IIS 6 sites with the WebDAV extension enabled may be vulnerable to authentication bypass because of a bug in the way that the extension handles Unicode characters.
Cutting the URI path with random Unicode characters allows hackers to bypass the access control list. Depending on the permissions of the Web server files, a hacker would be able to retrieve user names and passwords, upload, overwrite and delete files, or run malicious code.
Download the Free WebTuff Tool:
WebTuff link (zip file containing win32 binary + Python source code)
WebTuff-MD5 (MD5 hash of WebTuff binary)
Linux Remote Command Execution Vulnerability
NetStrategies and Applicure Partnership
Codero and Applicure Partnership
Please Wait... |