Penetration Testing mailing list archives

Re: finding webroot on IIS


From: "David Page" <david () melaniepage worldonline co uk>
Date: Thu, 14 Jun 2001 18:11:40 +0100

You could probably try something like

GET /blah.ida HTTP/1.1

Will probably disclose the webroot.

----- Original Message -----
From: "* (todd + 1)" <todd () ubermother net>
To: <pen-test () securityfocus com>
Sent: Thursday, June 14, 2001 5:30 AM
Subject: finding webroot on IIS


hello all,

Recently i came across an IIS webserver that i found to be vulnerable to
the
Unicode attacks. However, i cannot determine the webroot of this drive,
and
therefore i am having troubles reaching a full comprimise.  The directory
"C:\Inetpub" exists, but the only contents of this directory is the folder
"mailroot".

Additionally, when i connect and request the root document (ie GET / ), it
returns the string: "<% Response.ContentType = "text/plain" %> HELLO"

Does anyone come across anything like this before, and what would be the
simplest method of determining the webroot?

thanks in advance
todd willey
ubermother



Current thread: