MZ@ !L!This program cannot be run in DOS mode. $PEL6  \@dT.textv `.rdata@@.datal@.idataf@U VEf0@fE 2@Mf4@fU6@E}urhM QRh@AC h@AE}u3q E}u3\h8@1CAPB35}+M QREPAurhM QRh@AC h@AE}u3yE}u3h@@BN=AP B3M QREPaAurhM QRh@AB h@AmE}u3UE}u3@hP@ByAPA3h\@A3}M QREP@FM QREP@@#u8M QREP}@FM QREPc@@#tihM Q Rh@AA h@AhE}u3SE}u3Ah|@AAP@3h@@33^]UQE}}lE@A\ttU@A_uh@q@3MM닸]Uh@D@]Uhh@AP`@ h@QAh @RAA=AuPh$@?37Qh@?h@Ah@Ah@AR@]UQE؉E}t]UQEh؉E}t 9]UQE;؉E}ts V;9 h@>]UEfDžhlPfhQ[=E}th@>3lul%%%th@s><3dh@A<A=Auh@E>3;$Af A AQ RAH Rh$A@ ]U EEE$Af Aj<f"AAH QAB Qh$Aa@ jO<f"Ajjj8<@Ajh A@AR<=@Auh@[=@AP;3)h@<=} }`jh Ajjh @ @AQ;Eh CjjjhR@AP;tEMM뚃}h$@AR=hP@AP=h@ AQ=h@AR=h@@AP=h@ AQ=h@AR=hx@APo= h*A <]U EEE$Af Aj:f"AAH QAB Qh$A{> ji:f"AjjjR:@Ajh A@AR4:=@Auh@u;@AP :3%h@V;}}mjh Ajjh@ @AQ9Eh$AjjjhR@AP9tEh@MM덃}h@AR<h8@AP;h@ AQ;h@AR;h8@AP;h@ AQ;h@AR;hx@AP|;jjjhQ@AR8h@AP=;h@ AQ);hP@AR;h@AP;h@ AQ:hT@AR:h@AP:h<@ AQ: h*Ad9E}}UƄEE]U$DžDž@Dž@}ƄDžj7f"Ajjju7@Ajh A@ARW7=@Auh@8@AP073h*Ay8jh A @AQ-7}Uh@U8@AR6}ƄDž3c}ƄDžjhQ@AR6PQ=t~Dž}f+ u Dž7+  h*A7h@6Qh@AR 8 jjh @@AP5jhQ@ARm5331ƅjjh@@AP5jhQ@AR4203 0h<@AP27ƅjjh@ @AQ4ƅjhR@APq4Dž23uu0uiƅjhR@AP3QR@;t Dž5u$0u0u DžR2u70u+0uh@AP5Džƅjjh@@AR3jhP @AQ32u,0u 0uh@ARA5ƅjjh(@@AP2jhQ@AR2250ƅh0@AP4jjh@ @AQ2jhR@AP21u@5u40u(h@ AQD4h`8ƅƅjjh@@AR1jhP @AQu1ƅjjh@@ARH1jhP @AQ.11u,5u 0uh@ARo3jjh@@AP0jhQ@AR0'h@1jjh<@@AP0hD@ AQ2@ARO03]UEjD0f"Ajjj-0@Ajh A@AP0=@Au hT@Q1 @AQ/3h*A11jh A@AR/}h*A 1@AP/3hh@ AQ'2h@AR2h@AP2h@@ AQ1h@AR1h@AP1hP@ AQ1@AR/]UEPE}h|@50}u h@ AQ* h@AR hx@AP QZ3]UDžjPLf"Ajjj5jh APu h@WQ3h+A7jh AR} h@P3[jj#h,@QjhRPE2h@Ah@AhP@ARh@APh@ AQhT@ARh@APh@ AQxh@ARdh@APQhD@ AQ=h@AR)=*At-h@PQ*ARJ3]UDžjP<f"Ajjj%jh APu h@GQ3<h +A'jh AR} h@P3jj.h0@QjhRP|E2h@Ah@Ah`@ARh@APh(@ AQh@ARh@AP|=*At-h@QRJ*AP3]UDžjPf"Ajjjxjh APYu h0@Q13<h+Azjh AR.} hD@VP3jj+hX@QjhRPE2h@Ah@Ah@ARh@AP hD@ AQh@ARh@AP=*At-h@QBR*AP3]UdEEH@EP@jPf"Ajjjjh APu hT@Qy3Gh+Ajh ARv} hh@P53jjh|@Q1EjhRPEMQRcE}E}F}'E+EUDMMӋUREPE}t7h@ AQh@ARhD@| h+A h+AP-3]UdEET@E\@jPf"Ajjjjh APu h`@Q3Gh +Ajh AR} ht@Pr3jjh@QnEjhRPWEMQRE}E}F}'E+EUDMMӋUREPOE}t7h@ AQRh@AR>hT@ h$+A h(+APj3]UdEEl@Et@jPQf"Ajjj:jh APu hx@\Q3Gh,+A<jh AR} h@P3jjh@QEjhRPEMQRE}E}F}'E+EUDMMӋUREPE}t7h@ AQh@AR{ht@ h0+A h4+AP3]UdEE@E@jPf"Ajjjwjh APXu h@Q03Gh8+Ayjh AR-} h@UP3jjh@QEjhRPEMQRE}E}F}'E+EUDMMӋUREPE}t7h@ AQh$@ARh@3 h<+A\ h@+AMP3]UWDž@ @~3fjPf"AURPh@Qh@ARh@PjjjFjh AQ'u h@hR3hD+AHjh AP} h@$Q3BjRPPQjhRPEjjh@QojhRPUE3҃23Ƀ0#3Ƀ1#хtURh@AP f3҃23Ƀ0#3Ƀ0#хtURh@AP7 MQhp@AR Pt3_]UEjPhf"AjjjQjh AP2u h@sQ 3hH+ASjh AR} h@/P 3jj#h@Q EjhRP E2uEh@Ah@Ah@ARh(@APh@ AQR- 3]UEjP" f"Ajjj jh AP u h@-Q 3hL+A jh AR } h@ P 3jj#h@Q| EjhRPe E2uEh@Ah@Ah@ARhl@APh@ AQR 3]UAAEAAMQh @$jjjhA t2jhP+AhT+AhA t3vh4@bjjAR{ u?jhX+Ah\+AhAg thL@ 3#h`@hx@^ 3]U,EEEEEEEԌ@Eh@/}EPMQUREPMQURjEP E}t }E MMU;UcEktM؋Rh@APK MktU؃| u%EktM؋Rh(@AP MktU؃| u"EktM؋Rh@AP SMktU؃| u"EktM؋Rh@AP !MktU؋ Ph@ AQ UktE؋D3ҹQPh@ARf EktM؋TPRh @APE MktU؋D `;EuFMktU؋ PMQuh@ARh@APMktU؁| Ct9EktM؁|t&UktE؁|CtMktU؁| u"EktM؋Rh\@AP h`+A MktU؋D Ph@ AQP UktE؋L(Qh@AR. EktM؋T$Rh@AP  4M AU;Us!EktMU؋.AMM׃}t URjjAPuh@3]UQEh@E EEM; AjU.APM.ARhAMuEh@}EPQRPMQjUR:E}t }Dž;Ok E QhH@AR EPEMQURPU jMQR k MRPk U| uhl@AP+jk U| uh@AP?k U| uh@AP h@ AQ k ELQh<@AR P%E}t MQ%3]U(EEEEEjhl+Ahp+AMQFt3URhX@AP ]UDžDžEƅ\ƅƅ\ƅ}V@AƄ 랍RSE}uh@ }h@AP h,@ AQ RcEhl@AP h|@ AQ RE}uPh@ AQ  ht+A3]UEE@hMf"Ajjj6@Ajh A@AP=@Au h@Z @AQ3hx+A:jh A@AR}h|+A@AP3h@jjh0A @AQEjhR@APEMQRE}E+EU3ɃSU3҃e#ʋE3a#ȋU3҃t#ʅtdhDAAPihA AQUhAARAhAAP.h\A AQhAARhAAP @AQHh+A@AR(]%4A%ËeEP>EMd _^[]Ð=+At+D$P+h AÐQVt$ t=D$ L$PQV0 tT$ PD$RPO0 ^YË DAVjQA^YÐ`ASUVt$W;Ƌ `A,`AD9tV6tBtujz6jn6;tVa6PAu A3V5UD:tS3_^][3_^][_^]+A +A[ÐVt$F t%t!FPF %F 3FF^ÐVt$u V^V6t^ËF @tFP5^3^ÐSVt$ 3WF ȃuFt?F>+~4VWPR5 ;NjF ut$^F F_^[ F FF_^[Ðj ÐAS\$UVW333~MpAt7H t/uPtEutPu AF;|t_^][ÐVt$WFP7PAu3 pAul +AA +AF uP+Auh6+At-+AFFF F F _^_3^ÐD$Vt4t$ F t=VEF FF F^ËD$ H t P^ÐLSUVW$d33L$Gۈ\$@$d(t$(t$(L$T$<(AT$,T$@DPt#$`L$QRP` G$d$`L$QRP= D$ D$D$D$Ã53Ɋk@$j@D$0uD$D$t9$hRPD$`PA4}.T$\D$4T$3$hQfD$\T$\T$ $hP@t:Ht3T$t(L$D$,(D$,L$=(A3|$ID$0uD$D$t$hQȋD$L$t:u ,AL$ND$,tf8t Nu+'u (AL$Nҋt 8t@Nu+$hP-L$ tfL$D$4fT$D$4D$D T$D$\D$D$@T$} D$u guD$$h|$$hHL$LPD$DT$PPWT$dQD$XRPp(At$$tuL$\Q|(AguuT$\Rt(A|$\-uD$D$D$]D$|$3ID$D$0 @D$iD$0 _D$D$8D$8'D$D$0t5L$8D$"0QD$$L$#D$D$0t D$D$\$ǀt$hRb t3@t$hPgB$hQQ%*@t$hR4$hP!3@t|s؃ڀ\$ǀuL$}\$ uD$$$[D$I҉L$ tDD$0RUWVT$h91T$XRUWV009~\$8D$L$HD$뫋L$$[+@D$t80uu HED$0D$4\$@t*tD$"-tD$"+ t D$" D$$|$(T$$++ u$`D$PVWj [$`T$$L$QVD$*RPztuL$QVWj0D$,t$]fT$HPR /~"$`L$QRPD$TPKuƋ\$t$`L$QRWj $dGۈ\$@$dD$_^][LËD$T$RVUPc@Db@ib@b@c@%c@jc@:d@b@b@b@b@b@i@c@d@c@*d@i@Xd@'f@'f@ hAt"5dA;rtЋ hA;sh@h@:h$@h @(uU+AA^][ÐVt$W|$;stЃ;r_^ËD$SUVP3X u@^][Ãu^][ËL$-+A +AH5(A,A;} v+֍ A Ju 4A=uR=uD=u6=u(=u=u =u 4AQjӃ54A-+A^][Q@Ӄ-+A^][ËT$RTA^][ÐT$ AV50A;ʸAt v A ;s9u v A;s9t3^ÐQ+ASUV3Wt<=tF3ID T uPCt$5+Au j -+AUtc3IC=tESu j 3D$+ы8ʃD$Tu+AP+A_^][YÐVWhh+AjXA=A+A+A?u+AD$ L$PQjjW[T$ D$ Q7u jL$T$ RD$ PRVWD$H5+A_+A^ÐD$SUl$Vt$W|$$D$t ul$8"uVH@"t8t4-AtBtF@BtFH@"uȋBtF8"uV@SBtF@L$$T$$-AtBtF@ t t uuHtF3҉T$$8 t u@8t ul$L$ 3ɀ\u X@A\t8"u%ut x"u@3\$$3҅‰T$$ItAt\FCIut]u tT tOtEt*ف-At F@AFA@`-At@A@CtFl$AtED$ _^][AÐ,ASU-AV33W=Au%׋tՋ؅,Au ׋f>tf8uf8u+j@jjjUVjjAt>WD؃t/jjWSUVjjAu S/3VA_^][VA3_^][ÃuhuՋ؅t\ ÄtH@uH@u+@VuSA3_^][Ë΋SA_^][_^]3[ÐD$SUVWP.A;l$(u 3_^][3;uh3_^][3Ҹ@A9(0B=0ArL$QUA@3-A󫪃|$vqD$t7T$ t-3B;w-A-A@;vBu͸-A-A@=rU-.AR.A 5.A5.A33.A.A.A_^][95.Atq3_^][Ã_^][ù@3-AR3PAEt0Nt)3;w8A-A@;vFuGrD$(P.ADAHA.ADA .A@.A_^.A]3[ÐD$.Au.A%Au.A%AuH.A.AÐD$\w'3Ɋ@$@øøø3̈́@ӄ@ل@߄@@W@3-A3_.A.A.A.A.AÐj)ÐHSUVWhu j_5`A;`A s F^ `A;rT$RAf|$FD$HxL$,|D$D$ `A;}idAhtI `A `A;s@X;r`AL$;| `AL$D$3~IMt4t.u QAt֋ `AUHD$FG;|-A3ۋ`Aڍ4ڃuTFu HPՋt*WAt%>uF @uF  F @F FC|`APA_^][HÐjhjADAuuDAPA3øÐUSVWUjjh@u"]_^[]ËL$AtD$T$SVWD$Pjh@d5d%D$ Xp t.;t$$t(4v L$H |uhD@Td _^[3d y@uQ R 9QuSQ<A SQ<AMKCk Y[VC20XC00USVWU] E@EEEECs {ta v|tEVUkT]^] t3x<{SkVS vjDaC T{ v4롸UkjS]]_^[]UL$)APAPy]+At u.=$Au%h .AthÐL$PASUVW3;t E=Ar; PA+ANu =$A=o$hPjXAu\@$f$3$уuGGh@hPAt-$.AJ$.AG t;vw D$EHD$t }׋t.zu(J 9u @=|=u R;=At D$B_^][ÐL$A;Hv;Hr =At:u3сr#T$T$ %+ȉD3ÐD$L$V3+H tDL$0@u$.A@ $.Au j^ÐQ 'AS\$ UVWL$Ay + ;s.;|9_vSPV ucL$_;rҋiyq;s.;|9^vSPW uAL$^;rҋ 'A;ȉL$t7[L$ 'A+Ӊy_^][YËL$ 'A+Ӊq_^][YýA9MtE umAE uD$+ 3;u} PF;tj hPWD$ |A;T$D$3Ʌ~2GPPƀANuՋT$ -'A;s9t;r;#E _U +ˉ G+ÍLG_^][Yt5HYT'A+ӁQP+ӉP_^][Y_^]3[YÐT$ SUVW|$G;‰L$r:;s7G+‰7G WGЍA+_^][8t;Ë\$suu<~Fu@A8t;s9l$;u O+;L$%,;r;s +ʉOyOko;s~ ;squ#~Fu@A8t;s+;rL%;t$r3_^][Í;s +ʉO /GF+_^][_^]3[ÐT$+A3ɸ'A;tEA=p(Arr$w +A Ár+Av +AË 'A+AÐSUVW33`AtD;sXt ;r+NjuoF `A|_^][hztH=`A ;`A=`As# @H`A;r_^][ÐD$ `ASV;Wswȋ`A<`A<2uV $A\$u<t.HtHu1SjtA03_^[SjtA03_^[SjtA03_^[_^+A +A[ÐD$ `ASV;Wshȋ`A<`A\2 2t=9t89$Au!tHt Hujj jjjjtA03_^[_^+A +A[ÐD$ `A;sȃ`ALt+A +AÐD$ `A;s?ȋ `ADt'PPpAuA3t+A+A ÐD$ `A;SUVWȋ`A<`A|$$t$La$83;݉l$l$ u 3_^][ t jUP @Q$4D$ۋD$(+;s(G u t$ F@t$ @ЍL$(+с|ЋT$(D$+T$$jPL$0VQL$$RAD$T$;ƉT$|+;rt$D$umD$t9u+A+A _^][Po_^][ËL$$D@t}u 3_^][+A+D$ _^][+A _^]+A[AD$GL$U$8QSURAtD$D$D$AD$ X.AL$PQÐVt$Ww4u|$w V-3utV u3_^ÐD$Vp'A;wQauDAVjRA^ÐD$ `A;r3Ëȃ`AD@ÐD$uË 8.AufL$fwDË*AL$Q H.AjRPD$jPh QD$$AtL$t +A*ÐSVD$ uL$D$3؋D$ Aȋ\$T$D$ ud$ȋD$r;T$wr;D$ vN3ҋ^[SD$ uL$D$ 3D$3Pȋ\$T$ D$ ud$d$r;T$ wr;D$v+D$T$+D$T$ ؃[SUVt$WF n @3ۨt^N$F F ^$  F u&PAtpAu Uu V F tlF>N+PI;N~WPUV؊D$ StՋ `A0A@ t jSU& VD$L$WQU ;tF F _^][ËD$%_^][ _F ^][ÐSUVt$t$WwvA3҃wB;5'Aw(P-Ѓt3̓u- DAVjQӋЅuX.AtV u_^][_^][ÐAVW3;~QSpAt7X tPtG| pARpAAF;|[_^ÐL$SUV3WD$ t$t t$ D$ D$ D$ŀu@u =`.AtT$+tHtHD$D$@D$D$003ۊ@$@3 %=t ;t<U=t =t@f9=t$=K=t=2t5+AD$4#Ƅu@tD$ D$t t tu+A+A _^][ËT$D$(jWL$ UQSRPxAuAPB _^][WAu!WAAP_^][ÃuD$ @ u D$ D$WV\$΀\$D$`A`AȃHDL$(D$,jjV) u=+At|V _^][ÍD$0jPVD$< u*|$0u#UV)uV۾_^][jjV uV赾_^][ÊD$(uD$,t DL _^][É5+A_^]+A[@#@*@1@џ@Vt$ W|$uD$ f3_^Ë 8.AuL$ ff_^Ë (A%DAtO*A~*;|(L$ 3҅RQPH.AVj PA*AuX;r:NuM+A*_^ËD$ 3ɋH.AQPjVj RAu+A*_^ø_^3_^ÐVt$WF @Ft`A0A@|$D$WPCu+A*f _^ÃFuFHFxT$ D$ %AD$ VPt f_^f _^ËFFxD$f_^ËT$VR_^ÐL.AS3VWuBh@dAtj=hAh@VׅL.AtSh@Vht@VP.AףT.AP.AtЋ؅tT.AtSЋ؋D$L$T$PQRSL.A_^[_^3[ÐD$ `ASV;Wȋ`A`AD2tkPu+A _^[ËL$T$QjRPlAuA3tP_^[ËL0D0_^[_^+A +A[Ð\.AtL$QЃt3j詹Ð+Ah@+AL$AA tQ A AA AA AЉAAÐ`AS$ U3V;W>Ë`AD"jUSg |$jUSL $+3|$hS}PD$PS t+~Ճ=+Au +A WSH|$jWS _^][}?jQS StP`AMu+A A+AjWS^ _^][+A _^][Ð`A S\$UV;WÃ `A4`At$ D$PL$(|$$3DžHtT$R tGID T$jRQP Q\AuHAu+A+A _^][ Ãmu 3_^][ P_^][ ËT$LD t ? u $D$$;ʼnl$<< t FGM;s u   FGD$3L$UQT$0jR RG\AuAuXD$tPL$DHtD$(< u: FD /;t$$u |$( u T$ jjRVD$4 < t Fl$;1+t$$_^][ ËD$D @\ u +t$$_^][ 3_^][ _^]+A +A[ ÐSUVt$WF n@3ۨt^N$F F ^$\$  F u&PAtpAu Uu VLF tvF>N+P;N~WPUV\$ D$f_tՋ `A0A@ t jSU V\$D$f\$D$WPUf\$ P ;tF F _^][Ë%_^][ _F ^][ÐD$ `A;Vs`ȃ`ALTtDt$ %u @uɀ %^+A^+A ^ÐQ=L$r-=s+ȋą@P%A]@]@EEE50P (8PX700WP `h````ppxxxx(null)(null)runtime error TLOSS error SING error DOMAIN error R6028 - unable to initialize heap R6027 - not enough space for lowio initialization R6026 - not enough space for stdio initialization R6025 - pure virtual function call R6024 - not enough space for _onexit/atexit table R6019 - unable to open console device R6018 - unexpected heap error R6017 - unexpected multithread lock error R6016 - not enough space for thread data abnormal program termination R6009 - not enough space for environment R6008 - not enough space for arguments R6002 - floating point not loaded Microsoft Visual C++ Runtime Library Runtime Error! Program: ...GetLastActivePopupGetActiveWindowMessageBoxAuser32.dlll@@m@-w-nAll. NetBIOS only Web only Invalid arguments supplied. NetBIOS and Web only Invalid arguments supplied. Invalid hostname supplied. NTInfoScan ver 4.2.2 USAGE c:\>ntis [OPTIONS] remote-machine OPTIONS -w Do Web Service checks only. -n Do NetBIOS checks only Examples: c:\>ntis remotemachine This will perform all checks on remotemachine c:\>ntis -n remotemachine This will perform NetBIOS checks on remotemachine c:\>ntis -w remotemachine This will perform Web Service checks on remotemachine c:\>ntis -n -w remotemachine This will perform both NetBIOS and Web Service checks on remotemachine (C) David Litchfield 25th February 1999 Please report any problems to mnemonix@globalnet.co.uk .htmlw+Creation of results file - "%s" failed. Ensure you have write permission to this directory. Results are written to %s. NTInfoScan results for %s

NTInfoScan

Results

for

%s

by David Litchfield

Winscok Error! No winsock.dll No winsock.dll - 2nd Invalid Host Invalid Socket! Checking the Echo Service... AA

Echo Service

The Echo service on this machine contains a Denial of Service attack where
an attacker can spoof the IP address of another machine offering the Echo
service in a UDP packet, setting the source port to the echo port (7) which
will cause the two machines to continually send and echo messages to each other
consuming network bandwidth and CPU time. More information and a patch for this
can be found at the following KnowledgeBase article Q154460

Until a patch is installed Simple TCP/IP services should be disabled

Invalid Socket! Checking the Chargen Service... AA

Chargen Service

The Chargen (character generator) service on this machine contains a Denial
of Service attack where an attacker can spoof the IP address of another machine
offering the Chargen service in a UDP packet, setting the source port to the chargen
port (19) which will cause the two machines to continually send chargen output to each
other consuming network bandwidth and CPU time. More information and a patch for this
can be found at the following KnowledgeBase article Q154460

Until a patch is installed Simple TCP/IP services should be disabled

Chargen Service

The Chargen (character generator) service on this machine contains a Denial
of Service attack where an attacker can spoof the IP address of another machine
offering the Chargen service in a UDP packet, setting the source port to the chargen
port (19) which will cause the two machines to continually send chargen output to each
other consuming network bandwidth and CPU time. More information and a patch for this
can be found at the following KnowledgeBase article Q154460

Until a patch is installed Simple TCP/IP services should be disabled

500MicrosoftInvalid Socket! No ftp service Checking ftp service...

FTP Service

%s user anonymous pass NTInfoScan@security.check

Security Issues

Anonymous logins are allowed to the ftp service.
port 199,199,199,199,0,80
Service allows ftp bounce attack.
port 199,199,199,199,10,10
Service allows ftp bounce attack to ports greater than 1024.
cwd /c
Hidden /c directory found. This gives an anonymous user access to the c: drive.
stor ntis-ftp.txt
Anonymous uploads allowed to /c directory
quit
stor ntisftp.txt
Anonymous uploads allowed to root directory.
quit
Anonymous logins not allowed...
quit


Invalid Socket!

Telnet service

Allowing users to log on to the machine via the Telnet service should be done
only with great caution as any commands issued whilst logged on will execute locally
relative to the server, possibly executing with system privileges leaving the system
unstable or unusable. Added to this the Telnet service gives an attacker a platform from
which to launch against other machines on the network - the source of these attacks will
be more difficult to track down.

Checking web service... Checking web service... No Web Service... Server:Invalid Socket! HEAD / HTTP/1.0

Web Service

Web Server Software is Internet Information Server %c.0 Web Server Software is %c. Invalid Socket! Failed to connect!

Security Issues

GET /*.idc HTTP/1.0

http://%s/*.idc

The physical location of the root directory found at / . Service Pack 4 has been installed %c By requesting a non-existant IDC file it is possible to learn the physical location of the web service's root directory. If Internet Database Connectivity is not needed remove the script mapping for .idc files. Alternatively installing Service Pack 4 will resolve the problem. For more information read the Microsoft report :Q193689 Invalid Socket! Failed to connect!

Server exhibits the ::$DATA bug.

This can allow an attacker to download the source of scripts, such as Active Sever pages or Perl scripts. This problem is fixed with service pack 4 or a post SP3 hotfix can be downloaded the Microsoft web site. Invalid Socket! Failed to connect! GET /cgi-bin/ HTTP/1.0

http://%s/cgi-bin/

Directory listing is allowed of the /cgi-bin/. This allows an attacker to browse through scripts and executables in this directory allowing them to target and exploit potential weaknesses. Directory browsing should be disabled. scriptInvalid Socket! Failed to connect! GET /scripts/*%0a.pl HTTP/1.0

http://%s/scripts/*%0a.pl

Perl.exe is being used as the perl script interpreter - consequently virtual paths can be mapped to physical paths: The /scripts directory maps to %c. Use PerlIS.dll instead of perl.exe to resolve this problem.

Invalid Socket! Failed to connect! GET /scripts/ HTTP/1.0

http://%s/scripts/

Directory listing is allowed of the /scripts/ directory. This allows an attacker to browse through scripts and executables allowing them to target and exploit potential weaknesses. Directory browsing should be disabled. Invalid Socket! Failed to connect! GET /_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15 HTTP/1.0

http://%s/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15

Fpcount.exe has been found in the /_vti_bin/ directory. If, when the link above is followed , fifteen digits are displayed this version of fpcount.exe is from the FrontPage Server Extentions 97 package and it contains a buffer overrun that allows remote execution of arbitary code.

This should be deleted until a copy of the 98 version of FrontPage can be obtained. Invalid Socket! Failed to connect! GET /iisadmpwd/aexp3.htr HTTP/1.0

http://%s/iisadmpwd/aexp2.htr

From here an attacker can launch password attacks against the local machine or or proxied attacks against other machines on the network. More information can be found here Invalid Socket! Failed to connect! GET /iissamples/exair/search/advsearch.asp HTTP/1.0

http://%s/iissamples/exair/search/advsearch.asp

The sample ExAir site contains a number of scripts that can cause a temporary situation where the inetinfo.exe process consumes 100 percent of the processor time for 90 secs. This only happens if the Index Server ISAPI dlls have not been loaded into memory. If they are not and this page or query.asp or search.asp Are accessed directly the script will loop.

The solution to this problem is to remove these files. GET /iissamples/exair/search/advsearch.asp::$DATA HTTP/1.0 Invalid Socket! Failed to connect! GET /scripts/tools/newdsn.exe HTTP/1.0

http://%s/scripts/tools/newdsn.exe

Newdsn.exe can be used by an a attacker to create files anywhere on your disk if they have the NTFS correct file permissions to do so. Newdsn.exe can also be used to overwrite the DSNs on existing on-line databases making the information contained in the database inaccessible.

This file, getdrvrs.exe, dsnform.exe and mkilog.exe should be deleted or renamed unless there is a strong reason not to do so. In that case, ensure that only Administrators may access them. Invalid Socket! Failed to connect! GET /scripts/repost.asp HTTP/1.0

http://%s/scripts/repost.asp

Microsoft's Site Server 2.0 is installed. This allows users to upload files to the /users directory. Even if it doesn't exist any valid user can create the diectory via the web and the default NTFS permissions given to this directory give the Everybody Group the "Change" permission - which allows anybody to create, modify or delete files in that directory. Added to this IIS gives the "Write" permission allowing users to use the HTTP PUT REQUEST_METHOD to place content on the web site via the HTTP protocol. Because of the defaults, if anonymous access is granted to the site anybody can do this. Ensure that, if the directory exists the Anonymous Internet Account is given only read access to this directory. Remove change permissions for the Everybody Group and assign permissions per user. GET /iissamples/issamples/query.asp::$DATA HTTP/1.0 Invalid Socket! Failed to connect! GET /iissamples/issamples/query.asp HTTP/1.0

http://%s/iissamples/issamples/query.asp

The query.asp page is the default sample search page for Index Server on IIS4. From here an attacker can perform searches for files of a certain type using "#filename=*.exe" or "#filename=*.asp". Ensure that Index Server has been configured not to return reults for searches such as these. GET /iissamples/issamples/query.asp::$DATA HTTP/1.0 Invalid Socket! Failed to connect! GET /samples/search/queryhit.htm HTTP/1.0

http://%s/samples/search/queryhit.htm

The queryhit.htm page is the default sample search page for Index Server 1.1. From here an attacker can perform searches for files of a certain type using "#filename=*.exe" or "#filename=*.asp". Ensure that Index Server has been configured not to return reults for searches such as these. GET /samples/search/queryhit.htm::$DATA HTTP/1.0 Allow:PUTInvalid Socket! Failed to connect! OPTIONS / HTTP/1.0

PUT Request Method allowed to root directory /

NTInfoScan will attempt to create a file called ntisroot.txt to determine if permissions are not set correctly/ntisroot.txtAllow:PUTInvalid Socket! Failed to connect! OPTIONS /users/ HTTP/1.0

PUT Request Method allowed to /Users directory

NTInfoScan will attempt to create a file called ntisusers.txt to determine if permissions are not set correctly/users/ntisusers.txtAllow:PUTInvalid Socket! Failed to connect! OPTIONS /cgi-bin/ HTTP/1.0

PUT Request Method allowed to the /cgi-bin directory

NTInfoScan will attempt to create a file called ntiscgi.txt to determine if permissions are not set correctly/cgi-bin/ntiscgi.txtAllow:PUTInvalid Socket! Failed to connect! OPTIONS /scripts/ HTTP/1.0

PUT Request Method allowed to the /scripts directory

NTInfoScan will attempt to create a file called ntisscripts.txt to determine if permissions are not set correctly/scripts/ntisscripts.txtPUT HTTP/1.1 Host: Content-length: 6 Invalid Socket! Failed to connect! Hello!

%s created! Use NTFS permissions to block write access to the Anonymous Internet Account user - or remove write permissions from this directory from the IIS MMC.

%s already exists! Use NTFS permissions to block write access to the Anonymous Internet Account user - or remove write permissions from this directory from the IIS MMC.

Failed to create %s. Invalid Socket! Failed to connect! GET /scripts/perl.exe?-v HTTP/1.0

http://%s/scripts/perl.exe?-v

Perl.exe found in the /scripts directory. This is highly dangerous as it allows an attacker to run system commands. This should be removed as soon as possible. Invalid Socket! Failed to connect! GET /cgi-bin/perl.exe?-v HTTP/1.0

http://%s/cgi-bin/perl.exe?-v

Perl.exe found in the /cgi-bin. This is highly dangerous as it allows an attacker to run system commands. This should be removed as soon as possible. Connecting to %s...Connected. Connect failed. Connected. Cancel failed... AdministratorRetrieving account list... <H4>Account Name :<B>%s</B></H4> The %s account is a GUEST, and the password was changed The %s account is a normal USER, and the password was changed The %s account is an ADMINISTRATOR, and the password was changed The password on the % s account was last changed %d days ago. This account has been used %d times to logon. The default Administrator account has not been renamed. Consider renaming this account and removing most of its rights. Use a differnet account as the admin account. This account is the renamed original default Administrator account. The %s account is DISABLED. Comment :%s User Comment :%s Full name :%s Error cancelling connection... Checking passwords on accounts... <H3>WARNING %s's password is %s</H3> <H3>WARNING %s's password is blank</H3> Retrieving share information... Share Name :%s Share Type :Disk Share Type :Default Disk Share Share Type :Default Pipe Share Share Type :Printer Comment :%s

WARNING - Null session can be established to %ls

Couldn't connect via nbsession. <HR><CENTER><H2>NetBIOS</H2></CENTER><P><H3>Share Information</H3><PRE></PRE><P><H3>Account Information</H3><PRE></PRE>Server:Invalid Socket! Checking TCP port 180 (SLMail Remote Administration)... HEAD / HTTP/1.0

SLMail Remote Administration

Remote Administration of SLMail is enabled. Any user, even guest users with a local account can authenticate to the service and change SLMail's settings that can lead to a server compromise. More information can be found here.
Service listening on TCP port 180. Seems not to be SLMail's Remote Administration Service. . z@|@l@AA  `y!@~ڣ @ڣ AϢ[@~QQ^ _j21~  @@ @ l@@@@@@@`@(@@Ȱ@x@y@z@@@AAAAA        ! 5A CPR S WY l m pr   )    @ @ @ @ @ @(A(A ((((( H . DdXTPlL<*(<x Xf6 *HjP 4stPlL<*(<x Xf6 *HjP 4stWSOCK32.dll WNetCancelConnection2WWNetAddConnection2WMPR.dll1NetApiBufferFreeNetUserEnumNetShareEnumNETAPI32.dll?SleepGetCommandLineALGetVersionnHeapFreeGetLastErrorCloseHandlekExitProcessFTerminateProcessGetCurrentProcessPUnhandledExceptionFilterGetModuleFileNameAFreeEnvironmentStringsAMultiByteToWideCharFreeEnvironmentStringsWGetEnvironmentStringsGetEnvironmentStringsWnWideCharToMultiByteGetCPInfoGetACP GetOEMCPSetHandleCount*GetStdHandleGetFileType(GetStartupInfoAlHeapDestroyjHeapCreate^VirtualFreeRtlUnwind{WriteFile[VirtualAllochHeapAlloc)SetStdHandleFlushFileBuffers1CreateFileAGetProcAddressLoadLibraryASetFilePointerSetEndOfFileReadFileKERNEL32.dll