This exploit targets a Denial of Service (DoS) vulnerability in Microsoft IIS by sending malformed URI requests to specific directories (_vti_bin or _sharepoint). The code establishes multiple TCP connections and sends crafted HTTP GET requests to trigger the vulnerability.
Classification
Working Poc 95%
Target:
Microsoft IIS (versions affected by the vulnerability described in the referenced advisory)
No auth needed
Prerequisites:
Network access to the target IIS server · Target server must have the vulnerable directories (_vti_bin or _sharepoint) configured