NET IIS暴絕對(duì)路徑漏洞
更新時(shí)間:2007年02月09日 00:00:00 作者:
Title:Microsoft ASP.NET May Disclose Web Directory to Remote Users in Certain Cases
Description: If the ASP.NET application does not filter the error message, the web
directory information may be disclosed to remote users by using an unavailable file
which start with "~".
Hi, I'm Soroush Dalili from GrayHatz Security Group(GSG).I found new thing in .NET
Framework Version:1.1 (.ASPX Files).
If error mode in .net configuration is on, Run an unavailable aspx file that start with
"~" can cause showing full path in browsers.
For Example: Http://[URL]/~foo.aspx
------------------------------------------------------------------------
Note:Version 2 have not this bug and it return file does not exist
Vendor URL: www.microsoft.com
Version:1.1
Soloution: Update to version 2 or enable error filtering
Finder: Soroush Dalili
Team: GSG [GrayHatz Security group]
Web: grayhatz.net
Country: Iran
Email: Irsdl[a.t]yahoo[d.o.t]com
搜索引擎 inurl:aspx,然后隨便點(diǎn)個(gè)連接,在url后輸入~fly_ocean.aspx,即可暴出絕對(duì)路徑。
例如:
http://www.fodonline.com/qihuoju/default.aspx~fly_ocean.aspx
用于監(jiān)視的文件名無(wú)效:“D:\aaa\qihuoju\default.aspx~fly_ocean.aspx”。用于監(jiān)視的文件名必須具有絕對(duì)路徑,并且不包含通配符。
版本信息: Microsoft .NET Framework 版本:1.1.4322.2300; ASP.NET 版本:1.1.4322.2300
Description: If the ASP.NET application does not filter the error message, the web
directory information may be disclosed to remote users by using an unavailable file
which start with "~".
Hi, I'm Soroush Dalili from GrayHatz Security Group(GSG).I found new thing in .NET
Framework Version:1.1 (.ASPX Files).
If error mode in .net configuration is on, Run an unavailable aspx file that start with
"~" can cause showing full path in browsers.
For Example: Http://[URL]/~foo.aspx
------------------------------------------------------------------------
Note:Version 2 have not this bug and it return file does not exist
Vendor URL: www.microsoft.com
Version:1.1
Soloution: Update to version 2 or enable error filtering
Finder: Soroush Dalili
Team: GSG [GrayHatz Security group]
Web: grayhatz.net
Country: Iran
Email: Irsdl[a.t]yahoo[d.o.t]com
搜索引擎 inurl:aspx,然后隨便點(diǎn)個(gè)連接,在url后輸入~fly_ocean.aspx,即可暴出絕對(duì)路徑。
例如:
http://www.fodonline.com/qihuoju/default.aspx~fly_ocean.aspx
用于監(jiān)視的文件名無(wú)效:“D:\aaa\qihuoju\default.aspx~fly_ocean.aspx”。用于監(jiān)視的文件名必須具有絕對(duì)路徑,并且不包含通配符。
版本信息: Microsoft .NET Framework 版本:1.1.4322.2300; ASP.NET 版本:1.1.4322.2300
相關(guān)文章
10個(gè)好用的Web日志安全分析工具推薦小結(jié)
一款簡(jiǎn)單好用的Web日志分析工具,可以大大提升效率,目前業(yè)內(nèi)日志分析工具比較多,今天推薦十個(gè)比較好用的Web日志安全分析工具。感興趣的同學(xué)可以收藏一下2020-06-06怎么查QQ聊天記錄 怎樣恢復(fù)刪除的手機(jī)QQ聊天記錄技巧?
怎么查QQ聊天記錄 怎樣恢復(fù)刪除的手機(jī)QQ聊天記錄技巧?究竟對(duì)方在隱瞞什么呢,大家可以通過(guò)下面的方法試試。2012-01-01CTF AWD入門(mén)學(xué)習(xí)手冊(cè)
這篇文章主要為大家介紹了CTF AWD入門(mén)學(xué)習(xí)手冊(cè),有需要的朋友可以借鑒參考下,希望能夠有所幫助,祝大家多多進(jìn)步,早日升職加薪2022-10-10七個(gè)絕招應(yīng)對(duì)網(wǎng)上銀行盜賊
七個(gè)絕招應(yīng)對(duì)網(wǎng)上銀行盜賊...2006-09-09注冊(cè)驗(yàn)證java代碼[針對(duì)上篇文章]
注冊(cè)驗(yàn)證代碼[針對(duì)上篇文章] ,大家可以多參考腳本之家以前發(fā)布的文章。2009-08-08