Ô¤¾¯Í¨¸æ:Windows 2003 R2 II6.0Ô¶³Ì´úÂëÖ´ÐÐÎó²î
2017-03-28
3ÔÂ27ÈÕ£¬Zhiniang Peng ºÍChen WuÐû²¼Á˹ØÓÚIIS 6.0 WebDAVÔ¶³Ì´úÂëÖ´ÐеÄÎó²îÐÅÏ¢£¨CVE-2017-7269£¬CNNVD-201703-1151£©¡£¸ÃÎó²îÔ´ÓÚMicrosoft Windows Server 2003 R2µÄIIS 6.0 ÖÐWebDAV ·þÎñÏÂScStoragePathFromUrlº¯Êý£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îͨ¹ýÒ»¸öÒÔ¡±If: <http://¡± in a PROPFIND¿ªÍ·µÄ³¤Í·ÇëÇóÀ´Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬ºÍ2016Äê7-8Ô·Ý̻¶µÄÒªÁìÒ»Ö¡£
ÍøÉÏÒÑÓÐÐû²¼µÄPOC¡£
Ïà¹ØµØµã£º
https://github.com/edwardz246003/IIS_exploit
https://www.seebug.org/vuldb/ssvid-92834
Ó°ÏìµÄ°æ±¾
Windows Server 2003 쵀Microsoft IIS (6.0)
ÐÞ¸´ÒªÁì
¹Ø±ÕIIS ϵÄWebDAV·þÎñ¡£
2015Äê7ÔÂ15ÈÕ£¬Î¢ÈíÒÑ×èÖ¹¶ÔWindows Server 2003µÄÖ§³Ö£¬ÒÔÊǹٷ½Ã»ÓÐÏà¹Ø½â¾ö¼Æ»®£¬½¨ÒéÓû§Éý¼¶µ½×îÐÂϵͳ Windows Server 2016¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







