[TOOL] IISBanner, IIS Banner Changer

From: SecuriTeam (support_at_securiteam.com)
Date: 06/19/03

  • Next message: SecuriTeam: "[TOOL] ScanADS, Scans Alternate Data Streams"
    To: list@securiteam.com
    Date: 19 Jun 2003 14:35:03 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    Latest attack techniques.

    You're a pen tester, but is google.com still your R&D team?
    Now you can get trustworthy commercial-grade exploits and the latest
    techniques from a world-class research group.

    Learn more at http://www.coresecurity.com/promos/sit_e1,
    or call 617-399-6980

    - - - - - - - - -

      IISBanner, IIS Banner Changer
    ------------------------------------------------------------------------

    DETAILS

    ISAPI Filters are the only "safe" way of managing (changing, altering,
    customizing) some of the core parts of IIS. Customizing the response
    header "Server" is one of those tasks. IISBanner provides a simple yet
    powerful, although demonstrative, way of achieving such objective.
    IISBanner may be useful at a security perspective by disguising the web
    server banner (security by obscurity), but keep in mind that there are
    much more powerful ways of detecting a server type using tools like NMap.

    Features:
     * Changes IIS "Server" response header value to "Powered By IISBanner/1.0
    (KodeIT)"

    Notes:
     * Installation of this ISAPI Filter must be done at the WebServer level;
     * Although the Response Value could be set in a file (ex: ini), the
    author decided to "hard code" it to make it simple to understand the
    source code;
     * IISBanner is installed at http://www.kodeit.com and may be viewed by a
    network sniffer at each HTTP response received, or through this simple VBS
    script:

    Set oHTTP = WScript.CreateObject("Microsoft.XMLHTTP")
    Call oHTTP.Open("HEAD", "http://www.kodeit.com", False)
    Call oHTTP.Send()
    WScript.Echo oHTTP.GetAllResponseHeaders()
    Set oHTTP = Nothing

    ADDITIONAL INFORMATION

    The tool can be downloaded from:
     <http://www.kodeit.org/utils/iisbanner.zip>
    http://www.kodeit.org/utils/iisbanner.zip (binary),
    <http://www.kodeit.org/utils/iisbanner_src.zip>
    http://www.kodeit.org/utils/iisbanner_src.zip (source).

    The information has been provided by <mailto:thalm@netcabo.pt> Tiago
    Halm.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[TOOL] ScanADS, Scans Alternate Data Streams"

    Relevant Pages

    • RE: "Free" pen-test
      ... J.A. Terranson wrote: ... > acceptable practice. ... are you really saying that security ... >> Latest attack techniques. ...
      (Pen-Test)
    • RE: "Free" pen-test
      ... operations that has put the security industry in the position it is in now - ... > worried" that his web server could have been taken down in about 4 hours ... > Latest attack techniques. ... > You're a pen tester, but is google.com still your R&D team? ...
      (Pen-Test)
    • RE: "Free" pen-test
      ... I was tipped that a local firm had security issues. ... Latest attack techniques. ...
      (Pen-Test)
    • [NEWS] SpiDynamics WebInspect Keeps Track of Its Users (Trial License)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... WebInspect, S.P.I. Dynamic's premier product, is a network-based web ... We make no effort to hide that this remote authentication is done. ...
      (Securiteam)
    • [NT] DoS and Directory Traversal Vulnerabilities in WebServer 4 Everyone
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... requests and to allow attackers to download files that reside the outside ...
      (Securiteam)