Penetration Testing mailing list archives

RE: IIS & w2k


From: "Read, Greg" <ReadG () JAGUARS NFL com>
Date: Mon, 4 Jun 2001 12:48:08 -0400

If you're after a MS SQL server, check out http://www.sqlsecurity.com/

-----Original Message-----
From: Luis Javier Perez [mailto:lperez () scitum com mx]
Sent: Monday, June 04, 2001 10:49 AM
To: pen-test () securityfocus com
Subject: IIS & w2k


Hi everyone.

I'm actually doing a pt, and i'm facing a trouble, the scenario has a web
server with w2k and iis 5.0, now i have put netcat listening on port 99 and
i can browse files and stuff like that but i need to scale privileges, i
tried hk but it fails.. is there something like hk for win2k???
With the info i collected i noticed the server connects with a sql server..
how can i do to exploit the sql..

any help would be appreciated..


thanks..





Current thread: