Microsoft IIS User Existence Disclosure Vulnerability
BID:7492
Info
Microsoft IIS User Existence Disclosure Vulnerability
| Bugtraq ID: | 7492 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 1999 12:00AM |
| Updated: | Feb 24 1999 12:00AM |
| Credit: | Discovery of this issue credited to mnemonix <[email protected]>. |
| Vulnerable: |
Microsoft IIS 5.1 Microsoft IIS 5.0 Microsoft IIS 4.0 alpha Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS User Existence Disclosure Vulnerability
Microsoft IIS is prone to an issue where the existence of users may be revealed to remote attackers. The vulnerability exists when users attempt to authenticate against a vulnerable system.
IIS will generate an error page if authentication fails. Different messages are generated depending on whether the user exists or not.
Microsoft IIS is prone to an issue where the existence of users may be revealed to remote attackers. The vulnerability exists when users attempt to authenticate against a vulnerable system.
IIS will generate an error page if authentication fails. Different messages are generated depending on whether the user exists or not.
Exploit / POC
Microsoft IIS User Existence Disclosure Vulnerability
The following proof of concepts have been provided:
The following proof of concepts have been provided:
Solution / Fix
Microsoft IIS User Existence Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft IIS User Existence Disclosure Vulnerability
References:
References: