<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.1.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Xprobe2</title>
	<link>http://secure2s.net/tools/2006/06/23/xprobe2/</link>
	<description>Secure2S Security Tool Sets Blog</description>
	<pubDate>Thu, 20 Nov 2008 10:04:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.1.2</generator>

	<item>
		<title>By: ha.ckers.org security lab - Archive &#187; Finding 404s despite ErrorDocuments and fingerprinting IIS6.0</title>
		<link>http://secure2s.net/tools/2006/06/23/xprobe2/#comment-3</link>
		<author>ha.ckers.org security lab - Archive &#187; Finding 404s despite ErrorDocuments and fingerprinting IIS6.0</author>
		<pubDate>Mon, 26 Jun 2006 21:05:33 +0000</pubDate>
		<guid>http://secure2s.net/tools/2006/06/23/xprobe2/#comment-3</guid>
					<description>[...] As you can see, they are wildly different, despite the fact that the Apache instance above had an ErrorDocument. I have not been able to validate against the same type of error handling under IIS but based on this, I don&#8217;t believe IIS would handle the request at all, seeing it entirely as invalid (a 400 error instead of a 404 error). This could easily allow you to fingerprint a machine between IIS and Apache alone on a single malformed request, which could easily be built into httprint, xprobe or nmap or other similar tools. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] As you can see, they are wildly different, despite the fact that the Apache instance above had an ErrorDocument. I have not been able to validate against the same type of error handling under IIS but based on this, I don&#8217;t believe IIS would handle the request at all, seeing it entirely as invalid (a 400 error instead of a 404 error). This could easily allow you to fingerprint a machine between IIS and Apache alone on a single malformed request, which could easily be built into httprint, xprobe or nmap or other similar tools. [&#8230;]</p>
]]></content:encoded>
				</item>
</channel>
</rss>
