#Microsoft IIS WebDAV(HTTP Extensions for Distributed Authoring-RFC 2518) Run , Check rule (remote exploitable) # # #more information, patch #http://www.microsoft.com/technet/security/bulletin/MS03-007.asp #http://www.microsoft.com/korea/technet/security/bulletin/MS03-007.asp # #NOTE: #COPY,LOCK,UNLOCK are comment in default # #rule by pilot 2003/03 # # # #IIS WebDAV methods: DELETE, PUT, COPY, MOVE, MKCOL, PROPFIND, PROPPATCH, LOCK, UNLOCK, SEARCH # 403 Forbidden-> DELETE :/arirang_check ^IIS WebDAV DELETE method check;; 403 Forbidden-> PUT :/arirang_check ^IIS WebDAV PUT method check;; #400 Bad Request-> COPY :/arirang_check ^IIS WebDAV COPY method check;; 403 Forbidden-> MOVE :/arirang_check ^IIS WebDAV MOVE method check;; 403 Forbidden-> MKCOL :/arirang_check ^IIS WebDAV MKCOL method check;; 411 Length Required-> PROPFIND :/arirang_check ^IIS WebDAV PROPFIND method check;; 403 Forbidden-> PROPPATCH :/arirang_check ^IIS WebDAV PROPPATCH method check;; #LOCKing a collection -> LOCK :/arirang_check ^IIS WebDAV LOCK method check;; #400 Bad Request-> UNLOCK :/arirang_check ^IIS WebDAV UNLOCK method check;; 411 Length Required-> SEARCH :/arirang_check ^IIS WebDAV SEARCH method check;;