WebDAV Exploit Checking Tool

IIS 6 sites with the WebDAV extension enabled may be vulnerable to authentication bypass because of a bug in the way that the extension handles Unicode characters.

Cutting the URI path with random Unicode characters allows hackers to bypass the access control list. Depending on the permissions of the Web server files, a hacker would be able to retrieve user names and passwords, upload, overwrite and delete files, or run malicious code.



FAQs

Got questions about dotDefender? Please visit our knowledgebase for answers or contact Support at support@applicure.com.


Featured Blog Posts

CWE/SANS Top 25

With the release of the 2010 CWE/SANS Top 25 Most Dangerous Programming Errors came a ... read more ...

The Big Website Guide to a Hacking Attack

Working in IT, one of the most dreaded calls you can receive is the one ... read more ...

Web Hacking Facts and Figures

According to a new Data Breach Investigations Report from global comms and IT provider Verizon ... read more ...

Use the WebTuff utility to check your system vulnerability:

  1. Try to retrieve the file at the given URI using a simple WebDAV GET command
  2. Try to retrieve the file at the given URI using a simple WebDAV GET command, cutting the URI with these Hex | Unicode characters: %c0 and %af.
  3. Save the retrieved file locally and / or report server response

Download the Free WebTuff Tool:
WebTuff link (zip file containing win32 binary + Python source code)
WebTuff-MD5 (MD5 hash of WebTuff binary)


Related Articles:

Codero and Applicure Partnership
Linux Remote Command Execution Vulnerability
STI Group offering dotDefender

Please Wait...