[Full-disclosure] IIS 6.0 AUX.aspx DoS

Łukasz Pilorz lukasz at pilorz.net
Tue May 22 12:02:14 BST 2007


Off-Topic:

AUX seems also to be a funny way to check if Apache server stands on
Windows host.

Google inurl:phpinfo.php apache cmd.exe
check:
/test (returns 404)
/AUX (returns 403 - !)

Google inurl:phpinfo.php apache /bin/sh
check:
/test (returns 404)
/AUX (returns 404)

Best regards,
Łukasz Pilorz


Full-Disclosure is hosted and sponsored by Secunia.