Re: IIS Internal IP disclosure

From: H D Moore (hdmat_private)
Date: Wed Feb 26 2003 - 18:04:02 PST

  • Next message: Paul Johnston: "new magic strings for no404.nasl"

    Forgot to submit this one, Geoff Humes wrote it a while back. It uses the 
    directory scanner KB data and does some sanity checking of the 
    address/host. The output probably needs to be modified to report standard 
    Nessus results though...
    On Wednesday 26 February 2003 02:23 pm, Renaud Deraison wrote:
    > > This script is not something new, but rather an addition to an
    > > existing iis_nat script to increase Nessus chances of detecting
    > > internal IIS IP address which is a security risk and where
    > > iis_nat.nasl will miss find it.
    > Then I'd prefer you to send a patch for the iis_nat.nasl plugin so that
    > it does a proper check please.
    > 				-- Renaud

    This archive was generated by hypermail 2b30 : Wed Feb 26 2003 - 18:04:57 PST