Browsed by
Tag: Windows Server

Create certificate request with SHA256 on IIS 7

Create certificate request with SHA256 on IIS 7

Creating a CSR (or Certificate Singing Request) on an IIS 7 is pretty straight forward, but you end up with a request which uses the old SHA1 hashing method. Your certificate request will work, but the end result will be that your site might be vulnerable to SSL/TLS related attacks. So how to create a CSR that uses the SHA256 algorithm? All the information bellow can be found on ServerFault. First make a request.inf file. (Just use a text editor…

Read More Read More

Enable web deploy on IIS 8 running on 2012 R2

Enable web deploy on IIS 8 running on 2012 R2

Web deploy enables a developer (or anyone with sufficient privileges) to build and deploy a website using visual studio or via the command line using MSBuild. An example of such a build command can be found in my previous posts. We use it mainly in our continuous integration environment to automatically build, test and deploy new code if a new commit to the git master branch was detected. Installation via web platform installer First you will need administrator rights to…

Read More Read More

Shell detector app detects webshells (aspx, php)

Shell detector app detects webshells (aspx, php)

Shell detector is a great little application to, like the name suggests, detect (malicious) shells. I recently had the misfortune of having to deal with a so called web shell. Basically it created a backdoor by uploading a malicious file and its client application uses this file to send commands to be executed on the server. Looking at the capabilities of this malware I couldn’t believe what was possible. In short they owned the server. Now I know that the…

Read More Read More