WebDAV extends HTTP with methods (PROPFIND, MKCOL, PUT, MOVE, COPY) that let clients manage files on the server, implemented by IIS WebDAV and Apache mod_dav. It is attacked by discovering it and its allowed methods, bypassing weak authentication, traversing outside its root, and, most directly, using PUT to upload an executable file.
Subtopics#
- Discovery and methods: detecting DAV and its allowed methods.
- Authentication bypass: reaching DAV past weak auth.
- Directory traversal: escaping the DAV root.
- PUT upload to RCE: uploading a web shell.