This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Online IIS Metabase Explorer

From OWASP
Revision as of 15:36, 30 July 2016 by Johanna Curiel (talk | contribs)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search
This page contains out-of-date content. Please help OWASP to FixME.
Last revision (yyyy-mm-dd): 2016-07-31
Comment: The page should be updated.

Online IIS Metabase Explorer is a tool that allows the online browsing of the current IIS Metabase.

This tool clearly shows the current IIS Metabase ACL vulnerability which allows the disclose of the IIS Anonymous users' details (i.e. the username and password) by accounts that belong to the IIS_WPG security group

Screenshot

Metabase Explorer

Metabase Explorer.png