APPZXOR
Hello and welcome to APPZXOR,

We would appreciate if you register so you can enjoy
the full benefits of browsing, viewing and using our forum.
Here are some features:

• Create threads;
• Reply to threads;
• View links & images;
• Leave positive or negative feedback to a member.

What are you waiting for? Go ahead and register!
It's free, quick and easy!
APPZXOR
Hello and welcome to APPZXOR,

We would appreciate if you register so you can enjoy
the full benefits of browsing, viewing and using our forum.
Here are some features:

• Create threads;
• Reply to threads;
• View links & images;
• Leave positive or negative feedback to a member.

What are you waiting for? Go ahead and register!
It's free, quick and easy!
APPZXOR
Would you like to react to this message? Create an account in a few clicks or log in to continue.


Where Applications Become AppZ. Join Us Now!
 
HomePortalSearchLatest imagesRegisterLog in
Search
 
 

Display results as :
 
Rechercher Advanced Search
Latest topics
» See you next decade.
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeby LarsValraz Fri Sep 09, 2022 4:43 pm

» Clean Up On Database
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeby Vex338 Mon Jul 06, 2020 2:59 pm

» Guess who's back!
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeby Vex338 Thu Feb 01, 2018 12:16 pm

» [COC] Clash of Clans
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeby D'ShadowZRay Thu Jan 28, 2016 12:10 am

» iam new
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeby D'ShadowZRay Thu Jan 28, 2016 12:06 am

» I need some help
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeby akumasan_01 Fri May 01, 2015 1:25 pm

» HELLO GUYS! :))
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeby Appz-RhastaSix Fri Sep 19, 2014 9:14 am

» Visual C# Programming Basics
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeby Appz-RhastaSix Wed Sep 10, 2014 9:03 am

» Old Game!
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeby iRegen Tue May 13, 2014 12:28 am


Top posters
[Detheroc_93]
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_lcap[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_voting_bar[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_rcap 
MrStar
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_lcap[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_voting_bar[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_rcap 
kurosakinaruto
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_lcap[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_voting_bar[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_rcap 
GreyPhantom
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_lcap[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_voting_bar[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_rcap 
ShadowSonic
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_lcap[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_voting_bar[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_rcap 
Appzwesley29
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_lcap[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_voting_bar[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_rcap 
z_f
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_lcap[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_voting_bar[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_rcap 
MasterGandeo
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_lcap[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_voting_bar[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_rcap 
Vex338
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_lcap[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_voting_bar[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_rcap 
wafumon
[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_lcap[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_voting_bar[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  I_vote_rcap 

Share | 
 

 [TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.

View previous topic View next topic Go down 
AuthorMessage
MenzTration
Ultra Member

MenzTration

Posts : 525
Join date : 2011-11-28
Age : 26
Location : HELL

[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Empty
PostSubject: [TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.    [TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeSat Jan 28, 2012 3:52 am

Today I will be teaching a way to exploit very common a vulnerability and upload your shell and/or deface page to a Microsoft IIS 6.0 based website.

What you will need:
A windows machine.
Basic knowledge of shells.
A Microsoft/IIS 6.0 website with WebDAV enabled.
An ASP shell. - [You must be registered and logged in to see this link.] << Download link for the shell. (Do not even try a PHP shell, it won't work. You can use your ASP shell to upload your PHP shell after though.)

This is how to perform the exploit in Windows 7:
Click start > Computer.
You will see this page: [You must be registered and logged in to see this link.]

Next you will want to click "Map network drive", it has been circled in the picture above.
Now a window will pop-up, it should look like this: [You must be registered and logged in to see this link.]

As you can see again. I have circled what needs to be clicked. So click on that then a window will come up asking you to click "Next", do so. After you have clicked the "Next" button, you should see this: [You must be registered and logged in to see this link.]

You will need to highlight/click that folder I circled, then hit the "Next" button once again. It should redirect you to this page: [You must be registered and logged in to see this link.]

I put "[You must be registered and logged in to see this link.] as an example. You have to type in "http://vulnerablesite.com" otherwise it will not work. It requires HTTP, not [You must be registered and logged in to see this link.] You will receive an error unless you use HTTP (once again, [You must be registered and logged in to see this link.]
Hit the "Next" button again, then it should come up with the site name with the output "vulnerablesite.com", you can name it whatever you like, this is what I put: [You must be registered and logged in to see this link.]

Except I changed it to "IIS 6.0 Exploit for HF - Phizo".
It doesn't matter what you put, just make sure you remember it.
Make sure the box is ticked (open when finished) then go ahead and hit finish.
Okay, we've exploited the website. Now we want to upload our files to the website. A new window has just opened, as you can see, we're connected to the websites files, however we're not aloud to view the files as we're unauthorized. No matter, we can still upload our shells and what other files we would like to upload.
Okay, I don't think I will need to put any pictures in this one, it's that simple. Follow my instructions:
#1 - Open the directory of where your ASP shell is (example: desktop, documents, or custom folder). Your ASP shell should have a name similar to "shell.asp;anything.jpg".
#2 - Drag your ASP shell from your custom folder into the website folder we just exploited. It should just go straight in there with no problems.
Tada! We have successfully uploaded our shell! Now all we have to do is go to: [You must be registered and logged in to see this link.]

I hope this helps.
Back to top Go down
GreyPhantom
Administrator
Administrator

GreyPhantom

Posts : 3058
Join date : 2011-04-19
Age : 27
Location : Place Of Geeks

[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Empty
PostSubject: Re: [TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.    [TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeSat Jan 28, 2012 4:14 am

LOL The Link is Removed Bro , See this link?


An ASP shell. - [You must be registered and logged in to see this link.]
Back to top Go down
[Detheroc_93]
Administrator
Administrator

[Detheroc_93]

Posts : 5628
Join date : 2011-03-12

[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Empty
PostSubject: Re: [TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.    [TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitimeSat Jan 28, 2012 9:48 am

Why the link is removed?
Back to top Go down
Sponsored content





[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Empty
PostSubject: Re: [TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.    [TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.  Icon_minitime

Back to top Go down
 

[TuT] Exploiting Microsoft/IIS 6.0 WebDAV - Uploading Files.

View previous topic View next topic Back to top 

 Similar topics

-
» how to bypass http://uploading.com/ downloads per-day
» MICROSOFT OFFICE 2010 PROFESSIONAL PLUS X86 X64 SP1
» [31-Jan-2012] Premium accounts [Wupload,Filesonic,Uploading,Hotfile,Fileape etc] ( Updated Daily ! )
» magic of microsoft
» Microsoft hit with formal warning
Page 1 of 1

Permissions in this forum:You cannot reply to topics in this forum
APPZXOR :: Discussions :: Tools and Programs-
Create a forum on Forumotion | ©phpBB | Free forum support | Report an abuse | Forumotion.com