最新国产好看的视频,伊人天堂AV在线,国产Aaaaaa视频,蜜臀视频在线观看一区,人妻av色图,密臀久久久精品影片,青青视频免费观看毛片,久草在线观看视,国产三级精品色情在线

IIS Short File/Folder Name Disclosure(iis短文件或文件夾名泄露)

  發(fā)布時間:2012-07-04 14:29:53   作者:佚名   我要評論
IIS Short File/Folder Name Disclosure(iis短文件或文件夾名泄露)
I. 背景
---------------------
"IIS is a web server application and set of
feature extension modules created by Microsoft for use with Microsoft Windows.
IIS is the third most popular server in the world." (Wikipedia)
II. 概述
---------------------
Vulnerability Research Team discovered a  vulnerability
in Microsoft IIS.
The vulnerability is caused by a tilde character "~" in a Get request, which could allow remote attackers
to diclose File and Folder names.
III. 影響產(chǎn)品
---------------------------
    IIS 1.0, Windows NT 3.51
    IIS 2.0, Windows NT 4.0
    IIS 3.0, Windows NT 4.0 Service Pack 2
    IIS 4.0, Windows NT 4.0 Option Pack
    IIS 5.0, Windows 2000
    IIS 5.1, Windows XP Professional and Windows XP Media Center Edition
    IIS 6.0, Windows Server 2003 and Windows XP Professional x64 Edition
    IIS 7.0, Windows Server 2008 and Windows Vista
    IIS 7.5, Windows 7 (error remotely enabled or no web.config)
    IIS 7.5, Windows 2008 (classic pipeline mode)
    Note: Does not work when IIS uses .Net Framework 4.
IV. Binary Analysis & Exploits/PoCs
---------------------------------------
Tilde character "~" can be used to find short names of files and folders when the website is running on IIS.
The attacker can find important file and folders that they are not normaly visible.
In-depth technical analysis of the vulnerability and a functional exploit
are available through:
http://soroush.secproject.com/blog/2012/06/microsoft-iis-tilde-character-vulnerabilityfeature-short-filefolder-name-disclosure/
V. 解決方案
----------------
There are still workarounds through Vendor and security vendors.
Using a configured WAF may be usefull (discarding web requests including the tilde "~" character).
VII. 參考
----------------------
http://support.microsoft.com/kb/142982/en-us
http://soroush.secproject.com/blog/2010/07/iis5-1-directory-authentication-bypass-by-using-i30index_allocation/

相關(guān)文章

最新評論

榆社县| 甘孜县| 洛南县| 沾益县| 高青县| 两当县| 临颍县| 区。| 浮梁县| 马边| 沈丘县| 平罗县| 昭觉县| 山阴县| 宿松县| 凤凰县| 赫章县| 金昌市| 新野县| 忻州市| 临潭县| 咸丰县| 沅陵县| 盐边县| 依兰县| 铁岭县| 乌兰察布市| 邵武市| 连云港市| 玉山县| 滕州市| 叶城县| 广南县| 麻栗坡县| 绥中县| 蕲春县| 遂昌县| 石家庄市| 丰台区| 鲁甸县| 廉江市|