CNCVE编号:CNCVE-20020007 CVE编号: 安全级别:低 漏洞中文描述: Microsoft IIS是Windows系统默认的主服务器程序,它提供Web、Mail、Ftp、Nntp服务。Mcrosoft IIS认证过程实现上存在问题,在某些情况下,远程攻击者可以得到IIS服务器内部地址、NetBIOS名等相关信息,或者暴力猜测用户名和口令。IIS服务器支持匿名访问、基本认证和使用NTLM方式的Windows集成认证,通过发送包含认证信息的HTTP请求,远程攻击者可以强制让服务器以攻击者指定的方法认证自己,这样攻击者就可以确定服务器的认证方法的配置情况。如果服务器支持基本认证方式,并且处于防火墙或者NAT保护,攻击者就可以发送一个URL请求,并将Host域置空,Web服务器返回的信息中会包含其内部地址信息。如果服务器支持NTMLM认证方式,攻击者可以从Web服务器返回的信息中获取其NetBIOS名以及所属域的信息。攻击者也可能利用这个问题对服务器上的用户名和口令进行暴力猜解。 漏洞英文描述: Microsoft's Internet Information Server offers web, ftp, mail and nntp services. It is possible to force the web service to authenticate a user even if anonymous access is allowed to the resource being requested. This may open three low risk vulnerabilities on the server - two problems with information leakage and the possibility to perform brute force attacks against system user accounts. In terms of information leakage, if Basic auth is supported when making a request whatever is entered in the client Host HTTP header is used as the Realm. The Realm information is served by the server to the client so the client can tell when it should or shouldn't present authentication credentials. If the Host header field is left blank the server will, by default, use its IP address as the Realm. If the server is protected by a firewall that employs Network Address Translation and has a private IP address such as 10.x.x.x then this will be returned to the client. This information can aid an attacker when formulating other attacks. If NTLM authentication is supported then it is possible to discover the NetBIOS name of the server and the Windows NT domain it resides in. This information is returned as Base64 encoded text in response to a client Authorization request. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-03/0030.html http://www.nextgenss.com/advisories/iisauth.txt 系统类型: Win2000/NT 漏洞类型:设计错误