Re: are my binaries being exposed on my ASP.NET website?

From: Thor (thor_at_hammerofgod.com)
Date: 11/26/03

  • Next message: Mark Ribbans: "RE: local admin account password"
    To: "Ed Devlin" <Ed.devlin@detica.com>, <focus-ms@securityfocus.com>
    Date: Wed, 26 Nov 2003 07:25:58 -0800
    
    

    RE: are my binaries being exposed on my ASP.NET website?Sorry, I missed
    that-- when I read "remove the extension" my brain said "rename file." The
    consultant is reporting that all he does is remove the extension from the
    URL and he gets the binary files? Yet you can't reporduce it? Similar to the
    old :DATA bug?

    I think it is time you use the two words consultants just love to here:
    "Show me."

    t

    ----- Original Message -----
    From: Ed Devlin
    To: 'Thor' ; focus-ms@securityfocus.com
    Sent: Wednesday, November 26, 2003 3:35 AM
    Subject: RE: are my binaries being exposed on my ASP.NET website?

    Thanks for your response. I agree that WebDAV is a bit naughty, from a
    security point of view, and file renaming could be used to fool the ISAPI
    extensions.
    But the technique that our consultant is using does not require any renaming
    of files using WebDAV. The attack is simply to issue a request for a page
    without its .aspx extension, when logged into the public-facing website.
    As I said, I can't reproduce it. I just wondered if anyone else had
    seen/heard of something like this....
    Ed

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Mark Ribbans: "RE: local admin account password"

    Relevant Pages

    • Python Extension Building Network
      ... I am trying to get a small group of volunteers together to create ... Windows binaries for any Python extension developer that needs them, ... The main thing I need are people willing to test the binaries to make ...
      (comp.lang.python)
    • Code editor configuration for .vs files
      ... I need to configure Visual Studio 2003 so that it treat files with extension ... Software Developer & Consultant ... Prev by Date: ...
      (microsoft.public.vstudio.general)
    • Code editor configuration for .vs files
      ... I need to configure Visual Studio 2003 so that it treat files with extension ... Software Developer & Consultant ... Prev by Date: ...
      (microsoft.public.vsnet.general)