Web Hack List

Collected research

IIS6/ASP & file upload for fun and profit

48Bits Blog » Blog Archive » IIS6/ASP & file upload for fun and profit

IIS 6 decides whether ASP.dll should execute a request by scanning URL segments for executable extensions, so a directory named folder.asp makes IIS run any file beneath it - folder.asp/document.pdf executes as ASP. Combined with CVE-2009-4444 semicolons and NTFS alternate data streams (file.asp::$DATA, filename.asp:.jpg), it defeats extension filters in third-party upload components.

Record

Document
48Bits Blog » Blog Archive » IIS6/ASP & file upload for fun and profit
Researcher
Juan Galiana
Published by
blog.48bits.com
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Juan Galiana, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .