RE: Creating a secret web site on IIS 5.x using Alternative Data Streams
From: James C Slora Jr (Jim.Slora_at_phra.com)
Date: 08/09/05
- Previous message: iDEFENSE Labs: "iDEFENSE Security Advisory 08.09.05: AWStats ShowInfoURL Remote Command Execution Vulnerability"
- In reply to: inge_eivind.henriksen_at_chello.no: "Creating a secret web site on IIS 5.x using Alternative Data Streams"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: <bugtraq@securityfocus.com> Date: Tue, 9 Aug 2005 11:12:17 -0400
Mitigation at the IIS server looks pretty straightforward.
URLScan in default configuration prevents access to ADS files, generating
the following log line:
Client at 10.1.1.100: URL contains sequence ':', which is disallowed.
Request will be rejected. Site Instance='1', Raw
URL='/myremoteserver/help.gif:secret'
So you should see accesses in the IIS logs if you don't run URLScan, and
failed attempts in the URLScan logs if you do run it.
- Previous message: iDEFENSE Labs: "iDEFENSE Security Advisory 08.09.05: AWStats ShowInfoURL Remote Command Execution Vulnerability"
- In reply to: inge_eivind.henriksen_at_chello.no: "Creating a secret web site on IIS 5.x using Alternative Data Streams"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|