IIS Traffic Capture
The IIS traffic capture (iis_capture.acp) illustrates the traffic generated when a web browser connects to an IIS web server. In this case, however, the browser was used to exploit a vulnerability in the web server. The answers to the questions posed in Chapter 9 are listed below.
The version of the IIS web server is 5.0.
The browser, or UserAgent, used by the client is reported as Netscape 7.0 (see packet 40).
The operating system running on the client is reported as Windows NT 5.1 in packet 40. This is Windows XP.
There were four GET commands issued by the browser (packets 40, 81, 99, and 152).
The vulnerability used against the IIS web server is the directory transversal exploit. This is the same exploit that was used in
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access