手机
当前位置:查字典教程网 >网络安全 >安全设置 >IIS Short File/Folder Name Disclosure(iis短文件或文件夹名泄露)
IIS Short File/Folder Name Disclosure(iis短文件或文件夹名泄露)
摘要:I.背景---------------------"IISisawebserverapplicationandsetoffeatureext...

I. 背景

---------------------

"IIS is a web server application and set of

feature extension modules created by Microsoft for use with Microsoft Windows.

IIS is the third most popular server in the world." (Wikipedia)

II. 概述

---------------------

Vulnerability Research Team discovered a vulnerability

in Microsoft IIS.

The vulnerability is caused by a tilde character "~" in a Get request, which could allow remote attackers

to diclose File and Folder names.

III. 影响产品

---------------------------

IIS 1.0, Windows NT 3.51

IIS 2.0, Windows NT 4.0

IIS 3.0, Windows NT 4.0 Service Pack 2

IIS 4.0, Windows NT 4.0 Option Pack

IIS 5.0, Windows 2000

IIS 5.1, Windows XP Professional and Windows XP Media Center Edition

IIS 6.0, Windows Server 2003 and Windows XP Professional x64 Edition

IIS 7.0, Windows Server 2008 and Windows Vista

IIS 7.5, Windows 7 (error remotely enabled or no web.config)

IIS 7.5, Windows 2008 (classic pipeline mode)

Note: Does not work when IIS uses .Net Framework 4.

IV. Binary Analysis & Exploits/PoCs

---------------------------------------

Tilde character "~" can be used to find short names of files and folders when the website is running on IIS.

The attacker can find important file and folders that they are not normaly visible.

In-depth technical analysis of the vulnerability and a functional exploit

are available through:

http://soroush.secproject.com/blog/2012/06/microsoft-iis-tilde-character-vulnerabilityfeature-short-filefolder-name-disclosure/

V. 解决方案

----------------

There are still workarounds through Vendor and security vendors.

Using a configured WAF may be usefull (discarding web requests including the tilde "~" character).

VII. 参考

----------------------

http://support.microsoft.com/kb/142982/en-us

http://soroush.secproject.com/blog/2010/07/iis5-1-directory-authentication-bypass-by-using-i30index_allocation/

【IIS Short File/Folder Name Disclosure(iis短文件或文件夹名泄露)】相关文章:

远离IE浏览器漏洞 避免遭受黑客攻击的一些小结

加加米点击普通网站可刷积分的介绍及其修复方法(图解)

家庭用路由器功能的详细介绍

在 Windows 下关闭135/139/445端口的图文方法

关于机房服务器系统安全的七个必杀技的介绍

192.168.1.1进入路由器默认的用户名和密码是多少 常用路由默认密码大全

教你使用dos命令扫描开放端口

好的习惯来避免网络的不安全因素

曲折的FileZilla Server提权之路

易通企业网站系统(cmseasy) 权限提升的方法及getShell通杀漏洞的介绍

精品推荐
分类导航