IIS - Internet Information Services
Internal IP Address disclosure
nc -v domain.com 80
openssl s_client -connect domain.com:443GET / HTTP/1.0
HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Pragma: no-cache
Location: https://192.168.5.237/owa/
Server: Microsoft-IIS/10.0
X-FEServer: NHEXCHANGE2016Execute .config files
IIS HTTP Bruteforce
Local File Inclusion list
Old IIS vulnerabilities worth looking for
Microsoft IIS tilde character “~” Vulnerability/Feature – Short File/Folder Name Disclosure

Basic Authentication bypass
最后更新于