IIS
Fuzzing
/trace.axd
/trace.axd?id=1
/admin/help.cgi
/admin/help.cgi.bak
/admin/WS_FTP.LOG
/adovbs.inc
/confirm.asp.bak
/default.asp.bak
/login.asp.bak
/pindex.asp.bak
/rootlogin.asp.bak
/rootlogin.asp.old
/_vti_pvt/service.cnf
/include/common.inc
/WS_FTP.LOG
/service.cnf
/_vti_pvt/service.cnf
/aspnet_client
/global.asax
/msdeploy.axd
/msdeploy.axd <-- check CVE-2025-53772trace.axd enable
Information disclosure
PUT methode enabled
Insecure Upload File
Website using PHP
web.config or web.xml
Viewstate
Internal IP disclosure
Tilde Enumeration
IIs Tilde Enumration Scanner - Burp Extension


Nuclei Template
ShortScan
IIS ShortName Scanner

Generate Wordlist
Fuzzing
XSS
XSSCVE-2025-53772 IIS WebDeploy RCE
Resources
Script to configure IIS
Privilege Escalation



Interesting Books
Interesting BooksLast updated