Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

IIS 5/6 vulnerability (971492) - How to Find WebDAV

The ISC has posted some helpful links for IIS and System Admins on techniques to locate WedDAV services

Star ISS Administration - How to locally determine if WebDAV is active
http://isc.sans.org/diary.html?storyid=6433
http://support.microsoft.com/kb/328505
http://blogs.technet.com/srd/archive/2009/05/20/answers-to-the-iis-webdav-authentication-bypass-questions.aspx

Star ISS Administration - Using nmap to remotely locate WebDAV
http://isc.sans.org/diary.html?storyid=6436
http://nmap.org/nsedoc/scripts/http-iis-webdav-vuln.html