WebDAV
Sample Machines
Hack The Box: Granny (10.10.10.15)
Enumeration Tool
davtest
Running this command will give you the result of what can be uploaded.
Upload
cadaver
Then you can do:
If some extensions are not allow, say .exe
, you may try rename the filename to the allowed one first. For example, x.exe
to x.txt
. Then:
Done.
IIS 6 WebDAV exploit
Good one script KO
But it works only for the first time!
Last updated