Re: Parent Paths

From: Jason Brown [MSFT] (i-brjaso_at_online.microsoft.com)
Date: 10/27/04


Date: Wed, 27 Oct 2004 11:52:42 +1000

Yes, unless a malicious user is somehow able to upload a .asp or other
active file to the server - they could then in theory do just what you're
doing and use parent paths server-side.

This kind of vulnerability is more common than you may think - if a user can
upload a file to a web-viewable directory which contains script, then a URL
filter will do no good at all. Then again if you are vulnerable to that one,
then disabling PPs server-side is the least of your worries.

-- 
Jason Brown
Microsoft GTSC, IIS
This posting is provided "AS IS" with no warranties, and confers no rights.
"news.microsoft.com" <me@here.com> wrote in message 
news:Oqxjyh3uEHA.3376@TK2MSFTNGP12.phx.gbl...
> If I've enabled Parent Paths (PP) in IIS, but have installed the URL 
> Filter
> and disallowed ".." and "../" within links, am I covered from the
> vulnerabilities of PP's?
>
> This allows me to use PP's in #Include statements, but doesn't allow
> visitors to use PP's in their links to access directories on my server.
>
> Is this correct?
>
> TIA
>
> 


Relevant Pages

  • Re: File Upload - Security Issues
    ... You want to upload a file for what reason and ... these viruses have less chance of being able to execute (even if succeeded ... :> file and what pitfalls you see re: security might be helpful on this ... :>: files to an IIS server that doesn't have MS Office actually installed? ...
    (microsoft.public.scripting.vbscript)
  • Re: File Upload - Security Issues
    ... uploaded and the user could upload any or all of these in theory. ... There is no one product that can give you 100% security, ... > Code doesn't execute in local memory space unless remote user has rights ... > You don't have MS Office installed on the server. ...
    (microsoft.public.scripting.vbscript)
  • pure-ftp nologin
    ... I have a server running FreeBSD 6.3. ... # If you want to enable PAM authentication, ... AnonymousCanCreateDirs no ... # Disallow anonymous users to upload new files ...
    (comp.unix.bsd.freebsd.misc)
  • [NT] DeskNow Mail and Collaboration Server Directory Traversal Vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Collaboration Server is "a full-featured and integrated mail and instant ... attachment upload feature that may be exploited to upload files to ... * DeskNow Mail and Collaboration Server version 2.5.12 and prior ...
    (Securiteam)
  • Re: [Full-disclosure] phpBB 2.0.17 (and other BB systems as well) Cookie disclosure exploit.
    ... app that allows the user to upload an image of some type. ... Internet Explorer ignores the content type sent by the web server and ... > HTML code instead. ... > upload it as a phpBB avatar. ...
    (Full-Disclosure)