------------------------------------------
---------------------------------------------------------------------------Captus Networks Are you prepared for the next Sobig & Blaster? - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans - Precisely Define and Implement Network Security - Automatically Control P2P, IM and Spam Traffic FIND OUT NOW - FREE Vulnerability Assessment Toolkit http://www.captusnetworks.com/ads/42.htm
----------------------------------------------------------------------------
Current thread:
- Suspicious IIS Log entry Toby Schau (Sep 09)
- RE: Suspicious IIS Log entry Michael Moeller (Sep 09)
- Re: Suspicious IIS Log entry Tomasz Onyszko (Sep 09)
- Re: Suspicious IIS Log entry Flhex (Sep 09)
- RE: Suspicious IIS Log entry Paul Kurczaba (Sep 09)
- Re: Suspicious IIS Log entry Sean Earp (Sep 09)
- RE: Suspicious IIS Log entry Joey Peloquin (Sep 09)
- RE: Suspicious IIS Log entry Byron Copeland (Sep 10)
- Re: Suspicious IIS Log entry Tomas Wolf (Sep 10)
