Nessus Plugin #12113

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Private IP address Leaked using the PROPFIND method

Family:
General
Category:
infos
Copyright:
This script is Copyright (C) Sword & Shield Enterprise Security, Inc., 2004
Summary:
Checks for private IP addresses in PROPFIND response
Version:
$Revision: 1.5 $
Cve_id:
CAN-2002-0422
Bugtraq_id:
-
Xrefs:
-
Description:

The remote web server leaks a private IP address through the WebDAV interface. If this
web server is behind a Network Address Translation (NAT) firewall or proxy server, then
the internal IP addressing scheme has been leaked.

This is typical of IIS 5.0 installations that are not configured properly.

Detail: http://www.nextgenss.com/papers/iisrconfig.pdf

Solution: see http://support.microsoft.com/default.aspx?scid=KB%3BEN-US%3BQ218180&ID=KB%3BEN-US%3BQ218180
Risk factor : Low
Generiert am 27.04.2005 um 18:49:54 Uhr.