Microsoft IIS Various Domain User...

- AV AC AU C I A
发布: 2001-05-14
修订: 2025-04-13

Microsoft IIS contains a flaw in the handling of FTP domain authentication. A user attempting to authenticate using a valid login name appended with specially chosen characters, will not be required to specify the domain which the account belongs. The FTP service will instead search the domain and all trusted domains for the user account. Once the account is located, the user will have to complete the authentication process. At this point brute force attacks can be used in an attempt to gain access to the domain.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息