Penetration Testing mailing list archives

Sam File via IIS flaw


From: nordicsmak () yahoo com
Date: 28 Jun 2005 19:02:54 -0000

During a recent penetration test I've discovered a flaw in the IIS server that allows me to browse to and view any file 
on the system.

I'm able to browse to the /winnt/repair/sam file, but it obviously is unusable in the format that's presented in the 
browser.

Any way to get this file in a format that can be used in L0pht?

Thanks,
Chris


Current thread: