Introduction to 0X01 Vulnerabilities
Windows Server is a series of server operating systems released by Microsoft. Internet Information Services (IIS) is an internet-based basic service that runs in Microsoft Windows. A buffer overflow vulnerability exists in the ' scstoragepathfromurl ' function of the WebDAV service in the version of IIS 6.0 in Microsoft Windows Server 2003 R2. Remote attackers can use this vulnerability to execute arbitrary code by sending a specially crafted PROPFIND request. 0x02 Repair Method
1. Turn off the WebDAV service under IIS
2. If the direct closure of WebDAV will affect your business, you can flexibly configure a WebDAV-open approach, such as disabling the PropFind method:
1 Install the Microsoft release of the IIS Security Hardening tool urlscan,urlscan Default installation will screen WebDAV features;
Download Address: https://technet.microsoft.com/en-us/security/cc242650.aspx
2) Configure the Urlscan.ini file to filter the request method
Welcome to share the better ideas, eagerly look forward to ^ ^_^ ^!