On Thu, Dec 07, 2000 at 02:58:56AM -0800, Mark Kim wrote:
> Yeah, if I can get to any of those programs.
> 
> I got no access to the system.  I can contact it remotely via ports 22 and
> 80, no other way.  (I feel like a broken record... :(

Oh yeah. I forgot about that.

If I were in your shoes, and I did not want to bribe the security admins
with pizza and beer, I might try this:

[another wild guess]
When you do a http request doesn't it tell you the server?
(maybe it's just the client)
Find out what server is running and look for bugs. I think there were
buffer overflow bugs is most web servers, but I think almost all were
discovered and fixed a long time ago.

Here's one from '97 says "If you send a specially formatted URL of about
8K to IIS, you can crash the server" -- saw this at 
http://www.insecure.org/sploits_microshit.html

Reply via email to