Why I love hacking IIS servers: - Case insensitive, amazing for content discovery - IIS Shortname - VIEWSTATE deserialization RCE gadget - Web.config upload tricks - Debug mode w/ detailed stack traces and full path - Debugging scripts often deployed (ELMAH, Trace) - Telerik RCE
Replying to @infosec_au
do you know you can easily create a error page by requesting /nul: - easy way to test if remote debug logging is disabled without depending on anything custom.
4:01 PM - 20 Dec 2020
0 replies
4 retweets
59 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.