IIS 6 sites with the WebDAV extension enabled may be vulnerable to authentication bypass because of a bug in the way that the extension handles Unicode characters.
Cutting the URI path with random Unicode characters allows hackers to bypass the access control list. Depending on the permissions of the Web server files, a hacker would be able to retrieve user names and passwords, upload, overwrite and delete files, or run malicious code.
Download the Free WebTuff Tool:
WebTuff link (zip file containing win32 binary + Python source code)
WebTuff-MD5 (MD5 hash of WebTuff binary)
Frost & Sullivan Award
Applicure Unveils dotDefender v3.8
MaximumASP and Applicure Announce Partnership
Please Wait... |