

I. 背景
"IIS is a web server application and set of
feature extension modules created by Microsoft for use with Microsoft Windows.
IIS is the third most popular server in the world." (Wikipedia)
II. 概述
Vulnerability Research Team discovered a vulnerability
in Microsoft IIS.
The vulnerability is caused by a tilde character "~" in a Get request, which could allow remote attackers
to diclose File and Folder names.
III. 影响产品
IIS 1.0, Windows NT 3.51
IIS 2.0, Windows NT 4.0
IIS 3.0, Windows NT 4.0 Service Pack 2
IIS 4.0, Windows NT 4.0 Option Pack
IIS 5.0, Windows 2000
IIS 5.1, Windows XP Professional and Windows XP Media Center Edition
IIS 6.0, Windows Server 2003 and Windows XP Professional x64 Edition
IIS 7.0, Windows Server 2008 and Windows Vista
IIS 7.5, Windows 7 (error remotely enabled or no web.config)
IIS 7.5, Windows 2008 (classic pipeline mode)
Note: Does not work when IIS uses .Net Framework 4.
IV. Binary Analysis & Exploits/PoCs
Tilde character "~" can be used to find short names of files and folders when the website is running on IIS.
The attacker can find important file and folders that they are not normaly visible.
In-depth technical *** ysis of the vulnerability and a functional exploit
are available through:
V. 解决方案
There are still workarounds through Vendor and security vendors.
Using a configured WAF may be usefull (discarding web requests including the tilde "~" character).



从字面上理解的话就是在任用一个人之前没有好好地了解过这个人.察在现在是观察、察看的意思.可以有两个方面的理解,要看具体的语境.一是用人不疑, 所谓“知人”,就是要求组织部门摸清干部的“底子”,全面深...

2020年国庆节中秋节放假安排时间表 2020国庆中秋几号到几号放假

关于2020年国庆节中秋节放假安排的通知 根据国务院办公厅通知精神,现将2020年国庆节、中秋节放假安排通知如下: 10月1日(星期四)至8日(星期四)放假调休,共8天。9月27日(星期日)、10...



数据库怎么创建表(用SQL语句创建数据库和表)--------创建数据库 ----use master ----GO ----IF EXISTS (SELECT name FROM master...


  新华社昆明11月13日电(记者曾维)据云南省公安厅新闻办公室通报,13日,随着中方3艘执法艇顺利返回中国关累港,第99次中老缅泰湄公河联合巡逻执法圆满结束。   此次行动,四方采取全线联合巡逻、...


孩子家的时候吃饭习惯就不好,被送到幼儿园后不乖乖吃饭怎么办呢,孩子在学校吃饭特别慢怎么办好呢,友谊长存小编就来说说吧。 吃饭最末名宝宝该如何激励? 与环境的转变有关 宝宝在3-4岁上幼儿园早班,...



本文目录一览: 1、黑客帝国4 啥时候上映? 2、2021好莱坞大片排行榜前十名 3、黑客帝国4上映时间 4、22年后,《黑客帝国4》重归,母体和救世主谁才是最后的赢家? 黑客帝国4 啥...