Microsoft IIS 5.0 – Authentication Bypass (MS10-065)

  • 作者: Soroush Dalili
    日期: 2010-07-02
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/14179/
  • MS10-065 - Directory Authentication Bypass Vulnerability
    
    Description:
    This vulnerability is because of using Alternate Data Stream to open a protected folder. All of IIS
    authentication methods can be circumvented. In this technique, we can add a “:$i30:$INDEX_ALLOCATION” to a directory name to bypass the authentication.
    
    Download:
    https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/14179.pdf (IIS5.1_Authentication_Bypass.pdf)