請問查到這些資料有什麼用呢?



贊助商連結


Stranger
2001-08-15, 03:49 PM
小的今天因為閒著沒事便隨便找一個被防火牆檔下來的IP進行試驗...卻發現了如下資訊:
* + 211.*.*.*
|___ 25 [smtp] Simple Mail Transfer
|___ 42 [nameserver] WINS Host Name Server
|___ 53 [domain] Domain Name Server
|___ 80 [http] World Wide Web HTTP
|___ 119 [nntp] Network News Transfer Protocol

- Probing NT/2000 WWW Vulnerabilities -
Checking: Frontpage98 Hole(_vti_inf.html) !!! FOUND !!!
Checking: IIS Path Reveal(anything.idq) !!! FOUND !!!
Checking: IIS Path Reveal(anything.ida) !!! FOUND !!!
Checking: Index Server Security Hole(null.htw) !!! FOUND !!!
Checking: FrontPage 2k <=1.1 Path vul !!! FOUND !!!
Checking: FrontPage 2k,IIS Multiple (shtml.dll) !!! FOUND !!!
Checking: Frontpage97 fpcount bof(fpcount.exe) !!! FOUND !!!
Checking: FrontPage MS-DOS Device DoS(shtml.exe) !!! FOUND !!!
Checking: IIS 4/5 UNICODE !!! FOUND !!!
Checking: IIS 4/5 remote execute check method A !!! FOUND !!!
Checking: Site Server 2 File Upload(uploadn.asp) !!! FOUND !!!
Checking: Site Server 2 File Upload(postinfo.asp) !!! FOUND !!!
Checking: IIS some information(default.asp) !!! FOUND !!!
Checking: Indexing service for win2k .htw !!! FOUND !!!

請問....這些代表什麼意思?
如果是"有心人士"會做些什麼事情呢? :confused:

贊助商連結


milwater
2001-08-18, 11:31 AM
你是用什麼東東查的?:confused:

Stranger
2001-08-18, 03:44 PM
小的是先用「SuperScan」軟體查該主機有開放哪些Port,再用「Twwwscan」找漏洞∼:)

milwater
2001-08-20, 08:46 AM
難怪..
看它的文字敘述好像是在抓某IP的漏洞.
看來對方IP沒做Port Filter沒架防火牆.
若是某名駭客要動他, 那很簡單, 只要使用某些Hacking Software(eg:NC,Legion)來做,
不過就直覺上來說, 對方是被當做跳板的機會很大, 所以別把對方當駭客,
應該也是被害者..

Stranger
2001-08-20, 08:53 AM
謝謝大大的說明,小的知道了∼:)