IIS Internal IP disclosure

From: Alex Zimin (alexat_private)
Date: Tue Feb 25 2003 - 14:54:58 PST

  • Next message: Alex Zimin: "Re: IIS Internal IP disclosure"

    This plugin should detect IIS internal IP disclosure vulnerability.
    This is the first Nessus plugin I wrote, so please don't expect it to be
    perfect.
    
    This plugin should follow the vulnerability exploit discussion found here:
    http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0025.html
    
    CVE: CAN-2000-0649
    BID: 1499
    
    iis_nat.nasl does very similar check, but it relies only on the http
    banner captured during scan.
    
    Maybe these two plugins should be combined and enhanced for better
    vulnerability detection.
    
    Alex Zimin
    alexat_private
    
    
    
    



    This archive was generated by hypermail 2b30 : Tue Feb 25 2003 - 14:50:00 PST