Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

NT IIS IISAPI Extension Enumerate Root Web Server Directory Vulnerability

Solution:
In IIS4 and above, you can configure it to check for the existence of a file before it returns an error message.

In IIS4:
Preferences -> Home directory -> Application
select "Check if file exists" for all IISAPI mappings registered

Also, remove all unused mappings.








 

Privacy Statement
Copyright 2009, SecurityFocus