Discovery and methods

The first step is confirming WebDAV and learning what it allows. An OPTIONS request returns the DAV header and the Allow list of methods, and PROPFIND lists resources. Tools then probe which extensions can be uploaded and executed in each writable directory, which determines whether the server is exploitable through PUT.

bash
curl -s -X OPTIONS http://<target>/ -i | grep -iE 'DAV|Allow'
curl -s -X PROPFIND http://<target>/ -H 'Depth: 1' --data ''   # list resources
davtest -url http://<target>/                                   # test uploadable/executable types

Exploitation notes#

  • The Allow header reveals whether PUT, MOVE, DELETE, and MKCOL are available, shaping the attack.
  • davtest reports which file types upload successfully and which then execute, directly flagging the RCE path.
  • A directory that accepts PUT is the target for PUT upload to RCE; MOVE can rename a disallowed extension to an executable one.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more