module

Microsoft IIS HTTP Internal IP Disclosure

Disclosed
N/A

Description

Collect any leaked internal IPs by requesting commonly redirected locations from IIS.
CVE-2000-0649 references IIS 5.1 (win2k, XP) and older. However, in newer servers
such as IIS 7+, this occurs when the alternateHostName is not set or misconfigured. Also
collects internal IPs leaked from the PROPFIND method in certain IIS versions.
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.