undetected asp shell ?

No explicit questions like "how do I hack xxx.com" please!
Post Reply
User avatar
Radar_mX
suck-o-fied!
suck-o-fied!
Posts: 82
Joined: 03 Feb 2008, 17:00
16

undetected asp shell ?

Post by Radar_mX »

hi all suck-o members ,

Please if anyone has an undetected web shell I mean like insominashell or c99

I am looking for undetected one and written in asp or aspx

server doesnt have php , perl or python so it is useless if I upload php shell because I already successfully uploaded many unsupporeted files and I can see them, it has asp running but tried many asp shells all got detected.

---
look
http://img34.imageshack.us/i/32345916.jpg/

User avatar
Big-E
Administrator
Administrator
Posts: 1332
Joined: 16 May 2007, 16:00
16
Location: IN UR ____ , ____ING UR _____ .
Contact:

Post by Big-E »

Why don't you write your own?

Please forgive me if my allegations are misplaced, but if I am right, then you activities are the reason why most of us legitimate programmers/hackers are frowned upon when we mention that we like to hack. Instantly, they think of people like you; the skid who will one day upload commonplace scripts to the wrong server and get caught. Upon being charged, you will be labeled a hacker - which is an insult to people like us.

On another note, I should probably come out and say we are a fairly friendly community - but we just don't put up with people who have their head shoved up their ass.

Please re-evaluate your question for a better answer.

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

always worth a look (but don't expect fully precoded stuff):
http://www.shell-storm.org/

:wink:
Image

User avatar
Radar_mX
suck-o-fied!
suck-o-fied!
Posts: 82
Joined: 03 Feb 2008, 17:00
16

Post by Radar_mX »

Big-E wrote:Why don't you write your own?

Please forgive me if my allegations are misplaced, but if I am right, then you activities are the reason why most of us legitimate programmers/hackers are frowned upon when we mention that we like to hack. Instantly, they think of people like you; the skid who will one day upload commonplace scripts to the wrong server and get caught. Upon being charged, you will be labeled a hacker - which is an insult to people like us.

On another note, I should probably come out and say we are a fairly friendly community - but we just don't put up with people who have their head shoved up their ass.

Please re-evaluate your question for a better answer.

I know that I amn't supposed to ask questions directly . I didn't ask any1 to hack for me no explicit hack xxx.com

and I dont consider myself as scriptkiddie/skid compared to my knowledge

anyway thanks , next time I will try ask for help the innocent way and innocent questions

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

what IIS version do you have in mind btw?
Image

User avatar
Radar_mX
suck-o-fied!
suck-o-fied!
Posts: 82
Joined: 03 Feb 2008, 17:00
16

Post by Radar_mX »

IIS4.0

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

wow, this is funny, google is acting weird....when I search for "iis 4 shell" everything is normal, but when I search for "iis 4 shell asp" I get a "we're sorry, automated request, blah" screen and have to enter a captcha, even after entering it I get the same screen again.... *screwy*

can someone verify this?
Image

User avatar
computathug
Administrator
Administrator
Posts: 2693
Joined: 29 Mar 2007, 16:00
17
Location: UK
Contact:

Post by computathug »

Both links worked fine for me :?
The devil can cite Scripture for his purpose.
-- William Shakespeare, "The Merchant of Venice"
https://tshirt-memes.com

User avatar
ph0bYx
Staff Member
Staff Member
Posts: 2039
Joined: 22 Sep 2008, 16:00
15
Contact:

Post by ph0bYx »

Works fine here too :/

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

odd....it's not random, I can reproduce it every time...

here's "iis 4 shell asp":
Image

and here "iis 4 shell":
Image
Image

User avatar
Radar_mX
suck-o-fied!
suck-o-fied!
Posts: 82
Joined: 03 Feb 2008, 17:00
16

Post by Radar_mX »

on a page says "Welcome to IIS4.0" but with scanning server banner says Microsoft-iis/5.0

it is mostly probably IIS 5

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

hm, server banners are easy to spoof, have you used nmap to check the OS? you can also do a check on netcraft.com, their results are pretty reliable and it would be more stealth... :wink:
Image

User avatar
Radar_mX
suck-o-fied!
suck-o-fied!
Posts: 82
Joined: 03 Feb 2008, 17:00
16

Post by Radar_mX »

bad_brain wrote:hm, server banners are easy to spoof, have you used nmap to check the OS? you can also do a check on netcraft.com, their results are pretty reliable and it would be more stealth... :wink:
yes, I did nmap scan

nmap output line:
5000/tcp open http Microsoft IIS webserver 5.0

*thumb*

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

you should use the -A switch to check the OS, as I said, server banners are easy to spoof...suck-o "was running on IIS" too for a while... :lol:
if the OS says MS too then you can be pretty sure, because OS fingerprinting is a little harder to evade because the server admin has to manipulate the TCP stack... :wink:
Image

User avatar
Radar_mX
suck-o-fied!
suck-o-fied!
Posts: 82
Joined: 03 Feb 2008, 17:00
16

Post by Radar_mX »

nmap guessing many windows versrions with different percents at the end there is

OS: Windows

the bad news it is only running ASP.NET technology

Post Reply