Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Windows 2000 SP4 + IE (fully patched) - restrictions bypass

Windows 2000 SP4 + IE (fully patched) - restrictions bypass

From: Bartosz Kwitkowski <bartosz_at_wb.pl>
Date: 2 Nov 2004 01:31:31 -0000
('binary' encoding is not supported, stored as-is) Windows 2000 SP4 + IE (fully patched) - restrictions bypass

Restrictions for example:
- disabled protocols (ftp://,file://,news://,...);
- you can't view computers in your network, and you can't explore their resources

Bypass it :-)...

open your browser (IE) and type:
javascript:window.open('\\\\\\\\\\{computer name,or IP, or URL}\\{resource, for example D$}')

Windows changes those \\\... into file:// and restrictions are useless :-).

ex.: javascript:window.open('\\\\\\\\\\10.9.9.1\\D$')
and you if you know pass you can log in or download a file :-).

Regards,
Bartosz Kwitkowski
Received on Nov 03 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos