Find Jobs
Hire Freelancers

IIS Tilder Vulnerebility "~" Fix on Azure

$10-30 USD

Closed
Posted over 4 years ago

$10-30 USD

Paid on delivery
I'm writting a website and right now doing the penetration test. However my test keep failed on the windows short file disclosure issue. You can refer the link as i posted [login to view URL] Each time enter [login to view URL]*~1, my IIS will return Error 404 instead of custom error page. My client is using Azure VM Server 2012R2 and running IIS 8.5 at the moment. I've tried the following: 1. Deny URL sequence with "~" in Request Filtering in IIS. 2. Used URL rewrite with pattern (^[^\?]\~.\?.$)|(^[^\?]\~.*$), action: Abort Request 3. Tried URLScan 3.1 but seem no more working for IIS 8.5. 4. Tried with new project and create only 1 html file for test. 5. Disabled NtfsDisable8dot3NameCreation under registry. 6. Scanned c:\inetpub and there is 0 window short file name. 7. Run windows update All above with no luck. If you got better solution, please let me know and i will reward you. Attached with my [login to view URL] file for your reference.
Project ID: 23519780

About the project

2 proposals
Remote project
Active 4 yrs ago

Looking to make some money?

Benefits of bidding on Freelancer

Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
2 freelancers are bidding on average $25 USD for this job
User Avatar
Hi I'm able to test it in my Lab. Have you tried setting errorMode to "Custom" on IIS server instead of site. If you can share your screen I can try to fix the issue.
$20 USD in 1 day
5.0 (21 reviews)
4.4
4.4
User Avatar
Hi, can I help you with your project? I have experience in -Administration / management of systems and security in Linux, Windows Kali Linux Pentesting nmap metaesploit -Development of Java, VB.NET, PHP, SQL, MySQL, POSTGRESQL applications. -Virtualization VMware, Hyper-v -Design and implementation of Zimbra mail servers. - CUCM ip telephony -Graphic design -Creation of professional websites (wordpress, joomla, prestashop, etc.)
$30 USD in 7 days
5.0 (1 review)
1.0
1.0

About the client

Flag of MALAYSIA
Kuala Lumpur, Malaysia
0.0
0
Payment method verified
Member since Feb 13, 2015

Client Verification

Thanks! We’ve emailed you a link to claim your free credit.
Something went wrong while sending your email. Please try again.
Registered Users Total Jobs Posted
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Loading preview
Permission granted for Geolocation.
Your login session has expired and you have been logged out. Please log in again.