CNCVE编号:CNCVE-20020006 CVE编号: 安全级别:低 漏洞中文描述: Microsoft IIS是Windows系统默认的主服务器程序,它提供Web、Mail、Ftp、Nntp服务。 Microsoft IIS实现上存在问题,在某些情况下,远程攻击者可以得到IIS服务器的内部IP地址。 如果IIS服务器受一个有地址转换功能的防火墙的保护并使用一个内部IP地址,通过向服务器发送一个畸形的请求,远程攻击者可能得到主机的内部IP地址。可以发送一个Host属性为空的请求包给HTTP服务器,IIS通常会返回主机的IP地址。例如,发送如下的请求:ROPFIND / HTTP/1.1 Host: Content-Length: 0 服务器会返回207 Multi-Status信息,包含了页面的一些属性信息,在HREF属性中就会泄露主机的IP地址。在HTTP请求中使用WRITE或MKCOL方法,可以在回应信息的Location节中得到主机的IP地址。IIS 5和5.1支持WebDAV方法,所以受此漏洞的影响,当IIS 5.x和4.0使用基本Web认证时也受此漏洞影响。 漏洞英文描述: Microsoft's Internet Information Server offers web, ftp, mail and nntp services. If the server is protected by a firewall using Network Address Translation and the server uses a private internal IP address then, by making a malformed request to the web service it is possible for an attacker to discover this IP address. Whilst this won't come anywhere near to allowing an attacker to compromise a IIS server it will help them formulate further attacks. By making certain requests to the web service with a blank Host HTTP client header the server response will often contain the server's IP address, for example when using the PROPFIND request method. PROPFIND / HTTP/1.1 Host: Content-Length: 0 The server will return a 207 Multi-Status response with certain properties of the root page. The server's IP address will be revealed in the HREF property. Using the WRITE or MKCOL method will return the machine's IP address in the Location server HTTP header, though of course if the server allows the WRITE and MKCOL methods then the server has greater problems. Only IIS 5 and 5.1 support the WebDAV methods so these methods only affect these systems. IIS 5.x and 4.0 are both vulnerable to this issue if Basic authentication is enabled. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-03/0038.html http://www.nextgenss.com/advisories/iisip.txt 发送如下的请求: PROPFIND / HTTP/1.1 Host: Content-Length: 0 服务器会返回207 Multi-Status信息,包含了页面的一些属性信息,在HREF属性中就会泄露主机的IP地址。在HTTP请求中使用WRITE或MK 系统类型: Win2000/NT 漏洞类型:设计错误