IIS on Windows/NTFS inherits filesystem quirks and a handler-and-config model that produce a distinctive misconfiguration set. Fingerprint it from Server: Microsoft-IIS, the ASP.NET_SessionId cookie, X-AspNet-Version/X-Powered-By: ASP.NET, and default error pages, then work this checklist.
What to check#
- NTFS filename tricks:
::$DATAalternate data streams, trailing dots/spaces, and 8.3 short-name enumeration that disclose source or reveal hidden files. - Decoding: double-decode and overlong Unicode traversal on older IIS, where the path is decoded more than once.
- Handlers and web.config: handler mappings that execute uploads or disclose source, and
web.configbehavior (per-directory config, source exposure, and upload-as-config abuse).
Pages#
- NTFS filename tricks:
::$DATA, trailing dot/space, and short-name enumeration. - Double-decode and Unicode traversal: multi-stage and overlong decoding that smuggles traversal.
- Handlers and web.config: handler mappings, source disclosure, and
web.configabuse.
References#
- Microsoft IIS documentation; NTFS alternate data streams and 8.3 naming
- Soroush Dalili: IIS short-name and ::$DATA research