Security research and public tooling continue to highlight Microsoft IIS short file name disclosure, a long-standing issue in which IIS reveals whether files or directories exist by exposing Windows 8.3 short-name behavior through differential HTTP responses. Research published over several years shows the issue can be triggered with the tilde (~) character and remains observable across multiple IIS generations, including newer versions where detection can be performed with the OPTIONS method rather than GET. The disclosures also noted a related .NET Framework tilde-character denial-of-service condition, while emphasizing that the IIS issue is primarily an information leak that can still materially aid attackers by identifying sensitive files, admin paths, and application structure.
Later work expanded the practical impact by documenting improved enumeration techniques, edge cases involving HTTP.SYS, Kestrel, WAFs, and virtual paths, and methods to distinguish IIS applications, directories, and virtual directories. Researchers also described a way to recover full long file names in some cases when names contain a tilde followed by a digit, extending the value of the leak beyond basic short-name discovery. Open-source tools such as sns and IISRecon have operationalized the technique, allowing defenders and attackers alike to scan exposed IIS servers and brute-force likely paths once short names are identified.
See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
A GitHub issue in the nuclei-templates repository proposed updates to the iis-shortname.yaml template used to detect IIS short file name disclosure. The issue reflects continued maintenance and refinement of public detection logic for the long-known IIS shortname exposure.
A GitHub repository for IISRecon was published, describing a shell-based tool that uses SNS to enumerate IIS shortnames and then brute-force discovered paths recursively with wordlists. The project reflects continued offensive tooling development around IIS shortname exposure.
The 2023 retrospective says newer research presented at SteelCon 2023 advanced understanding of IIS short file name disclosure, including methods to distinguish IIS applications, directories, and virtual directories. It also described a technique to reveal full long file names when the name contains a tilde followed by a digit.
An open-source IIS shortname scanner called SNS, written in Go, was published on GitHub. The tool is intended to detect exposure to IIS shortname enumeration and references the earlier IIS tilde-character research.
The author reported a new technique using the HTTP OPTIONS method to detect IIS short file name disclosure on newer IIS versions. Testing reportedly succeeded against fresh IIS 7.5 on Windows Server 2008 R2 and IIS 8.0 on Windows Server 2012 systems.
Alongside the 2012 disclosure, the researchers published proof-of-concept source code for an IIS Shortname Scanner to detect and demonstrate the short-name disclosure behavior. They also indicated their paper would be updated with workaround and prevention information.
Research published advisories for an IIS short file/folder name disclosure issue triggered with the tilde (~) character and a separate .NET Framework tilde-character denial-of-service issue. The researchers also said they were working with security vendors on mitigation guidance.
According to the 2023 retrospective, the author first identified the IIS short file name (8.3/SFN) disclosure issue on August 1, 2010. The issue allows IIS to leak information about existing files and directories through differential HTTP responses tied to Windows short-name handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcesoroush.me
Open sourcecode.google.com
Open sourcesoroush.secproject.com
Open sourcecoresecurity.com
Open sourcesoroush.secproject.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.