Web Hack List

Collected research

RCE by uploading a web.config

Where an IIS upload filter blocks executable extensions such as .asp and .aspx, uploading a web.config instead is allowed. That file registers an ISAPI handler for .config and removes the request-filtering entries that hide it, so the uploaded config executes the ASP embedded in its own comments, yielding remote code execution as nt authority system.

Record

Researcher
003random
Published by
003Random's Blog
Date
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of 003random, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .