Penetration Testing mailing list archives

Re: Webdev fuss so what?


From: mvillanova <mvillanova () citadel com>
Date: 09 May 2003 13:56:34 -0500

On Thu, 2003-05-08 at 19:16, peter devris wrote:
What is all the fuss about the webdev vul?

I have an IIS5.0 server SP3 and thought I best check
this out so tried the following to test and exploit my
server

webdevfinder.pl - by SensePost Research
      returns - WebDAV possibly in use

Try using the KaHT tool, (www.greyhat.org) it will return a root shell
or add a user depending on your command line switch.  I've found it very
accurate.  

---------------------------------------------------------------------------
Did you know that you have VNC running on your network?
Your hacker does.
Plug your security holes.
Download a free 15-day trial of VAM:
http://www.securityfocus.com/StillSecure-pen-test
----------------------------------------------------------------------------


Current thread: