IIS 5.0 problem with "backup" files in executable directories....how to enumerate them?

From: fr0stman (fr0stman@sun-tzu-security.net)
Date: 03/16/03

  • Next message: Gary O'leary-Steele: "IMAP password cracker?"
    From: fr0stman <fr0stman@sun-tzu-security.net>
    To: pen-test@securityfocus.com
    Date: Sun, 16 Mar 2003 13:19:10 -0500
    
    

    Ok I have a scanner utility that is enumerating backup copies of files that
    are present:

    i.e. http://www.blah.com/index.html

    If there's an index.old or index.html.old the script will find these with
    subsequent GET requests for the "backup" files.

    Where I'm running into a problem is with IIS 5.0 (Apache doesn't do this).

    i.e. http://www.blah.com/scripts/login.asp

    When I make a POST request to /scripts/login.old, etc I get a 405 method not
    allowed. The error in the returned header states only methods OPTIONS and
    TRACE are allowed which I'm assuming are the default methods allowed for a
    file extension that hasn't previously been setup in the IIS directory
    configuration. GET requests of course return 403 access denied errors. TRACE
    returns 200 OK for any request and OPTIONS of course returns the allowed HTTP
    methods.

    Has anyone else overcome this error or have a reliable method of determining
    "backup" copies of files are present in executable directories? Thanks in
    advance.

    -- 
    -- fr0stman --
    ----------------------------------------------------------------------------
    Did you know that you have VNC running on your network? 
    Your hacker does. Plug your security holes now! 
    Download a free 15-day trial of VAM:
    http://www2.stillsecure.com/download/sf_vuln_list.html
    

  • Next message: Gary O'leary-Steele: "IMAP password cracker?"

    Relevant Pages

    • Re: failed backup
      ... To me it looks like RMS doesn't get requests from bkprunner or bkpruner ... Entries in work queue indicate that enumeration process is starting OK, ... I unchecked the 'automatically delete requests' to see if more info> will turn up. ... > I have run drive diagnostics until I'm blue and cannot get the drive to> error, also a backup configured with ntbackup runs fine - so I'm of the> opinion presently that this is an issue with SBSbackup, and only on this> server. ...
      (microsoft.public.windows.server.sbs)
    • Re: DFHSM QUESTION - UNABLE TO BACKUP DSN
      ... AUTOBACKUP should have nothing to do with command backup. ... I would issue a QUERY REQUESTS and QUERY ACTIVE to find out what is waiting and what is active. ... DFHSM QUESTION - UNABLE TO BACKUP DSN ...
      (bit.listserv.ibm-main)
    • Re: DFHSM QUESTION - UNABLE TO BACKUP DSN
      ... you are saying that there were 1740 backup ... requests waiting. ... If there are active backup requests, ... of the queue. ...
      (bit.listserv.ibm-main)
    • Re: Press release: BookMasters go live on OpenQM
      ... QM development is driven by user requests, ... operating system level tools for snapshot backup of the entire system. ... And a point from an earlier posting from Tony... ...
      (comp.databases.pick)
    • Re: Corrupted dbf file... help!!
      ... possible to backup the controlfile to trace - i assume you knew that - ... In this mount phase yo can do a backup to ... solution that falls within the oracle database as opposed to your ... filescanning trick. ...
      (comp.databases.oracle.server)