Penetration Testing mailing list archives

RE: finding webroot on IIS


From: "George Milliken" <gmilliken () farm9 com>
Date: Thu, 14 Jun 2001 10:12:18 -0700

pipe this through the unicode shell and observe the results


roughly




cmd.exe attrib -s index.html

George
farm9

-----Original Message-----
From: * (todd + 1) [mailto:todd () ubermother net]
Sent: Wednesday, June 13, 2001 9:30 PM
To: pen-test () securityfocus com
Subject: finding webroot on IIS


hello all,

Recently i came across an IIS webserver that i found to be vulnerable to the
Unicode attacks. However, i cannot determine the webroot of this drive, and
therefore i am having troubles reaching a full comprimise.  The directory
"C:\Inetpub" exists, but the only contents of this directory is the folder
"mailroot".

Additionally, when i connect and request the root document (ie GET / ), it
returns the string: "<% Response.ContentType = "text/plain" %> HELLO"

Does anyone come across anything like this before, and what would be the
simplest method of determining the webroot?

thanks in advance
todd willey
ubermother


Current thread: