Microsoft IIS Failure To Log Undocumented TRACK Requests Vulnerability
BID:9313
Info
Microsoft IIS Failure To Log Undocumented TRACK Requests Vulnerability
| Bugtraq ID: | 9313 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2003 12:00AM |
| Updated: | Dec 29 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Parcifal Aertssen. |
| Vulnerable: |
Microsoft IIS 5.0 |
| Not Vulnerable: |
Microsoft IIS 6.0 |
Discussion
Microsoft IIS Failure To Log Undocumented TRACK Requests Vulnerability
A vulnerability has been reported to affect Microsoft IIS. It has been reported that IIS fails to log HTTP TRACK calls made to the affected server. A remote attacker may exploit this condition in order to enumerate server banners.
A vulnerability has been reported to affect Microsoft IIS. It has been reported that IIS fails to log HTTP TRACK calls made to the affected server. A remote attacker may exploit this condition in order to enumerate server banners.
Exploit / POC
Microsoft IIS Failure To Log Undocumented TRACK Requests Vulnerability
The following proof of concept has been supplied:
TRACK / HTTP/1.0 [\r\r]
The following proof of concept has been supplied:
TRACK / HTTP/1.0 [\r\r]
Solution / Fix
Microsoft IIS Failure To Log Undocumented TRACK Requests Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft IIS Failure To Log Undocumented TRACK Requests Vulnerability
References:
References:
- Microsoft IIS Logging Failure (Parcifal Aertssen)