首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Microsoft IIS 6.0 and 7.5 Multiple Vulnerabilities
来源:vfocus.net 作者:Kingcope 发布时间:2012-06-11  

THIS IS A GENUINE ISOWAREZ RELEASE
********************************************************
------------------------------------------------------------------------------------------------------------------------------------------------------------
Title: Microsoft IIS 6.0 with PHP installed Authentication Bypass

Affected software:
Microsoft IIS 6.0 with PHP installed
(tested on Windows Server 2003 SP1 running PHP5)

Details:
By sending a special request to the IIS 6.0 Service running PHP the attacker can
successfully bypass access restrictions.

Take for example:
1.) IIS/6.0 has PHP installed
2.) There is a Password Protected directory configured
--> An attacker can access PHP files in the password protected
directory and execute them without supplying proper credentials.
--> Example request (path to the file): /admin::$INDEX_ALLOCATION/index.php

IIS/6.0 will gracefully load the PHP file inside the "admin" directory
if the ::$INDEX_ALLOCATION postfix is appended to directory name.
This can result in accessing administrative files and under special
circumstances execute arbirary code remotely.
------------------------------------------------------------------------------------------------------------------------------------------------------------

Title: Microsoft IIS 7.5 Classic ASP Authentication Bypass

Affected Software:
Microsoft IIS 7.5 with configured Classic ASP and .NET Framework 4.0
installed (.NET Framework 2.0 is unaffected, other .NET frameworks
have not been tested)
(tested on Windows 7)

Details:
By appending ":$i30:$INDEX_ALLOCATION" to the directory serving the
classic ASP file access restrictions can be successfully bypassed.

Take this Example:
1.) Microsoft IIS 7.5 has Classic ASP configured (it allows serving .asp files)
2.) There is a password protected directory configured that has
administrative asp scripts inside
3.) An attacker requests the directory with :$i30:$INDEX_ALLOCATION
appended to the directory name
4.) IIS/7.5 gracefully executes the ASP script without asking for
proper credentials

------------------------------------------------------------------------------------------------------------------------------------------------------------
Title: Microsoft IIS 7.5 .NET source code disclosure and authentication bypass

Affected Software:
Microsoft IIS/7.5 with PHP installed in a special configuration
(Tested with .NET 2.0 and .NET 4.0)
(tested on Windows 7)
The special configuration requires the "Path Type" of PHP to be set to
"Unspecified" in the Handler Mappings of IIS/7.5

Details:
The authentication bypass is the same as the previous vulnerabilities:
Requesting for example
http://<victimIIS75>/admin:$i30:$INDEX_ALLOCATION/admin.php will run
the PHP script without asking for proper credentials.

By appending /.php to an ASPX file (or any other file using the .NET
framework that is not blocked through the request filtering rules,
like misconfigured: .CS,.VB files)
IIS/7.5 responds with the full source code of the file and executes it
as PHP code. This means that by using an upload feature it might be
possible (under special circumstances) to execute arbitrary PHP code.
Example: Default.aspx/.php

 

Cheerio and signed,

/Kingcope


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Tom Sawyer Software GET Extens
·Symantec Web Gateway 5.0.2.8 A
·Sielco Sistemi Winlog Buffer O
·PEamp Null Pointer Dereference
·ComSndFTP Server 1.3.7 Beta Re
·PEamp (.mp3) Memmory Corruptio
·Safari On iOS Denial Of Servic
·MS12-005 Microsoft Office Clic
·Microsoft IIS MDAC msadcs.dll
·Total Video Player V1.31 [.flv
·Microsoft IIS MDAC msadcs.dll
·F5 BIG-IP Remote Root Authenti
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved