Microsoft's IIS 6 has a badly resolved file name error

Source: Internet
Author: User
Tags iis
iis| Error | microsoft | file name

Test method: In FTP to create a test.asp folder, folder name is test.asp, in this folder upload a hack.jpg, this JPG content can be directly <%=now%> With IE remote access to this hack.jpg, you can find that it is the same as ASP file to run! Obviously, as long as your site program, allowing users to create their own folders and upload pictures, hackers can upload images as an ASP Trojan to run.

WORKAROUND: Set the Execute permission option, directly will have upload permission directory, cancel ASP's running permissions, can solve this problem.



Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.