RE: IIS & w2k

From: Yonatan Bokovza (Yonatanat_private)
Date: Mon Jun 04 2001 - 09:50:51 PDT

  • Next message: Harold Thimm: "How secure are dongles for copy-protection?"

    There's some newfound evil in win2k debug
    registers, see:
    http://www.securityfocus.com/bid/2764 
    
    For further investigations regarding SQL see this list
    archive.
    
    Regards,
    Yonatan Bokovza
    Xpert Systems
    
    > -----Original Message-----
    > From: Luis Javier Perez [mailto:lperezat_private]
    > Sent: Monday, June 04, 2001 17:49
    > To: pen-testat_private
    > Subject: IIS & w2k
    > 
    > 
    > Hi everyone.
    > 
    > I'm actually doing a pt, and i'm facing a trouble, the 
    > scenario has a web
    > server with w2k and iis 5.0, now i have put netcat listening 
    > on port 99 and
    > i can browse files and stuff like that but i need to scale 
    > privileges, i
    > tried hk but it fails.. is there something like hk for win2k???
    > With the info i collected i noticed the server connects with 
    > a sql server..
    > how can i do to exploit the sql..
    > 
    > any help would be appreciated..
    > 
    > 
    > thanks..
    > 
    > 
    > 
    



    This archive was generated by hypermail 2b30 : Mon Jun 04 2001 - 12:09:32 PDT