Results 1 to 5 of 5

Thread: Pen Test IIS

  1. #1
    Join Date
    Mar 2010
    Beans
    91
    Distro
    Ubuntu 11.04 Natty Narwhal

    Pen Test IIS

    Hi ,

    I need to do a pentest on a Microsoft IIS webserver to test the efficiency of the HIPS i have installed on ...
    any suggestions concerning tools or methods to simulate attacks so that i can check if the HIPS will detect them ?
    also , any suggestions of good HIPS out there ?

    Thanks

  2. #2
    Join Date
    Apr 2008
    Beans
    164
    Distro
    Ubuntu 10.04 Lucid Lynx

    Re: Pen Test IIS

    start here - http://www.backtrack-linux.org/
    I also find this site a good resource
    http://www.darknet.org.uk/

    you may also wanna look at this link to a microsoft product
    |AMD Phenom II X4 955|8Gb ddr3 1333|GTS250 1Gb|
    Teeth cut on Redhat, Moved to Debian, Loving Ubuntu.

  3. #3
    Join Date
    Mar 2010
    Beans
    91
    Distro
    Ubuntu 11.04 Natty Narwhal

    Re: Pen Test IIS

    Quote Originally Posted by BbUiDgZ View Post
    start here - http://www.backtrack-linux.org/
    I also find this site a good resource
    http://www.darknet.org.uk/

    you may also wanna look at this link to a microsoft product

    Hi ,
    thanks for your reply

    i already use backtrack for 2 years now
    and also am familiar with MBSA

    the thing is i need an attack that probably all HIPS would detect ... just to make sure that the one i have installed is running well ...
    also i need a good HIPS for an IIS server (other than snort cause i need one installable on windows)

    any suggestions ?

  4. #4
    Join Date
    Apr 2006
    Location
    Montana
    Beans
    Hidden!
    Distro
    Kubuntu Development Release

    Re: Pen Test IIS

    Snort will run on Windows.

    This kind of activity is gray hat stuff at best and is not really supported on these forums.

    First you are asking about a windows server -> we would ask you to ask for windows support on a windows forums.

    Second you are not asking for support on getting any particular application running, you are asking for cracking tools. Honestly I am not sure what is included in Backtrack, but I would be surprised if it did not have tools.

    If nothing else , port scan your server, a port scan is easy to perform and should, IMO, be detected.

    Otherwise Google search your question
    There are two mistakes one can make along the road to truth...not going all the way, and not starting.
    --Prince Gautama Siddharta

    #ubuntuforums web interface

  5. #5
    Join Date
    Mar 2010
    Beans
    91
    Distro
    Ubuntu 11.04 Natty Narwhal

    Re: Pen Test IIS

    Quote Originally Posted by bodhi.zazen View Post
    Snort will run on Windows.

    This kind of activity is gray hat stuff at best and is not really supported on these forums.

    First you are asking about a windows server -> we would ask you to ask for windows support on a windows forums.

    Second you are not asking for support on getting any particular application running, you are asking for cracking tools. Honestly I am not sure what is included in Backtrack, but I would be surprised if it did not have tools.

    If nothing else , port scan your server, a port scan is easy to perform and should, IMO, be detected.

    Otherwise Google search your question
    actually this is why im asking ... i port scanned the server using ubuntu .
    i got results and hardened some configs and the results im getting now are ok .
    but my made me curious is that the HIPS did not pick up the port scan ! not even as probe !
    this is why i was asking what kind of simulation all HIPS detect ...

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •