Authentication bypass

WebDAV authentication frequently has gaps. Basic and Digest credentials are often weak or default; some configurations enforce authentication on GET but not on the WebDAV write methods, so PUT or MOVE succeed unauthenticated; and server implementations have had flaws that expose the DAV interface regardless of configured auth.

bash
# Weak/default Basic auth
curl -u admin:admin -X PROPFIND http://<target>/ -H 'Depth: 1'
# Method gap: GET is protected but PUT is not
curl -X PUT http://<target>/test.txt --data 'x' -i

Exploitation notes#

  • Test whether write methods are protected independently of GET; access-control that only covers read is a common misconfiguration.
  • Try vendor defaults and reused credentials from elsewhere in the environment against the DAV realm.
  • Unauthenticated PUT leads straight to PUT upload to RCE.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more