IIS6 WebDav

Microsoft Windows 2003|2008|XP

nmap finds webdav

  • nmap -sV -sC -oA nmap 10.x.x.x

  • Allowed Methods: OPTIONS, TRACE, GET, HEAD, COPY, PROPFIND, SEARCH, LOCK, UNLOCK

  • Options: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, POST, COPY, MOVE

  • GET - download

  • PUT - upload

  • MOVE - you can rename/move

davtest

cadaver

PUT/MOVE

  • Scenario:

    • Can 'put' text - upload

    • NOT 'put' aspx

    • Can 'move' aspx

Burp

iis6-exploit

Windows 2003

Windows Server 2003 and IIS 6.0 privledge escalation using impersonation: https://www.exploit-db.com/exploits/6705/

Last updated

Was this helpful?