RE: IIS5.0 Directory Browsing

From: CHRIS GRABENSTEIN (LFGRABC@lf.vccs.edu)
Date: 11/29/01


Message-Id: <sc0635ad.070@lf.vccs.edu>
Date: Thu, 29 Nov 2001 13:16:17 -0500
From: "CHRIS GRABENSTEIN" <LFGRABC@lf.vccs.edu>
To: <focus-ms@securityfocus.com>
Subject: RE: IIS5.0 Directory Browsing

Wouldn't entering http://yourserver.com/blabla.htm return the 404 error
page on most setups? Is there a way for a client to instruct the server
to ignore the default page?

-----Original Message-----
From: "McCammon, Keith" <Keith.McCammon@eadvancemed.com>
Sent: Thursday, November 29, 2001 10:46 AM
To: "Enrico Tausz" <etausz@ig.com.br>, <focus-ms@securityfocus.com>
Subject: RE: IIS5.0 Directory Browsing

Use a different search tool. You do not need to enable directory
browsing to search a web site. DB is not necessarily a huge security
hole, assuming that your server is thoroughly secured. However, it
should be considered an "unnecessary risk."
And putting a default document in each directory is useless. I can
just
type in http://yourserver.com/blabla.htm and get a full listing
(assuming that you don't have a page called blabla.htm). If you do
have
that page, I'll just try something else until I get the goods.
Cheers
Keith



Relevant Pages

  • Re: NEED help with DNS / IIS Please
    ... include a folder name or any file name, that is why you want the Home ... You can also turn Directory Browsing on or off ... > our website instead of hitting the one on our old server. ...
    (microsoft.public.windows.server.networking)
  • Re: Browse web server
    ... party control from directory browsing could be used or you could just use a ... > yes i understand applications security but this is not what i want, ... > not find suitable control for that task, ... you'd need to enable directory browsing at the server level for ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: IIS 6 Directory browsing not working like it should...?
    ... directory web site with directory browsing enabled so that users going to ... On the very same web server, I have created another virtual directory web ... on this second web site just like on the first so I can't understand why ... it's not behaving like the first web site. ...
    (microsoft.public.inetserver.iis)
  • RE: 402 Forbidden Error
    ... Directory browsing was already checked. ... Expand Protocols, expand HTTP, and then expand Exchange Virtual Server. ... Shijaz Abdulla ... "Perry" wrote: ...
    (microsoft.public.isa)
  • Re: ##### HELP: Getting List of file on a Web Server ######
    ... if it is your server look into allowing it with your configuration ... allso search google for .htaccess it is a file that can be put ... articles about enable and disabeling directory browsing that you can ... additionally these articles are tailored ...
    (comp.lang.java.help)