2020-10-24 21:21:17 +00:00
|
|
|
id: iis-shortname
|
|
|
|
info:
|
|
|
|
name: iis-shortname
|
|
|
|
author: nodauf
|
|
|
|
severity: info
|
2020-10-24 21:25:47 +00:00
|
|
|
description: If IIS use old .Net Framwork it's possible to enumeration folder with the symbol ~.
|
2020-10-24 21:21:17 +00:00
|
|
|
|
|
|
|
# References:
|
|
|
|
# - https://github.com/lijiejie/IIS_shortname_Scanner
|
|
|
|
# - https://www.exploit-db.com/exploits/19525
|
|
|
|
|
|
|
|
requests:
|
|
|
|
- method: GET
|
|
|
|
path:
|
|
|
|
- "{{BaseURL}}/N0t4xist*~1*/a.aspx"
|
|
|
|
- "{{BaseURL}}/*~1*/a.aspx'"
|
|
|
|
- method: OPTIONS
|
|
|
|
path:
|
|
|
|
- "{{BaseURL}}/N0t4xist*~1*/a.aspx"
|
|
|
|
- "{{BaseURL}}/*~1*/a.aspx'"
|
|
|
|
|
|
|
|
matchers:
|
|
|
|
- type: dsl
|
2020-11-20 13:19:39 +00:00
|
|
|
name: iis-scan
|
2020-10-24 21:21:17 +00:00
|
|
|
dsl:
|
|
|
|
- "status_code_1!=404 && status_code_2 == 404 || status_code_3 != 404 && status_code_4 == 404"
|