Misconfiguration of IIS in a food system leads to arbitrary code execution

Source: Internet
Author: User

Improper IIS configuration leads to arbitrary code execution, and multiple sites under the company fall. A large amount of procurement and financial data can be queried by listed companies.

In fact, the problem is very simple.

1. Set WebDAV to allow in the WEB Server Extension

2. The write permission is enabled in the website permission configuration.



Http://iservice.qiaqiafood.com: 8003/

First, we found the two OA Systems of the food and Its huabang real estate. This is precisely because the IIS configuration on this server is improper. WEBDAV is allowed to have write permissions, and the parsing vulnerability of IIS6.0 can be directly transmitted.

Asp;.jpg

Suffix (upload tool DAV explorer), kitchen knife connection successful

Open web. config, find the database information, connect to the database, and there are a lot of trousers. The rough calculation covers more than 30 WEB systems, some systems, and some of them are Intranet systems under the China Communications Group, including a large number of procurement, financial, customer information and other information, especially the OA system has a lot of such customer information (detailed to the county-level supermarkets, stores ), financial information includes basic purchase, travel, and other personnel information, which is full of commercial value. However, for public companies, the exposure of short messages in the OA system is more complicated...

 





 

Because there are too many systems and websites involved, we will not list them here. We also need to pay attention to web applications on the Intranet and Internet. Many weak passwords exist in the mis Management Information System, security training for internal employees should be strengthened

Solution:

1. Disable webdav

2. Disable write permission

In addition, I scanned the tool and found that IIS tilde directory enumeration exists on several servers. Specifies the name of the short file/folder to be exposed. Microsoft's URLScan can be done, the specific use of see http://www.freebuf.com/articles/4908.html (refer to: License)

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.