1. INTRODUCTION
2. HOW TO FIND THEM
3. HOW TO USE THEM
4. THE DIFFRENT TYPES OF EXPLOITS
5. SOME GOOD SITES TO FIND THEM
--------------------------------------------------
1. INTRODUCTION
----------------------
Exploits are used to gain root on a system. Root is just really being the administrator of the system you hope to gain access to. Exploits are found by a file which you can access though http normally, thats how you would use a scanner to check for the exploit. There are many diffrent kinds of exploits e.g ones that let you upload, view files and delete, Buffer overflows, ROOT and DOS (Dential Of Server) attacks (I don't really belive that a dos attack is an exploit). The ones which let you upload.view and delete are normally though a script or http e.g Frontpage extensions and Cold Fusion. Bufferoverflows really act a bit like a DOS attack it gives the server to much info or really just confuses the server and gives you root access to it. A DOS attack is normally when the server cpu overloads and causes the website to come offline. This can be done bye useing GET/POST methods though http or though a script (Linux).
2. HOW TO FIND THEM
---------------------------
To find out if you can exploit the server you need to know if an exploit exists. You can almost find out if an exploit exists though a file which you can see though your browser. There are two methods of checking to see if there is a file on the server these are by either typeing the file path in the address bar or getting an exploit scanner. There are many diffrent scanners about but the best ones I have found for windows and linux would be these ones. For windows it would be CGIscan which allows you to add extra exploits to a file which it read from. You can get this from http://www.wangproducts.co.uk. There are many good scanners for linux but one of the best I would say would be the one from insecure.org. This has some of the best exploits to use in it. If you ever want to check for a new exploit out insecure.org is a site which collects exploits and rootshell.com. Rootshell has a search engine which allows you to search for keywords e.g Redhat6.2. If there is know records found or and exploit containing the keywords you typed in it has an option to search other search engines on exploit sites.
3. HOW TO USE THEM
--------------------------
I often get alot of questions from people who have found an exploit from a scanner but don't know how to use it. If I find an exploit when scanning a site and don't know what it is I will vist the url of the file which the scanner picked up see what it contains and what information it gives me. If im still stuck on this exploit I would vist rootshell and use the big search engine and type in the name of the exploit found. About 99% of the time it finds what I searched for. Then you would vist the link and read every bit about this exploit. Normally the file on it contains everything you need to know about the exploit you have found and how to use it/patch it. Some times it is best to know a programming language just in case you need to write a program to use the exploit. Its just that you can't always find a program to do what you want it to do!
4. THE DIFFRENT TYPES OF EXPLOITS
--------------------------------------------
I mentioned a little bit about the diffrent types of exploits in the introduction but in this section ill go in a bit more depth about them. The main type of exploit you will probley be looking for would be one to get you root on the server. If you get root on a server you are really the administrator. You have complete access to all files/logs and you don't have restrictions on the commands you give to the server. Being root also allows you to create your self some more account just like root useing a series of commands though telent. Root can be gained from alomost every kind of exploit there is (http,files,commands though a shell, Even a program,Bufferoverflows). It just depends on what the exploit does/works it might just get you upload/delete/view access though http or it could give you the username and password in plain text or des/md5 encrypted form. A bufferoverflow is another method of getting root. Somtimes these can be the best to get root with but all so could get you caught very easy depending how the bufferoverflows works. A bufferoverflows tricks the server into giveing you root access. It works a bit like a DOS attack but does not cause damage like a DOS attack does. It just sends so much commands to the server and the server ends up giveing out root to the person that caused the Bufferoverflow. This works because the server gets to much data and can't really keep up/loses track and can be tricked into giveing out root access
5. SOME GOOD SITES TO FIND THEM
-------------------------------------------
Here are some good sites to find exploits on. packetstorm.securify.com / www.securityfocus.com /www.insecure.org / www.rootshell.com that should keep you going for a while. After some time you will find many more sites that might be big or might be small. Some times the small sites can be the best if they have people who look for bugs in new software because they will have the first site to see it posted on if they find a good exploit.
RSS Subscribe
Saturday, May 9, 2009
Subscribe to:
Post Comments (Atom)

0 comments:
Post a Comment