Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Penetration Testing: Re: IIS 5.0 with Integrated Window Authentication

Re: IIS 5.0 with Integrated Window Authentication

From: Kevin Spett <kspett_at_spidynamics.com>
Date: Wed, 6 Nov 2002 15:50:26 -0500

WebInspect supports NTLM. Your assumption is correct, it's got to be
designed specifically for it.

Kevin Spett
SPI Labs
http://www.spidynamics.com/

----- Original Message -----
From: <cc_mofo_at_hushmail.com>
To: <pen-test_at_securityfocus.com>; <webappsec_at_securityfocus.com>
Sent: Wednesday, November 06, 2002 3:15 PM
Subject: IIS 5.0 with Integrated Window Authentication

>
> -----BEGIN PGP SIGNED MESSAGE-----
>
> I'm doing a security review and penetration test of a site running on IIS
with Integrated Windows Authentication. Anyone know of an IIS Scanner that
can do an IWA exchange before scanning?
>
> The SPIKE proxy looks promising, but it appears the NTLM support is not
quite "there" yet for this purpose. The goofy three-message exchange that
sets up the NTLM security doesn't seem to make it through the proxy, which
leads me to believe that any tool that will work for this must have
intentionally added support for IWA.
>
> -----BEGIN PGP SIGNATURE-----
> Version: Hush 2.2 (Java)
> Note: This signature can be verified at https://www.hushtools.com/verify
>
> wlwEARECABwFAj3JeFQVHGNjX21vZm9AaHVzaG1haWwuY29tAAoJEDsVajchvitlDKIA
> n1atyjW01supq8g9YhQqS3xC013lAJ9BjVmoqZOorkOOFLrjNEns9Ao4qw==
> =O5GH
> -----END PGP SIGNATURE-----
>
>
>
>
> Get your free encrypted email at https://www.hushmail.com
>

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/
Received on Nov 08 2002

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]