<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>80sec &#187; Filename</title>
	<atom:link href="http://www.80sec.com/tag/filename/feed" rel="self" type="application/rss+xml" />
	<link>http://www.80sec.com</link>
	<description>Know it then hack it!</description>
	<lastBuildDate>Tue, 20 Dec 2011 08:10:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Microsoft Internet Infomation Server 6.0 ISAPI Filename Analytic Vulnerability</title>
		<link>http://www.80sec.com/microsoft-internet-infomation-server-6-isapi-filename-analytic-vulnerabilitie.html</link>
		<comments>http://www.80sec.com/microsoft-internet-infomation-server-6-isapi-filename-analytic-vulnerabilitie.html#comments</comments>
		<pubDate>Fri, 24 Apr 2009 06:39:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[漏洞发布]]></category>
		<category><![CDATA[Filename]]></category>
		<category><![CDATA[IIS6]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.80sec.com/?p=57</guid>
		<description><![CDATA[Microsoft Internet Infomation Server 6.0 ISAPI Filename Analytic Vulnerability function Copyright() { var Author=”80sec”; var Email=”kEvin#80sec.com”.replace(“#”,”@”) var Site=”http://www.80sec.com”; var Date=new Date(2009,4,24).toLocaleString(); var Reference=”http://www.80sec.com/Microsoft-Internet-Infomation-Server-6-ISAPI-filename-analytic-Vulnerabilitie.html”; return Reference; } /* 漏洞描述: IIS6 (Internet Infomation Server 6.0) 是微软出品的一款WEB服务器系统, 广泛用于各种个人/商业信息发布/网站架设领域。80sec在测试中发现, IIS设计上在处理畸形文件名的时候存在一个严重的安全漏洞, 可能绕过web程序的逻辑检查从而能导致服务器以IIS进程权限执行任意恶意用户定义的脚本, 黑客可以通过制造畸形的服务器文件来触发该 漏洞, 并从而控制服务器. 漏洞厂商: Microsoft [ http:\/\/www.microsoft.com ] 漏洞测试: Undefined 解决方案: 等待微软更新官方补丁. */]]></description>
			<content:encoded><![CDATA[<p>Microsoft Internet Infomation Server 6.0 ISAPI Filename Analytic Vulnerability</p>
<p>function Copyright()<br />
{</p>
<p>	var Author=”80sec”;<br />
	var Email=”kEvin#80sec.com”.replace(“#”,”@”)<br />
	var Site=”http://www.80sec.com”;<br />
	var Date=new Date(2009,4,24).toLocaleString();<br />
	var Reference=”http://www.80sec.com/Microsoft-Internet-Infomation-Server-6-ISAPI-filename-analytic-Vulnerabilitie.html”;<br />
	return Reference;</p>
<p>}</p>
<p>/*</p>
<p>	漏洞描述:<br />
	<span id="more-57"></span><br />
		IIS6 (Internet Infomation Server 6.0) 是微软出品的一款WEB服务器系统, 广泛用于各种个人/商业信息发布/网站架设领域。80sec在测试中发现, IIS设计上在处理畸形文件名的时候存在一个严重的安全漏洞, 可能绕过web程序的逻辑检查从而能导致服务器以IIS进程权限执行任意恶意用户定义的脚本, 黑客可以通过制造畸形的服务器文件来触发该	漏洞, 并从而控制服务器.</p>
<p>	漏洞厂商: </p>
<p>		Microsoft [ http:\/\/www.microsoft.com ]</p>
<p>	漏洞测试:</p>
<p>		Undefined</p>
<p>	解决方案:</p>
<p>		等待微软更新官方补丁.</p>
<p>*/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.80sec.com/microsoft-internet-infomation-server-6-isapi-filename-analytic-vulnerabilitie.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

