CGI安全漏洞資料速查 v1.0(轉(zhuǎn)四)
Jun 21, 2016 am 09:12 AMcgi|安全|安全漏洞
76
類型: 攻擊型
名字: aexp.htr
風(fēng)險等級: 中
描述: 在/iisadmpwd目錄下存在aexp.htr文件,類似的還有aexp2.htr,aexp3.htr和aexp4b.htr等,這些文件允許攻擊者用窮舉法等方式破解和修改NT用戶的密碼。
建議: 建議禁止對/iisadmpwd目錄的訪問
解決方法: 刪除aexp.htr文件
____________________________________________________________________________________
77
類型: 攻擊型
名字: aexp2.htr
風(fēng)險等級: 中
描述: 在/iisadmpwd目錄下存在aexp2.htr文件,類似的還有aexp2.htr,aexp3.htr和aexp4b.htr等,這些文件允許攻擊者用窮舉法等方式破解和修改NT用戶的密碼。
建議: 建議禁止對/iisadmpwd目錄的訪問
解決方法: 刪除aexp2.htr文件
_______________________________________________________________________________________
78
類型: 攻擊型
名字: aexp3.htr
風(fēng)險等級: 中
描述: 在/iisadmpwd目錄下存在aexp3.htr文件,類似的還有aexp2.htr,aexp3.htr和aexp4b.htr等,這些文件允許攻擊者用窮舉法等方式破解和修改NT用戶的密碼。
建議: 建議禁止對/iisadmpwd目錄的訪問
解決方法: 刪除aexp3.htr文件
_________________________________________________________________________________________
79
類型: 攻擊型
名字: aexp4b.htr
風(fēng)險等級: 中
描述: 在/iisadmpwd目錄下存在aexp4b.htr文件,類似的還有aexp2.htr,aexp3.htr和aexp4b.htr等,這些文件允許攻擊者用窮舉法等方式破解和修改NT用戶的密碼。
建議: 建議禁止對/iisadmpwd目錄的訪問
解決方法: 刪除aexp4b.htr文件
____________________________________________________________________________________
80
類型: 攻擊型
名字: achg.htr
風(fēng)險等級: 中
描述: 在/iisadmpwd目錄下存在aechg.htr文件,類似的還有aexp2.htr,aexp3.htr和aexp4b.htr等,這些文件允許攻擊者用窮舉法等方式破解和修改NT用戶的密碼。
建議: 建議禁止對/iisadmpwd目錄的訪問
解決方法: 刪除achg.htr文件
____________________________________________________________________________________
81
類型: 攻擊型
名字: ExprCale.cfm
風(fēng)險等級: 中
描述: 在Coldfusion的web目錄: /cfdocs/expeval/ExprCalc.cfm文件,這個文件有個漏洞允許用戶讀取服務(wù)器硬盤上的任意文件包括用戶密碼數(shù)據(jù)庫sam文件
建議: 刪除相關(guān)的文件
解決方法: 刪除ExprCalc.cfm文件
_______________________________________________________________________________________
82
類型: 攻擊型
名字: getfile.cfm
風(fēng)險等級: 中
描述: 在Coldfusion的web目錄: /getfile.cfm文件,這個文件有個漏洞允許用戶讀取服務(wù)器硬盤上的任意文件包括用戶密碼數(shù)據(jù)庫sam文件
建議: 刪除相關(guān)的文件
解決方法: 刪除getfile.cfm文件
_______________________________________________________________________________
119
類型: 信息型
名字: x.htw
風(fēng)險等級: 中
描述: IIS4.0上有一個應(yīng)用程序映射htw--->webhits.dll,這是用于Index Server的點(diǎn)擊功能的。盡管你不運(yùn)行Index Server,該映射仍然有效。這個應(yīng)用程序映射存在漏洞,允許入侵者讀取本地硬盤上的文件,數(shù)據(jù)庫文件,和ASP源代碼。
建議:
建議在IIS控制臺中刪除無用的應(yīng)用程序映射
________________________________________________________________________________
120
類型: 信息型
名字: qfullhit.htw
風(fēng)險等級: 中
描述: IIS4.0上有一個應(yīng)用程序映射htw--->webhits.dll,這是用于Index Server的點(diǎn)擊功能的。盡管你不運(yùn)行Index Server,該映射仍然有效。這個應(yīng)用程序映射存在漏洞,允許入侵者讀取本地硬盤上的文件,數(shù)據(jù)庫文件,和ASP源代碼。
建議: 建議在IIS控制臺中刪除無用的應(yīng)用程序映射
____________________________________________________________________________________
121
類型: 信息型
名字: iirturnh.htw
風(fēng)險等級: 中
描述: IIS4.0上有一個應(yīng)用程序映射htw--->webhits.dll,這是用于Index Server的點(diǎn)擊功能的。盡管你不運(yùn)行Index Server,該映射仍然有效。這個應(yīng)用程序映射存在漏洞,允許入侵者讀取本地硬盤上的文件,數(shù)據(jù)庫文件,和ASP源代碼。
建議: 建議在IIS控制臺中刪除無用的應(yīng)用程序映射
相信認(rèn)真看的朋友會看到,在序號82處,漏了幾十條信息..那也是沒辦法,不是我的問題,我拿到這份資料時就是這樣了...不知道是因?yàn)槟菐资畻l漏洞信息比較有破壞性還是什么原因。。請有識之士補(bǔ)全 :)

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

index.html represents the home page file of the web page and is the default page of the website. When a user visits a website, the index.html page is usually loaded first. HTML (HypertextMarkupLanguage) is a markup language used to create web pages, and index.html is also an HTML file. It contains the structure and content of a web page, as well as tags and elements used for formatting and layout. Here is an example index.html code: <

WindowsServerBackup is a function that comes with the WindowsServer operating system, designed to help users protect important data and system configurations, and provide complete backup and recovery solutions for small, medium and enterprise-level enterprises. Only users running Server2022 and higher can use this feature. In this article, we will explain how to install, uninstall or reset WindowsServerBackup. How to Reset Windows Server Backup If you are experiencing problems with your server backup, the backup is taking too long, or you are unable to access stored files, then you may consider resetting your Windows Server backup settings. To reset Windows

How to modify the default name of nginx, you can disguise it a little, or you can install Tip: Generally, modifications are made before nginx is compiled. After modification, the code needs to be recompiled as follows: scr/core/nginx.conf#definenginx_version"1.4.7"#definenginx_ver"nginx/"n

On the occasion of releasing the build 26040 version of Windows Server, Microsoft announced the official name of the product: Windows Server 2025. Also launched is the Windows11WindowsInsiderCanaryChannel version build26040. Some friends may still remember that many years ago someone successfully converted Windows NT from workstation mode to server mode, showing the commonalities between various versions of Microsoft operating systems. Although there are clear differences between Microsoft's current version of the server operating system and Windows 11, those who pay attention to the details may be curious: why Windows Server updated the brand,

PHP source code running problem: Index error resolution requires specific code examples. PHP is a widely used server-side scripting language that is often used to develop dynamic websites and web applications. However, sometimes you will encounter various problems when running PHP source code, among which "index error" is a common situation. This article will introduce some common causes and solutions of index errors, and provide specific code examples to help readers better deal with such problems. Problem Description: When running a PHP program

While Microsoft released the Win11 preview update for the desktop, today it also released the Windows Server Long Term Service Channel (LTSC) preview Build 25335. As usual, Microsoft did not publish a complete change log, or even provide a corresponding blog post. Microsoft has adjusted the Windows Server preview version update log to make it the same as the Canary channel version. If no new content is introduced, the official blog post will not be posted. Note from IT Home: The server brand has not been updated and is still Windows Server 2022 in the preview version. In addition, Microsoft calls these versions Windows Server vNext instead of the Windows version that is already on the market.

IT House reported on March 14 that in addition to the Windows 11 Build 26080 preview update for the desktop, Microsoft also updated and launched the Windows Server Build 26080 preview update. As the latest preview version of the upcoming Windows Server Long Term Servicing Channel (LTSC), Windows Server Build 26080 provides Data Center Edition and Standard Edition, and users can choose desktop experience and Server Core installation options. This release also includes an annual channel for container hosts, and an Azure release specifically for virtual machine evaluation. IT House queries X social media. User feedback clicks the Copilot button in the lower right corner.

If you need to restart the WindowsServerBackup service, just follow the steps below. You can use a method to start and stop the Windows Server Backup service in almost all versions of Windows Server. Here we will discuss the entire process so that you can easily follow it if needed. How to restart the Windows Server Backup service This process consists of two main stages. First, you should be familiar with how to start the Windows Server Backup service. Next, you can learn the steps on how to stop the service. If the service is already running in the background, you can use another method to kill the process.
