七天酒店入住记录多久删除(如家酒店入住记录

访客3年前关于黑客接单1010

I. 背景
---------------------
"IIS is a web server application and set of
feature extension modules created by Microsoft for use with Microsoft Windows.
IIS is the third most popular server in the world." (Wikipedia)
II. 概述
---------------------
Vulnerability Research Team discovered a vulnerability
in Microsoft IIS.
The vulnerability is caused by a tilde character "~" in a Get request, which could allow remote attackers
to diclose File and Folder names.
III. 影响产品
---------------------------
IIS 1.0, Windows NT 3.51
IIS 2.0, Windows NT 4.0
IIS 3.0, Windows NT 4.0 Service Pack 2
IIS 4.0, Windows NT 4.0 Option Pack
IIS 5.0, Windows 2000
IIS 5.1, Windows XP Professional and Windows XP Media Center Edition
IIS 6.0, Windows Server 2003 and Windows XP Professional x64 Edition
IIS 7.0, Windows Server 2008 and Windows Vista
IIS 7.5, Windows 7 (error remotely enabled or no web.config)
IIS 7.5, Windows 2008 (classic pipeline mode)
Note: Does not work when IIS uses .Net Framework 4.
IV. Binary Analysis & Exploits/PoCs
---------------------------------------
Tilde character "~" can be used to find short names of files and folders when the website is running on IIS.
The attacker can find important file and folders that they are not normaly visible.
In-depth technical *** ysis of the vulnerability and a functional exploit
are available through:
http://soroush.secproject.com/blog/2012/06/microsoft-iis-tilde-character-vulnerabilityfeature-short-filefolder-name-disclosure/
V. 解决方案
----------------
There are still workarounds through Vendor and security vendors.
Using a configured WAF may be usefull (discarding web requests including the tilde "~" character).

相关文章

seo关键词优化考核指标

利用数据化统计考核指标核定seo工作成效才是科学的seo。我们做seo工作也好,做关键词带来的流量转化也罢,都要以数据分析为前提的。没有数据指标考核的工作室一头雾水没有效率的。通常来讲,细化的关键词优...

微信如何偷偷精准定位他人的几类小窍门

微信是约七年发展趋势到今日,其便捷性和隐私保护被欢迎,谁也基础做到手机微信的水准以前,互联网技术上丟了中老年人客户也手机微信的客户添加部队,每日的盆友...

吹泡泡机怎么使用

吹泡泡是孩子都喜爱的游戏,因为泡泡的色彩很绚丽,仿佛每个泡泡都是一个奇妙的世界,里面有好看的风景和有趣的故事,美丽的泡泡漫天飞舞给人带来浪漫的气息和美丽的遐想。抖音同款网红小羊泡泡机有着可爱的卡通图案...

黑客帝国很火bgm(黑客帝国 bgm)

黑客帝国很火bgm(黑客帝国 bgm)

黑客帝国2中就是追车戏里崔尼蒂带着制匙者上摩托飞下大卡车的背景音乐是... 1、,《黑客帝国2:重装上阵》剧情介绍:实际上,整个《重装上阵》是尼奥探寻自己使命背后真相的过程,他要为自己的行动寻找一个可...

阳泉当面交易的黑客(阳泉当面交易的黑客是谁)

阳泉当面交易的黑客(阳泉当面交易的黑客是谁)

本文目录一览: 1、APT黑客组织为何又盯上数字货币? 2、有哪些安全有关黑客 3、币圈怎么第一时间知道黑客攻击 4、发现股票里的盈利有黑客怎么处理 APT黑客组织为何又盯上数字货币?...

聊天记录看好几遍「老婆清空了一个人的聊天记录」

  自从表白后,我和她貌似忽冷忽热,没办法谁叫她有男朋友的啊。期末考加司法考试,弄得我基本一天早上9点在图书馆看书看到晚上8点。真的好累啊,昨晚洗完澡躺床上上着手机QQ,十一点多等着0点的足球赛。有人...