【IIS】Microsoft IIS Tilde directory enumaration problems问题解决??

wxlwxlwxlwxl 2012-08-22 03:00:26
扫描工具显示Microsoft IIS的漏洞:
Microsoft IIS tilde directory enumeration Alert group

Description:It is possible to detect short names of files and directories which have an 8.3 file naming scheme
equivalent in Windows by using some vectors in several versions of Microsoft IIS. For instance, it is
possible to detect all short-names of ".aspx" files as they have 4 letters in their extensions. This
can be a major issue especially for the .Net websites which are vulnerable to direct URL access as
an attacker can find important files and folders that they are not normally visible.

Recommendations: Consult the "Prevention Technique(s)" section from Soroush Dalili's paper on this subject. A link to
this paper is listed in the Web references section bellow.

哪位大侠遇到过类似问题,帮忙回复下,多谢
...全文
1853 3 打赏 收藏 转发到动态 举报
写回复
用AI写文章
3 条回复
切换为时间正序
请发表友善的回复…
发表回复
jenycheng 2014-12-29
  • 打赏
  • 举报
回复
请参考 http://support.microsoft.com/kb/121007/en-us
ping9107 2013-09-09
  • 打赏
  • 举报
回复
引用 1 楼 aaguxibin 的回复:
把目录浏览权限关闭,试试看,我也正遇到
目录浏览权限关闭,还是不行啊!求解
aaguxibin 2012-09-05
  • 打赏
  • 举报
回复
把目录浏览权限关闭,试试看,我也正遇到

8,329

社区成员

发帖
与我相关
我的任务
社区描述
Web 开发 IIS
社区管理员
  • IIS
加入社区
  • 近7日
  • 近30日
  • 至今
社区公告
暂无公告

试试用AI创作助手写篇文章吧