CGI安全漏洞資料速查 v1.0(轉(zhuǎn)四)
Jun 21, 2016 am 09:12 AMcgi|安全|安全漏洞
76
類型: 攻擊型
名字: aexp.htr
風(fēng)險(xiǎn)等級(jí): 中
描述: 在/iisadmpwd目錄下存在aexp.htr文件,類似的還有aexp2.htr,aexp3.htr和aexp4b.htr等,這些文件允許攻擊者用窮舉法等方式破解和修改NT用戶的密碼。
建議: 建議禁止對(duì)/iisadmpwd目錄的訪問
解決方法: 刪除aexp.htr文件
____________________________________________________________________________________
77
類型: 攻擊型
名字: aexp2.htr
風(fēng)險(xiǎn)等級(jí): 中
描述: 在/iisadmpwd目錄下存在aexp2.htr文件,類似的還有aexp2.htr,aexp3.htr和aexp4b.htr等,這些文件允許攻擊者用窮舉法等方式破解和修改NT用戶的密碼。
建議: 建議禁止對(duì)/iisadmpwd目錄的訪問
解決方法: 刪除aexp2.htr文件
_______________________________________________________________________________________
78
類型: 攻擊型
名字: aexp3.htr
風(fēng)險(xiǎn)等級(jí): 中
描述: 在/iisadmpwd目錄下存在aexp3.htr文件,類似的還有aexp2.htr,aexp3.htr和aexp4b.htr等,這些文件允許攻擊者用窮舉法等方式破解和修改NT用戶的密碼。
建議: 建議禁止對(duì)/iisadmpwd目錄的訪問
解決方法: 刪除aexp3.htr文件
_________________________________________________________________________________________
79
類型: 攻擊型
名字: aexp4b.htr
風(fēng)險(xiǎn)等級(jí): 中
描述: 在/iisadmpwd目錄下存在aexp4b.htr文件,類似的還有aexp2.htr,aexp3.htr和aexp4b.htr等,這些文件允許攻擊者用窮舉法等方式破解和修改NT用戶的密碼。
建議: 建議禁止對(duì)/iisadmpwd目錄的訪問
解決方法: 刪除aexp4b.htr文件
____________________________________________________________________________________
80
類型: 攻擊型
名字: achg.htr
風(fēng)險(xiǎn)等級(jí): 中
描述: 在/iisadmpwd目錄下存在aechg.htr文件,類似的還有aexp2.htr,aexp3.htr和aexp4b.htr等,這些文件允許攻擊者用窮舉法等方式破解和修改NT用戶的密碼。
建議: 建議禁止對(duì)/iisadmpwd目錄的訪問
解決方法: 刪除achg.htr文件
____________________________________________________________________________________
81
類型: 攻擊型
名字: ExprCale.cfm
風(fēng)險(xiǎn)等級(jí): 中
描述: 在Coldfusion的web目錄: /cfdocs/expeval/ExprCalc.cfm文件,這個(gè)文件有個(gè)漏洞允許用戶讀取服務(wù)器硬盤上的任意文件包括用戶密碼數(shù)據(jù)庫(kù)sam文件
建議: 刪除相關(guān)的文件
解決方法: 刪除ExprCalc.cfm文件
_______________________________________________________________________________________
82
類型: 攻擊型
名字: getfile.cfm
風(fēng)險(xiǎn)等級(jí): 中
描述: 在Coldfusion的web目錄: /getfile.cfm文件,這個(gè)文件有個(gè)漏洞允許用戶讀取服務(wù)器硬盤上的任意文件包括用戶密碼數(shù)據(jù)庫(kù)sam文件
建議: 刪除相關(guān)的文件
解決方法: 刪除getfile.cfm文件
_______________________________________________________________________________
119
類型: 信息型
名字: x.htw
風(fēng)險(xiǎn)等級(jí): 中
描述: IIS4.0上有一個(gè)應(yīng)用程序映射htw--->webhits.dll,這是用于Index Server的點(diǎn)擊功能的。盡管你不運(yùn)行Index Server,該映射仍然有效。這個(gè)應(yīng)用程序映射存在漏洞,允許入侵者讀取本地硬盤上的文件,數(shù)據(jù)庫(kù)文件,和ASP源代碼。
建議:
建議在IIS控制臺(tái)中刪除無(wú)用的應(yīng)用程序映射
________________________________________________________________________________
120
類型: 信息型
名字: qfullhit.htw
風(fēng)險(xiǎn)等級(jí): 中
描述: IIS4.0上有一個(gè)應(yīng)用程序映射htw--->webhits.dll,這是用于Index Server的點(diǎn)擊功能的。盡管你不運(yùn)行Index Server,該映射仍然有效。這個(gè)應(yīng)用程序映射存在漏洞,允許入侵者讀取本地硬盤上的文件,數(shù)據(jù)庫(kù)文件,和ASP源代碼。
建議: 建議在IIS控制臺(tái)中刪除無(wú)用的應(yīng)用程序映射
____________________________________________________________________________________
121
類型: 信息型
名字: iirturnh.htw
風(fēng)險(xiǎn)等級(jí): 中
描述: IIS4.0上有一個(gè)應(yīng)用程序映射htw--->webhits.dll,這是用于Index Server的點(diǎn)擊功能的。盡管你不運(yùn)行Index Server,該映射仍然有效。這個(gè)應(yīng)用程序映射存在漏洞,允許入侵者讀取本地硬盤上的文件,數(shù)據(jù)庫(kù)文件,和ASP源代碼。
建議: 建議在IIS控制臺(tái)中刪除無(wú)用的應(yīng)用程序映射
相信認(rèn)真看的朋友會(huì)看到,在序號(hào)82處,漏了幾十條信息..那也是沒辦法,不是我的問題,我拿到這份資料時(shí)就是這樣了...不知道是因?yàn)槟菐资畻l漏洞信息比較有破壞性還是什么原因。。請(qǐng)有識(shí)之士補(bǔ)全 :)

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

index.html represents the home page file of the web page and is the default page of the website. When a user visits a website, the index.html page is usually loaded first. HTML (HypertextMarkupLanguage) is a markup language used to create web pages, and index.html is also an HTML file. It contains the structure and content of a web page, as well as tags and elements used for formatting and layout. Here is an example index.html code: <

WindowsServerBackup is a function that comes with the WindowsServer operating system, designed to help users protect important data and system configurations, and provide complete backup and recovery solutions for small, medium and enterprise-level enterprises. Only users running Server2022 and higher can use this feature. In this article, we will explain how to install, uninstall or reset WindowsServerBackup. How to Reset Windows Server Backup If you are experiencing problems with your server backup, the backup is taking too long, or you are unable to access stored files, then you may consider resetting your Windows Server backup settings. To reset Windows

How to modify the default name of nginx, you can disguise it a little, or you can install Tip: Generally, modifications are made before nginx is compiled. After modification, the code needs to be recompiled as follows: scr/core/nginx.conf#definenginx_version"1.4.7"#definenginx_ver"nginx/"n

On the occasion of releasing the build 26040 version of Windows Server, Microsoft announced the official name of the product: Windows Server 2025. Also launched is the Windows11WindowsInsiderCanaryChannel version build26040. Some friends may still remember that many years ago someone successfully converted Windows NT from workstation mode to server mode, showing the commonalities between various versions of Microsoft operating systems. Although there are clear differences between Microsoft's current version of the server operating system and Windows 11, those who pay attention to the details may be curious: why Windows Server updated the brand,

PHP source code running problem: Index error resolution requires specific code examples. PHP is a widely used server-side scripting language that is often used to develop dynamic websites and web applications. However, sometimes you will encounter various problems when running PHP source code, among which "index error" is a common situation. This article will introduce some common causes and solutions of index errors, and provide specific code examples to help readers better deal with such problems. Problem Description: When running a PHP program

While Microsoft released the Win11 preview update for the desktop, today it also released the Windows Server Long Term Service Channel (LTSC) preview Build 25335. As usual, Microsoft did not publish a complete change log, or even provide a corresponding blog post. Microsoft has adjusted the Windows Server preview version update log to make it the same as the Canary channel version. If no new content is introduced, the official blog post will not be posted. Note from IT Home: The server brand has not been updated and is still Windows Server 2022 in the preview version. In addition, Microsoft calls these versions Windows Server vNext instead of the Windows version that is already on the market.

If you need to restart the WindowsServerBackup service, just follow the steps below. You can use a method to start and stop the Windows Server Backup service in almost all versions of Windows Server. Here we will discuss the entire process so that you can easily follow it if needed. How to restart the Windows Server Backup service This process consists of two main stages. First, you should be familiar with how to start the Windows Server Backup service. Next, you can learn the steps on how to stop the service. If the service is already running in the background, you can use another method to kill the process.

Server matching logic When nginx determines which server block to execute a request, it mainly focuses on the listen and server_name fields in the server block. The listen command listen field defines the IP and port of the server response. If the listen field is not explicitly configured, the default listening 0.0.0.0:80 (root) or 0.0.0.0:8080 (non-root) listen can be configured as: a combination of ip and port, a single ip, listening on port 80 by default, a single port, and listening on all ip interfaces by default A unixsocket path where the last entry is usually only used in different
