13.03.2001 -- m0sad security team -----------------------------[ ]---


                              ==============================
                              =                            =
                              =  :: IIS Storm 2 Manual ::  =
                              =                            =
                              ==============================


Intro
-----

1. IIS storm is a tool made for Remote WebSite Defacement that is 
running IIS ( Internet Information Server ( NT platform ) ) and 
that also vunerabile to the Unicode Exploit.

Here in this little manual i'll try to explain how to use this
tool, i'll try to make the things easy to understand to people
that not familar with computer security. And excuse me for my
bad english i usually don't go to this lessons at school. :)



Uploading Files
---------------

2. Now lets learn how to use IIS Storm.
First lets see what each object means :

"URL" means that you write there the address of the WebServer that you want
to Deface. Example: http://www.microsoft.com/

Now press the "Query Server" button and then the program will do some
magics and show you the name of the server that is running on that machine.
look at the status screen. If you see Microsoft-IIS 4.0 or IIS 5.0 this is 
good , then it will tell you can the server be exploited or not.
* if it shows some other WebServer name like: Apache , Zeus , etc ...
  you can't do anything, i would go and by some candies at your place.

Go to "Upload Files" Tab, the first object is "Remote Dir" 
this means where files must be upoaded to ( the Path to it on 
the victims computer ).

Now the "FTP Setting":
An FTP server is needed to deface the site, u need to have an access 
to some ftp server, you will place there the files that u want to 
upload to the victims computer. In our case we need some *.html files
to uplad, because this tool is used for site defacement.
Lets say you have such ftp server, and you uploaded files to it 
at the "Address" you write the address of the FTP, Example: ftp.microsoft.com
"Login" means your login at the FTP server.. and "Password" i think you know
what does it mean.
So now the program knows where to take files from, now we need to tell it, which 
file to download from the FTP, so now you write the name of the file that you
want to be downloaded and push the "Add File" button.
You can add as many files as you want. In case that you want to remove the file
from the list just click on the file and push the "Remove" button.
"Clear" button clears the list of files .

To start uploading files just click on the RED button that says "Upload" 
and see the Status Screen of the Program.

The little "CLS" button at the right top corner of the status screen clears this 
screen from server messages.


Directory Listing
-----------------
3. Here is not many things to explain, you just need to write the path that you
want to check for files at the "Directory" stirig , and it will show you the files
that located on that path. Example : C:\winnt will show you all the files and
directories that located at the Windows NT folder. If you need to list files in long name
dirs you can use dos style like: c:\progra~1\common\ (c:\program files\common\) or
you can put all the path in brakets (" ") like: "c:\program files\common"

Now we go forward and study how to searh for files.
It's easy just after dir path enter + and /S parameter.
For example this command: "c:\CCs\*.mdb+/S" will search for all *.mdb files
in c:\CCs\ directory. Including all sub directories.

* If you will search for c:\*.* - it will give you all files and their path in c:\
* Such search method is slow (dependin on server speed)
* Dont Forget to click "List Files" button . =)


Settings
--------
4. This tab is for more "advanced" users :), dont worry all this sceary strings
are just shit, there is nothing to understand, read and you will see.

lests start from "Advance" tab.
"Unicode to use" its the string that will be sent to the server , this is a special
characters that the server understand like "/" string. some servers use other strings
than "c0" "af" example if the IIS server is using Arabs fonts u need the arab string
for "/" or some other language. but this happends very rarley.
i suggest to use C0 AF.

"Custom Client Settings" tab:
"Agent" Emulates a Web Browser, so server thinks that you connect with a regular
web browser and not just send some unclear data.

"Accept" This enables the ability to get some file formats when they exsist on the 
server webpage.

"Proxy Setup" i strongly suggest to use a proxy server when defacing, and not just a
proxy server, even a good proxy server because IIS has logs, and your IP will be 
written at the logs if you dont use a proxy, so be careful with this realy.
Click on the "Use Proxy Server" Checkbox , then enter the port of the proxy server
and finally the address. 

* Use only anonymous proxy servers.

Here is a list of some anonymous proxy servers, but try to find some of yours:

+-------------------+--------+
|Server             |  Port  |
+-------------------+--------+
|210.120.192.20     |   8080 | 
|209.105.155.54     |   80   |
|195.128.76.69      |   80   |
|proxy.qatar.net.qa |   8080 |
|195.38.236.213     |   80   |
|dmitrow.ru         |   80   |
|209.161.64.32      |   8080 |
|209.161.64.32      |   8080 |
+-------------------+--------+





Last Words
----------
As always, not me and not our team are not responcible for the damage made 
by this program, this program written for Information Purposes only, to help
system administrators test their systems for security problems.
And the important thing is that the author of this program was very drunk
at the time of writing it, and he doesnt know what shit did he compiled.
and what the hell am i writing this crap ? 
who knows ...
maybe someone is reading it ? or not ?




Thats it, thank you for your time. go visit our site for updates and some more
shit and stuff. 

http://www.m0sad.com/



Best Regrads ..    


                                         -= m0sad team =-

written by [Rapt0r]

seen by LovinGood
<LovinGood>hmm, rap, don't mix beer with vodka !!
