Remote Exploit Forums

Go Back   Remote Exploit Forums > BackTrack News


BackTrack News Updated BackTrack news from Offensive Security blog

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 09-01-2009, 03:12 AM
muts
 
Join Date: Jan 2006
Posts: 149
Default Microsoft IIS FTP 5.0 Remote SYSTEM Exploit



A remote Microsoft FTP server exploit was released today by Kingcope, and can be found at http://milw0rm.com/exploits/9541, A quick examination of the exploit showed some fancy manipulations in a highly restrictive environment that lead to a”useradd” type payload. The main issue was the relatively small payload size allowed by the SITE command, which was limited [...]

More...

Last edited by muts; 09-01-2009 at 06:40 AM.
Reply With Quote
  #2 (permalink)  
Old 09-01-2009, 03:50 AM
pureh@te's Avatar
Jenkem Addict
 
Join Date: Mar 2007
Location: /dev/null
Posts: 5,401
Default

Mubix has also made a quick nmap script to search out this vulnerability.

More info on that here
Reply With Quote
  #3 (permalink)  
Old 09-01-2009, 04:42 PM
Junior Member
 
Join Date: Aug 2009
Posts: 7
Default

Doesnt work under w2003 server patched.
Reply With Quote
  #4 (permalink)  
Old 09-01-2009, 06:39 PM
theprez98's Avatar
Super Moderator
 
Join Date: Apr 2007
Location: Maryland
Posts: 2,530
Default

Quote:
Originally Posted by voodooo View Post
Doesnt work under w2003 server patched.
That's why is called an IIS 5.0 exploit!
__________________
theprez98
"I want peace on earth and goodwill toward men."
"We are the United States Government. We don't do that sort of thing!"
Reply With Quote
  #5 (permalink)  
Old 09-12-2009, 11:52 AM
Member
 
Join Date: Oct 2008
Posts: 70
Default

for german windows 2k prof you can use the following JMP ESP:

Code:
$retaddr = "\x7B\x30\xE3\x77"; # JMP ESP german win2k platforms (fully patched)

More details including screenshot can be found here: http://www.s3cur1ty.de/iis-ftp-exploit-german-win2k

m-1-k-3
Reply With Quote
  #6 (permalink)  
Old 09-23-2009, 06:00 PM
Armagedeon's Avatar
Member
 
Join Date: Feb 2008
Posts: 73
Default Replication Problem

Hello everyone

After a while I'm back... waiting eagerly for the final release of BT4...
I've tried to replicate this in a win2k Server SP0 box, in a VMware environment with no luck… could it be that the return address for JMP ESP is different in server version??? Or could it be related to the VMware environment? Any thoughts??

Thanks.
Reply With Quote
  #7 (permalink)  
Old 09-23-2009, 09:21 PM
Member
 
Join Date: Oct 2008
Posts: 70
Default

Quote:
Originally Posted by Armagedeon View Post
Hello everyone

I've tried to replicate this in a win2k Server SP0 box, in a VMware environment with no luck… could it be that the return address for JMP ESP is different in server version??? Or could it be related to the VMware environment? Any thoughts??
The JMP ESP is different in the different Service Packs and also in the different languages.

m-1-k-3
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 01:03 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2