Captain
08-22-2002, 01:38 PM
Hi,
That is big problem in server windwos evryone can get for that he can hacker all server, That expolit apper in server iPlanet when him search.
version It have
- iPlanet Web Server 6.0 SP2
- iPlanet Web Server 4.1 SP9
on system Windows NT and Windows 2000
Can you see That win you use command
NS-query-pat in HTML on server iPlanet.
After That you see
GET /search?NS-query-pat=..\\..\\..\\..\\..\\boot.ini
That is expolit in this server after that you can see contents boot.ini .
If you want cancel That problem Just Stop search as we fine other that.
Regards,
Captain
SynHost
08-22-2002, 04:37 PM
I can't even decipher your message..
Captain
08-22-2002, 05:42 PM
Sorry My English language not good :bawling:
I will write the messege again
dbzgod
08-22-2002, 05:47 PM
Originally posted by Captain
Hi,
That is big problem in server windwos evryone can get for that he can hacker all server, That expolit apper in server iPlanet when him search.
version It have
- iPlanet Web Server 6.0 SP2
- iPlanet Web Server 4.1 SP9
on system Windows NT and Windows 2000
Can you see That win you use command
NS-query-pat in HTML on server iPlanet.
After That you see
GET /search?NS-query-pat=..\\..\\..\\..\\..\\boot.ini
That is expolit in this server after that you can see contents boot.ini .
If you want cancel That problem Just Stop search as we fine other that.
Regards,
Captain
I understnad. What he is saying is:
That is big problem in server windwos evryone can get for that he can hacker all server, That expolit apper in server iPlanet when him search.
There is a big problem in windows servers that everyone can get at. He can hack the server. The exploit is in the server iPlanet when the hacker does a search.
version It have
- iPlanet Web Server 6.0 SP2
- iPlanet Web Server 4.1 SP9
on system Windows NT and Windows 2000
This hack can be used in versions iPlanet Web Server 6.0 SP2 and iPlanet Web Server 4.1 SP9. Only on Windows NT and 2000 servers.
Can you see That win you use command
NS-query-pat in HTML on server iPlanet.
After That you see
GET /search?NS-query-pat=..\\..\\..\\..\\..\\boot.ini
That is expolit in this server after that you can see contents boot.ini .
Can you see that when you use the command NS-query-pat in html on the server iPlanet you can see GET /search?NS-query-pat=..\\..\\..\\..\\..\\boot.ini.
This is an exploid in the server that you can see teh contents of boot.ini
If you want cancel That problem Just Stop search as we fine other that.
If you want to get rid of the exploit, just stop the search feature and you will be fine other than that.
Hope this helps,
Andy
Captain
08-22-2002, 06:23 PM
Yeah
That is right
Thank you Mr. dbzgod
Hope this helps,
Captain
nathanp
08-23-2002, 06:36 PM
what is iplanet used for ? does it come installed defaultly?
Man I'm still going "Huh!" :confused:
dbzgod
08-23-2002, 10:10 PM
I'm guessing iPlanet is a webserverl ike apache???
markcastle
08-23-2002, 10:15 PM
Does anyone still use iPlanet?
Samuel
08-23-2002, 10:20 PM
Attempting..
Hi,
There is a major exploit available in Window's servers running the Iplanet software. This problem exposes the entire server allowing the attacker to take over the system.
The exploit appears in Windows server (WinNT 4 - Windows 2000 Server).
Specific Version Information.
- iPlanet Web Server 6.0 SP2
- iPlanet Web Server 4.1 SP9
The above software runs on Windows NT4 Server, and Windows 2000 Server.
If you have this combination of software you can test for the exploit by:
Using the command command NS-query-pat in HTML within the iPlanet server.
An exploitable system will result from that query this:
GET /search?NS-query-pat=..\\..\\..\\..\\..\\boot.ini
This exploit allows the attacker to view the boot.ini
One way that has been used as a workaround has been to stop the search function.
Regards,
Captain
IPlanet is the old Netscape Web Server now owned by IPlanet ( which belongs to AOL I think).
Mac
anantatman
08-24-2002, 04:26 AM
yeah when it was named to iPlanet it had a built JSP/Servlet container like Tomcat, and a J2EE compliant EJB container.
basically a Java Application Server like BEA or WebSphere
Captain
08-24-2002, 08:11 AM
I Thank iPlanet it name for software use in server windows without apache
Just That my Option