RE: IIS5.0 Directory Browsing

From: McCammon, Keith (Keith.McCammon@eadvancemed.com)
Date: 11/29/01


Subject: RE: IIS5.0 Directory Browsing
Date: Thu, 29 Nov 2001 10:46:18 -0500
Message-ID: <BB7FD4FF9E440648A731452E5D341FB0C6619D@hitsexchange01.advance-med.com>
From: "McCammon, Keith" <Keith.McCammon@eadvancemed.com>
To: "Enrico Tausz" <etausz@ig.com.br>, <focus-ms@securityfocus.com>

Use a different search tool. You do not need to enable directory
browsing to search a web site. DB is not necessarily a huge security
hole, assuming that your server is thoroughly secured. However, it
should be considered an "unnecessary risk."

And putting a default document in each directory is useless. I can just
type in http://yourserver.com/blabla.htm and get a full listing
(assuming that you don't have a page called blabla.htm). If you do have
that page, I'll just try something else until I get the goods.

Cheers

Keith

-----Original Message-----
From: Enrico Tausz [mailto:etausz@ig.com.br]
Sent: Thursday, November 29, 2001 1:06 AM
To: focus-ms@securityfocus.com
Subject: IIS5.0 Directory Browsing

Hello everyone,

I´m evaluating a search tool named 'webinator' and to

make the searh work, I have to permit 'directory

brosing' in my IIS. To prevent expose my diretories, I

put a default document in every subdirectory.

Can somebody tell me if my server is VUL using this

solution ?

Thanks in Advance.

Enrico

etausz@ig.com.br



Relevant Pages

  • RE: IIS5.0 Directory Browsing
    ... Subject: IIS5.0 Directory Browsing ... the fact that I mis-spoke does not change the fact that placing ... a default page in every directory is a horrible security practice, ... Use a different search tool. ...
    (Focus-Microsoft)
  • RE: IIS5.0 Directory Browsing
    ... Subject: IIS5.0 Directory Browsing ... Is there a way for a client to instruct the server ... Use a different search tool. ... assuming that your server is thoroughly secured. ...
    (Focus-Microsoft)
  • IIS 6 Directory browsing not working like it should...?
    ... I have created a virtual directory web site with directory browsing enabled so that users going to the site can click on a text file and either open it in a web browser or save it to disk. ... Problem though is that the file is not presented like it is in the first web site, when users go to this second site the file is opened automatically by the browser...the users do not see it sitting there nicely ready to be clicked on. ...
    (microsoft.public.inetserver.iis)
  • how to enable directory browsing for asp.net web site?
    ... I want to enable directory browsing for an internal web site so that ... I created a web site on IIS manager and click Directory browsing from ... home directory tab and untick "enable default content page" from ...
    (microsoft.public.dotnet.framework.aspnet)