链家明信仕林府陈陈 發表於 2012-7-4 14:29:53

IIS Short File/Folder Name Disclosure(iis短文件或文件夹名泄露)

I. 背景<br />---------------------<br />&quot;IIS is a web server application and set of<br />feature extension modules created by Microsoft for use with Microsoft Windows.<br />IIS is the third most popular server in the world.&quot; (Wikipedia)<br />II. 概述<br />---------------------<br />Vulnerability Research Team discovered a&nbsp; vulnerability<br />in Microsoft IIS.<br />The vulnerability is caused by a tilde character &quot;~&quot; in a Get request, which could allow remote attackers<br />to diclose File and Folder names.<br />III. 影响产品<br />---------------------------<br />&nbsp;&nbsp;&nbsp; IIS 1.0, Windows NT 3.51<br />&nbsp;&nbsp;&nbsp; IIS 2.0, Windows NT 4.0<br />&nbsp;&nbsp;&nbsp; IIS 3.0, Windows NT 4.0 Service Pack 2<br />&nbsp;&nbsp;&nbsp; IIS 4.0, Windows NT 4.0 Option Pack<br />&nbsp;&nbsp;&nbsp; IIS 5.0, Windows 2000<br />&nbsp;&nbsp;&nbsp; IIS 5.1, Windows XP Professional and Windows XP Media Center Edition<br />&nbsp;&nbsp;&nbsp; IIS 6.0, Windows Server 2003 and Windows XP Professional x64 Edition<br />&nbsp;&nbsp;&nbsp; IIS 7.0, Windows Server 2008 and Windows Vista<br />&nbsp;&nbsp;&nbsp; IIS 7.5, Windows 7 (error remotely enabled or no web.config)<br />&nbsp;&nbsp;&nbsp; IIS 7.5, Windows 2008 (classic pipeline mode)<br />&nbsp;&nbsp;&nbsp; Note: Does not work when IIS uses .Net Framework 4.<br />IV. Binary Analysis &amp; Exploits/PoCs<br />---------------------------------------<br />Tilde character &quot;~&quot; can be used to find short names of files and folders when the website is running on IIS. <br />The attacker can find important file and folders that they are not normaly visible.<br />In-depth technical analysis of the vulnerability and a functional exploit<br />are available through:<br />http://soroush.secproject.com/blog/2012/06/microsoft-iis-tilde-character-vulnerabilityfeature-short-filefolder-name-disclosure/<br />V. 解决方案<br />----------------<br />There are still workarounds through Vendor and security vendors.<br />Using a configured WAF may be usefull (discarding web requests including the tilde &quot;~&quot; character).<br />VII. 参考<br />----------------------<br />http://support.microsoft.com/kb/142982/en-us<br />http://soroush.secproject.com/blog/2010/07/iis5-1-directory-authentication-bypass-by-using-i30index_allocation/
頁: [1]
查看完整版本: IIS Short File/Folder Name Disclosure(iis短文件或文件夹名泄露)