ASP security flaw in MS IIS server (MS, flaw)

Source: Internet
Author: User
Tags microsoft iis
Involving procedures:
Microsoft IIS Server

Describe:
IIS enables users who have permission to upload and use ASP programs to change any file

With:
This is a very serious vulnerability for IIS, even IIS4.0, which still does not fix this vulnerability: you build
such as http://www.cnns.net/frankie/text/aspwrite.txt such a simple ASP program named Write.asp, note that the program does not allow line-wrapping!
It is then uploaded to any web directory (allowing script execution), such as:
Http://www.xxx.com/frankie/write.asp
Then enter the address in the browser
This will replace the home page! Red Word Black Bottom, show: This page is hacked by small-hacker!
Solution:
No related patches, only non-admin users can be prevented from uploading ASP programs and executing scripts

Security recommendations:
Administrators should be aware of the fact that if you open ASP upload and script execution permissions to the user, it is tantamount to handing over control of the entire system to the user. So don't open it easy.
Put the permissions of ASP to the general user

Related downloads:
Http://www.cnns.net/frankie/text/aspwrite.txt

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.