Vulnerability Development mailing list archives

MS Frontpage shtml.dll Path Leak Vulnerability


From: master3k () HOTMAIL COM (Greg)
Date: Mon, 13 Mar 2000 05:50:30 -0000


Hi All

This is my first time I have written to this forum so
please excuse any annoying 'newbie' style message habits.

I currently run NT4 Server with IIS4.  I have discovered a
hole where the actual path is produced on the web page if
someone does the following provided the server running is
NT4/IIS and have the FrontPage extensions installed:

http://www.anydomainname.com/_vti_bin/shtml.dll/any_nonexist
ent_web_page.htm

Does anyone know of a fix available or a work around?

I thank anyone who can help me out with this.

Cheers ;-)

- Greg


Current thread: