Full Disclosure mailing list archives
ASHX, ASMX or What?
From: Nahuel Grisolia <nahuel () bonsai-sec com>
Date: Fri, 24 Jun 2011 13:16:13 -0300
List, Imagine that you're in front of an """"insecure"""" file upload in the context of an IIS6,7 (no ;.jpg :P) and the regex filtering the file is like: [anything].asp[anything] (yeah, my.aspirator.jpg is filtered hehe) No .aspx, no .asp and no .aspx;jpg even if the server is vulnerable... So... is there any way to bypass this control? Like uploading a malicious Webservice (can we simply upload a Webservice file? I think they need to be precomplied first) or something like that? Thanks a lot! regards, -- Nahuel Grisolia - C|EH Information Security Consultant Bonsai Information Security Project Leader http://www.bonsai-sec.com/ (+54-11) 4777-3107 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- ASHX, ASMX or What? Nahuel Grisolia (Jun 24)
- Re: ASHX, ASMX or What? Christian Sciberras (Jun 24)
- Re: ASHX, ASMX or What? Nahuel Grisolia (Jun 24)
- Re: ASHX, ASMX or What? Thor (Hammer of God) (Jun 24)
- Re: ASHX, ASMX or What? Christian Sciberras (Jun 24)