BugTraq
Creating a secret web site on IIS 5.x using Alternative Data Streams Aug 04 2005 04:22PM
inge_eivind henriksen chello no (1 replies)
RE: Creating a secret web site on IIS 5.x using Alternative Data Streams Aug 09 2005 03:12PM
James C Slora Jr (Jim Slora phra com)
Mitigation at the IIS server looks pretty straightforward.

URLScan in default configuration prevents access to ADS files, generating
the following log line:

Client at 10.1.1.100: URL contains sequence ':', which is disallowed.
Request will be rejected. Site Instance='1', Raw
URL='/myremoteserver/help.gif:secret'

So you should see accesses in the IIS logs if you don't run URLScan, and
failed attempts in the URLScan logs if you do run it.

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus