Главная
Study mode:
on
1
Intro
2
Have you seen this before?
3
Resolving the HTTPAPI 2.0 404 Error
4
After fixing the host header
5
Accessing an internal admin panel via VHost Hopping ($1900)
6
Accessing the VHost
7
Reap the benefits
8
Typical Local File Disclosure in C#
9
Local file disclosure? web.config is your friend.
10
ASP.NET Viewstate Deserialization
11
Targeting Dependencies
12
Source Code Analysis through DNSpy
13
Navigating through DNSpy
14
Constraints
15
Local DTDs (Attempt 1)
16
Stack Trace But No Love
17
Local DTDs (Attempt 2)
18
Logical fuzzing of files and folders
19
More resources on hacking IIS
Description:
Dive into advanced IIS server hacking techniques in this 22-minute conference talk from NahamCon2021. Explore HTTPAPI 2.0 asset management, VHost hopping, local file disclosure in ASP.NET MVC applications, and complex XXE vectors. Learn to resolve 404 errors, access internal admin panels, leverage web.config files, and perform source code analysis using DNSpy. Discover logical fuzzing techniques for files and folders, and gain insights into ASP.NET Viewstate deserialization and targeting dependencies. Perfect for security professionals looking to enhance their IIS hacking skills.

Hacking IIS

NahamSec
Add to list
0:00 / 0:00