Fingerprinting IIS

  You can analyze the responses sent from a webserver to determine the version of IIS running (And in turn the version of the Windows Server). I have seen a lot of people discuss this. So here is my guide … The easiest way is to capture a network trace or Fiddler trace and analyze…


MIB OIDs for IIS 6.0

Here is a list of the OID values related to IIS that you can query using SNMP.     TotalBytesSent_HighWord 1.3.6.1.4.1.311.1.7.3.1.1.0 TotalBytesSent_LowWord 1.3.6.1.4.1.311.1.7.3.1.2.0 TotalBytesReceived_HighWord 1.3.6.1.4.1.311.1.7.3.1.3.0 TotalBytesReceived_LowWord 1.3.6.1.4.1.311.1.7.3.1.4.0 TotalFilesSent 1.3.6.1.4.1.311.1.7.3.1.5.0 TotalFilesReceived 1.3.6.1.4.1.311.1.7.3.1.6.0 CurrentAnonymousUsers 1.3.6.1.4.1.311.1.7.3.1.7.0 CurrentNonAnonymousUsers 1.3.6.1.4.1.311.1.7.3.1.8.0 TotalAnonymousUsers 1.3.6.1.4.1.311.1.7.3.1.9.0 TotalNonAnonymousUsers 1.3.6.1.4.1.311.1.7.3.1.10.0 MaxAnonymousUsers 1.3.6.1.4.1.311.1.7.3.1.11.0 MaxNonAnonymousUsers 1.3.6.1.4.1.311.1.7.3.1.12.0 CurrentConnections 1.3.6.1.4.1.311.1.7.3.1.13.0 MaxConnections 1.3.6.1.4.1.311.1.7.3.1.14.0 ConnectionAttempts 1.3.6.1.4.1.311.1.7.3.1.15.0 LogonAttempts 1.3.6.1.4.1.311.1.7.3.1.16.0 TotalOptions 1.3.6.1.4.1.311.1.7.3.1.17.0 TotalGets 1.3.6.1.4.1.311.1.7.3.1.18.0…