IIS ShortName Scanner
by StarGazer777 - Wednesday May 29, 2024 at 05:05 PM
#1
This is an old tool, but it is capable to tackle even the latest IIS (IIS 10 on Windows Server 2022) Big Grin

Microsoft IIS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered during the parsing of a request that contains a tilde character (~). This may allow a remote attacker to gain access to file and folder name information. Smile 

It is possible to detect short names of files and directories which have an 8.3 equivalent in Windows by using some vectors in several versions of Microsoft IIS. For instance, it is possible to detect all short-names of ".aspx" files as they have 4 letters in their extensions.


https://github.com/irsdl/IIS-ShortName-Scanner

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Scraping | https://breachforums.ai/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Largest Discord User History Archive - 10m+ Users Mega 318 40,226 9 hours ago
Last Post: phas3lock
  A collection of deepweb sites [2025] dg7ka 108 3,108 Yesterday, 09:29 PM
Last Post: Moneymaking123
  In front an abuse in the school, any suggestion? dai5 0 120 Yesterday, 11:02 AM
Last Post: dai5
  Questrade leak anyone? username000 0 200 May 01, 2026, 11:36 PM
Last Post: username000
  OSINT repositories by country browdbrowniebread 0 287 Apr 30, 2026, 07:41 PM
Last Post: browdbrowniebread

Forum Jump:


 Users browsing this forum: 1 Guest(s)