I. 背景
---------------------
"IIS is a web server application and set of
feature extension modules created by Microsoft for use with Microsoft Windows.
IIS is the third most popular server in the world." (Wikipedia)
II. 概述
---------------------
Vulnerability Research Team discovered a vulnerability
in Microsoft IIS.
The vulnerability is caused by a tilde character "~" in a Get request, which could allow remote attackers
to diclose File and Folder names.
III. 影响产品
---------------------------
IIS 1.0, Windows NT 3.51
IIS 2.0, Windows NT 4.0
IIS 3.0, Windows NT 4.0 Service Pack 2
IIS 4.0, Windows NT 4.0 Option Pack
IIS 5.0, Windows 2000
IIS 5.1, Windows XP Professional and Windows XP Media Center Edition
IIS 6.0, Windows Server 2003 and Windows XP Professional x64 Edition
IIS 7.0, Windows Server 2008 and Windows Vista
IIS 7.5, Windows 7 (error remotely enabled or no web.config)
IIS 7.5, Windows 2008 (classic pipeline mode)
Note: Does not work when IIS uses .Net Framework 4.
IV. Binary Analysis & Exploits/PoCs
---------------------------------------
Tilde character "~" can be used to find short names of files and folders when the website is running on IIS.
The attacker can find important file and folders that they are not normaly visible.
In-depth technical *** ysis of the vulnerability and a functional exploit
are available through:
http://soroush.secproject.com/blog/2012/06/microsoft-iis-tilde-character-vulnerabilityfeature-short-filefolder-name-disclosure/
V. 解决方案
----------------
There are still workarounds through Vendor and security vendors.
Using a configured WAF may be usefull (discarding web requests including the tilde "~" character).
我的方法可以比普通免费多出4个500人的QQ群!因为我平时需要的QQ群比较多,所以天天琢磨,就发现了这个方法!免费的哟! 查看创建条件 1、先看一下我的QQ,由于之前我已经创建了两个500人的QQ...
本文导读目录: 1、黑客是什么意思?干什么的? 2、‘黑客’一词是什么意思??? 3、黑客是什么意思? 4、黑客是什么意思? 5、黑客是什么意思 6、黑客是什么意思,用来干嘛的...
转正工作总结怎么写(员工试用期转正工作总结范本) 范文一:IT员工试用期转正工作总结 从XX月到现在, 我已经在公司工作近X个月了。这段时间我收获了很多, 对于我从学生到一个职业人的转变具有重...
锤子是什么意思(“锤子”文化,你理解多少) “锤子”在四川人的眼里就是指身体上的某个器官,具体是什么这里就不描述了,只要是四川人都懂的。现在在外地打工的四川人很多,在外地人眼里看到的四川人说话时出现...
龙腾和网络黑客有什么不同 网络黑客能够通过自学吗(网络黑客通过自学) 网络黑客最很有可能进攻的是啥 qq解封4元钱一单(qq飞车解封器免费下载) 我国怎祥解决网络黑客 黑客技...
中新网1月9日电 据欧联网援引欧联通讯社报道,意大利民防部8日通报,意全国累计新冠确诊病例增至2237890例,死亡77911例。意大利国家众议院议员、政府国会关系部部长德因卡(Federico...