[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4uHD_CNgKvyY46VA5l0dlrFRZPlKOSehMq5PI0_oALk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},115,"What are the recommended methods to detect an IIS module backdoor?","Detection focuses on inspecting the list of installed modules. Using `APPCMD.EXE list module` from the command line or checking Modules in IIS Manager (inetmgr.exe) will reveal any suspicious entries. Since module DLLs reside in the w3wp.exe process, memory analysis can also identify abnormal loaded modules. Regular audits of module configurations and file integrity checks on the DLLs are effective defenses. For more on bypassing controls, see [Testing and Analysis of Bypassing AppLocker Using LUA Scripts](\u002Fnews\u002Ftesting-and-analysis-of-bypassing-applocker-using-lua-scripts).","\u003Cp>Detection focuses on inspecting the list of installed modules. Using `APPCMD.EXE list module` from the command line or checking Modules in IIS Manager (inetmgr.exe) will reveal any suspicious entries. Since module DLLs reside in the w3wp.exe process, memory analysis can also identify abnormal loaded modules. Regular audits of module configurations and file integrity checks on the DLLs are effective defenses. For more on bypassing controls, see [Testing and Analysis of Bypassing AppLocker Using LUA Scripts](\u002Fnews\u002Ftesting-and-analysis-of-bypassing-applocker-using-lua-scripts).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fbypassing-firewalls-using-iis-module-functionality\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-recommended-methods-to-detect-an-iis-module-backdoor-1777485170621","IIS backdoor detection, APPCMD list module, w3wp.exe process, module audit, defense",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},30,"Bypassing Firewalls Using IIS Module Functionality","bypassing-firewalls-using-iis-module-functionality","Learn to bypass firewalls using IIS module functionality for remote server management. Explore C++ and C# module development, testing with IIS-Raid, and defense strategies.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Bypassing Firewalls Using IIS Port Sharing Functionality', the following problem was addressed:\u003C\u002Fp>\u003Cp>Windows servers have IIS service enabled, and the firewall only allows communication through port 80 or 443. How can remote management of this server be achieved without using webshells? Furthermore, if only low privileges are available, is there a way?\u003C\u002Fp>\u003Cp>This article will introduce another solution to the above problem: bypassing firewalls using IIS module functionality.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>IIS Module Functionality\u003C\u002Fli>\u003Cli>Developing Modules Using C++\u003C\u002Fli>\u003Cli>Developing Modules Using C#\u003C\u002Fli>\u003Cli>IIS-Raid Testing\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003Cli>Defense and Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 IIS Module Functionality\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Starting from IIS7, developers can extend IIS functionality through the Module feature\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-gb\u002Fiis\u002Fdevelop\u002Fruntime-extensibility\u002Fextending-web-server-functionality-in-net\u003C\u002Fp>\u003Cp>If we can read HTTP request content and control HTTP response content via the module functionality, it is entirely possible to achieve remote server management using modules\u003C\u002Fp>\u003Cp>IIS modules exist in the form of DLLs and do not run as separate processes after loading\u003C\u002Fp>\u003Cp>In 2018, PaloAlto Unit42 discovered APT34 using this method as an IIS backdoor, naming it RGDoor\u003C\u002Fp>\u003Cp>This article will replicate some functionalities of RGDoor, focusing on detection and identification of this exploitation method\u003C\u002Fp>\u003Ch2>0x03 Developing Modules with C++\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-gb\u002Fiis\u002Fdevelop\u002Fruntime-extensibility\u002Fdevelop-a-native-cc-module-for-iis\u003C\u002Fp>\u003Cp>IIS 7.0 and later versions allow server extension through modules developed in two ways:\u003C\u002Fp>\u003Cul>\u003Cli>Managed Modules, using managed code and ASP.NET server extensibility APIs\u003C\u002Fli>\u003Cli>Native Module, using native code and IIS native server extensibility API\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The reference materials introduce the usage of Native Module\u003C\u002Fp>\u003Cp>Pay attention to the following issues:\u003C\u002Fp>\u003Cul>\u003Cli>Can be developed using Visual Studio\u003C\u002Fli>\u003Cli>DLL must contain the exported function RegisterModule\u003C\u002Fli>\u003Cli>Use CHttpModule as the implementation for module class inheritance\u003C\u002Fli>\u003Cli>Use the IHttpModuleFactory interface to create module instances\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Module Development\u003C\u002Fh3>\u003Cp>For specific implementation code, refer to IIS-Raid, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002F0x09AL\u002FIIS-Raid\u003C\u002Fp>\u003Cp>For code details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.mdsec.co.uk\u002F2020\u002F02\u002Fiis-raid-backdooring-iis-using-native-modules\u002F\u003C\u002Fp>\u003Cp>IIS-Raid registers two events, RQ_BEGIN_REQUEST and RQ_SEND_RESPONSE, in the RegisterModule function to handle requests and responses\u003C\u002Fp>\u003Ch3>2. Module Registration\u003C\u002Fh3>\u003Cp>Choose from the following three methods:\u003C\u002Fp>\u003Col>\u003Cli>Using the APPCMD.EXE command-line tool\u003C\u002Fli>\u003Cli>Using the IIS Administration Tool for GUI operations\u003C\u002Fli>\u003Cli>Modifying the configuration file applicationHost.config\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Method 1 and Method 2 will be demonstrated in 0x05\u003C\u002Fp>\u003Ch2>0x04 Developing modules using C#\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-gb\u002Fiis\u002Fdevelop\u002Fruntime-extensibility\u002Fdeveloping-a-module-using-net\u003C\u002Fp>\u003Cp>IIS 7.0 and later versions allow extending the server through modules developed in two ways:\u003C\u002Fp>\u003Cul>\u003Cli>Managed Module, using managed code and ASP.NET server extensibility APIs\u003C\u002Fli>\u003Cli>Native Module, using native code and IIS native server extensibility APIs\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The reference introduces the usage of Managed Modules\u003C\u002Fp>\u003Cp>Pay attention to the following issues:\u003C\u002Fp>\u003Cul>\u003Cli>Can be developed using Visual Studio\u003C\u002Fli>\u003Cli>Is a .NET class\u003C\u002Fli>\u003Cli>Uses the System.Web.IHttpModule interface\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Module Development\u003C\u002Fh3>\u003Cp>For specific implementation code, refer to IIS_backdoor at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FWBGlIl\u002FIIS_backdoor\u003C\u002Fp>\u003Cp>For code details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmp.weixin.qq.com\u002Fs\u002Fz1d3yvp14GWakyonTh_b8A\u003C\u002Fp>\u003Ch3>2. Module Registration\u003C\u002Fh3>\u003Cp>You can choose from the following three methods:\u003C\u002Fp>\u003Col>\u003Cli>Using the APPCMD.EXE command-line tool\u003C\u002Fli>\u003Cli>Using the IIS Administration Tool for interface operations\u003C\u002Fli>\u003Cli>Modifying the configuration file web.config\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For specific usage methods, you can also refer to the following materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-gb\u002Fiis\u002Fdevelop\u002Fruntime-extensibility\u002Fdeveloping-iis-modules-and-handlers-with-the-net-framework\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Faspnet\u002Fms227673(v=vs.100)\u003C\u002Fp>\u003Ch2>0x05 IIS-Raid Test\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System:\u003C\u002Fp>\u003Cp>Windows Server 2012r2 x64 (Administrator privileges required)\u003C\u002Fp>\u003Cp>IIS-Raid address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002F0x09AL\u002FIIS-Raid\u003C\u002Fp>\u003Cp>Compile and generate IIS-Backdoor.dll using Visual Studio\u003C\u002Fp>\u003Ch3>1. Backdoor Installation\u003C\u002Fh3>\u003Cp>You can choose one of the following two methods:\u003C\u002Fp>\u003Ch4>(1) Using the APPCMD.EXE command-line tool\u003C\u002Fh4>\u003Cp>The command to view installed modules is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\system32\\inetsrv\\APPCMD.EXE list module\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019798500_0_4bdfae9bbf.jpeg\">\u003C\u002Fp>\u003Cp>The command to install the module is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\system32\\inetsrv\\APPCMD.EXE install module \u002Fname:test \u002Fimage:\"c:\\test\\IIS-Backdoor.dll\" \u002Fadd:true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to delete the module is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\system32\\inetsrv\\APPCMD.EXE uninstall module test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using the IIS Administration Tool for interface operations\u003C\u002Fh4>\u003Cp>Run inetmgr.exe to enter the IIS Manager\u003C\u002Fp>\u003Cp>Select Modules, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019811108_1_760e6532f7.jpeg\">\u003C\u002Fp>\u003Cp>After entering, select Configure Native Modules..., then select Register..., as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019822902_2_1421ab4f51.jpeg\">\u003C\u002Fp>\u003Cp>Fill in the Name and Path, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019833530_3_e7ddbbebde.jpeg\">\u003C\u002Fp>\u003Cp>After successful addition, the newly added content is displayed on the Modules page, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019853643_4_20e942f409.jpeg\">\u003C\u002Fp>\u003Ch3>2. Function Testing\u003C\u002Fh3>\u003Cp>The configuration file for IIS-Raid is saved in Functions.h, including the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#define COM_HEADER \"X-Chrome-Variations\"\u003Cbr>#define PASS_FILE \"C:\\\\Windows\\\\Temp\\\\creds.db\"\u003Cbr>#define PASSWORD \"SIMPLEPASS\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>COM_HEADER is the header name used for communication between the backdoor and the controller\u003C\u002Fp>\u003Cp>PASS_FILE is the location where the dump command reads the file\u003C\u002Fp>\u003Cp>PASSWORD defines the password that will be used for authentication to the backdoor\u003C\u002Fp>\u003Ch4>(1) Connect to the backdoor\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python .\u002Fiis_controller.py --url http:\u002F\u002F192.168.18.138\u002F --password SIMPLEPASS\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019864613_5_a5c510d0f9.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Test functionality\u003C\u002Fh4>\u003Cp>Execute the cmd command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cmd whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019868303_6_b54c2428cc.jpeg\">\u003C\u002Fp>\u003Cp>Execute the dump command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dump\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default reads the contents of the file C:\\\\Windows\\\\Temp\\\\creds.db\u003C\u002Fp>\u003Cp>Test as shown in Figure 3-3\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019871554_7_8b09eacbd4.jpeg\">\u003C\u002Fp>\u003Cp>Execute shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>inject shellcode.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>shellcode.txt stores the base64-encrypted shellcode, loaded by first creating the process C:\\\\Windows\\\\System32\\\\credwiz.exe, then injecting\u003C\u002Fp>\u003Cp>Test as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019875534_8_a743f33ec9.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Using the IIS module as a backdoor has the following characteristics:\u003C\u002Fp>\u003Cul>\u003Cli>Requires obtaining administrator privileges on the IIS server first\u003C\u002Fli>\u003Cli>Payload in DLL form\u003C\u002Fli>\u003Cli>Launched through module installation\u003C\u002Fli>\u003Cli>DLL resides in w3wp.exe process\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Detect whether IIS has been backdoored by checking Modules\u003C\u002Fp>\u003Cp>Two specific methods:\u003C\u002Fp>\u003Ch4>1. Using APPCMD.EXE command-line tool\u003C\u002Fh4>\u003Cp>Command to view installed modules:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\system32\\inetsrv\\APPCMD.EXE list module\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Using IIS Administration Tool for GUI operation\u003C\u002Fh4>\u003Cp>Run inetmgr.exe to enter IIS Manager\u003C\u002Fp>\u003Cp>Select Modules\u003C\u002Fp>\u003Cp>Note: Module-related DLLs can only be found in w3wp.exe process after successful module loading\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the functionality of IIS modules, demonstrates bypassing firewalls using IIS module features, tests the open-source tool IIS-Raid, and shares recommendations for defense and detection.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Bypassing Firewalls Using IIS Port Sharing Functionality', the following problem was addressed:\u003C\u002Fp>\u003Cp>Windows servers have IIS service enabled, and the firewall only allows communication through port 80 or 443. How can remote management of this server be achieved without using webshells? Furthermore, if only low privileges are available, is there a way?\u003C\u002Fp>\u003Cp>This article will introduce another solution to the above problem: bypassing firewalls using IIS module functionality.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>IIS Module Functionality\u003C\u002Fli>\u003Cli>Developing Modules Using C++\u003C\u002Fli>\u003Cli>Developing Modules Using C#\u003C\u002Fli>\u003Cli>IIS-Raid Testing\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003Cli>Defense and Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 IIS Module Functionality\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Starting from IIS7, developers can extend IIS functionality through the Module feature\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-gb\u002Fiis\u002Fdevelop\u002Fruntime-extensibility\u002Fextending-web-server-functionality-in-net\u003C\u002Fp>\u003Cp>If we can read HTTP request content and control HTTP response content via the module functionality, it is entirely possible to achieve remote server management using modules\u003C\u002Fp>\u003Cp>IIS modules exist in the form of DLLs and do not run as separate processes after loading\u003C\u002Fp>\u003Cp>In 2018, PaloAlto Unit42 discovered APT34 using this method as an IIS backdoor, naming it RGDoor\u003C\u002Fp>\u003Cp>This article will replicate some functionalities of RGDoor, focusing on detection and identification of this exploitation method\u003C\u002Fp>\u003Ch2>0x03 Developing Modules with C++\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-gb\u002Fiis\u002Fdevelop\u002Fruntime-extensibility\u002Fdevelop-a-native-cc-module-for-iis\u003C\u002Fp>\u003Cp>IIS 7.0 and later versions allow server extension through modules developed in two ways:\u003C\u002Fp>\u003Cul>\u003Cli>Managed Modules, using managed code and ASP.NET server extensibility APIs\u003C\u002Fli>\u003Cli>Native Module, using native code and IIS native server extensibility API\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The reference materials introduce the usage of Native Module\u003C\u002Fp>\u003Cp>Pay attention to the following issues:\u003C\u002Fp>\u003Cul>\u003Cli>Can be developed using Visual Studio\u003C\u002Fli>\u003Cli>DLL must contain the exported function RegisterModule\u003C\u002Fli>\u003Cli>Use CHttpModule as the implementation for module class inheritance\u003C\u002Fli>\u003Cli>Use the IHttpModuleFactory interface to create module instances\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Module Development\u003C\u002Fh3>\u003Cp>For specific implementation code, refer to IIS-Raid, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002F0x09AL\u002FIIS-Raid\u003C\u002Fp>\u003Cp>For code details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.mdsec.co.uk\u002F2020\u002F02\u002Fiis-raid-backdooring-iis-using-native-modules\u002F\u003C\u002Fp>\u003Cp>IIS-Raid registers two events, RQ_BEGIN_REQUEST and RQ_SEND_RESPONSE, in the RegisterModule function to handle requests and responses\u003C\u002Fp>\u003Ch3>2. Module Registration\u003C\u002Fh3>\u003Cp>Choose from the following three methods:\u003C\u002Fp>\u003Col>\u003Cli>Using the APPCMD.EXE command-line tool\u003C\u002Fli>\u003Cli>Using the IIS Administration Tool for GUI operations\u003C\u002Fli>\u003Cli>Modifying the configuration file applicationHost.config\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Method 1 and Method 2 will be demonstrated in 0x05\u003C\u002Fp>\u003Ch2>0x04 Developing modules using C#\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-gb\u002Fiis\u002Fdevelop\u002Fruntime-extensibility\u002Fdeveloping-a-module-using-net\u003C\u002Fp>\u003Cp>IIS 7.0 and later versions allow extending the server through modules developed in two ways:\u003C\u002Fp>\u003Cul>\u003Cli>Managed Module, using managed code and ASP.NET server extensibility APIs\u003C\u002Fli>\u003Cli>Native Module, using native code and IIS native server extensibility APIs\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The reference introduces the usage of Managed Modules\u003C\u002Fp>\u003Cp>Pay attention to the following issues:\u003C\u002Fp>\u003Cul>\u003Cli>Can be developed using Visual Studio\u003C\u002Fli>\u003Cli>Is a .NET class\u003C\u002Fli>\u003Cli>Uses the System.Web.IHttpModule interface\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Module Development\u003C\u002Fh3>\u003Cp>For specific implementation code, refer to IIS_backdoor at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FWBGlIl\u002FIIS_backdoor\u003C\u002Fp>\u003Cp>For code details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmp.weixin.qq.com\u002Fs\u002Fz1d3yvp14GWakyonTh_b8A\u003C\u002Fp>\u003Ch3>2. Module Registration\u003C\u002Fh3>\u003Cp>You can choose from the following three methods:\u003C\u002Fp>\u003Col>\u003Cli>Using the APPCMD.EXE command-line tool\u003C\u002Fli>\u003Cli>Using the IIS Administration Tool for interface operations\u003C\u002Fli>\u003Cli>Modifying the configuration file web.config\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For specific usage methods, you can also refer to the following materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-gb\u002Fiis\u002Fdevelop\u002Fruntime-extensibility\u002Fdeveloping-iis-modules-and-handlers-with-the-net-framework\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Faspnet\u002Fms227673(v=vs.100)\u003C\u002Fp>\u003Ch2>0x05 IIS-Raid Test\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System:\u003C\u002Fp>\u003Cp>Windows Server 2012r2 x64 (Administrator privileges required)\u003C\u002Fp>\u003Cp>IIS-Raid address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002F0x09AL\u002FIIS-Raid\u003C\u002Fp>\u003Cp>Compile and generate IIS-Backdoor.dll using Visual Studio\u003C\u002Fp>\u003Ch3>1. Backdoor Installation\u003C\u002Fh3>\u003Cp>You can choose one of the following two methods:\u003C\u002Fp>\u003Ch4>(1) Using the APPCMD.EXE command-line tool\u003C\u002Fh4>\u003Cp>The command to view installed modules is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\system32\\inetsrv\\APPCMD.EXE list module\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019798500_0_4bdfae9bbf-1.jpeg\">\u003C\u002Fp>\u003Cp>The command to install the module is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\system32\\inetsrv\\APPCMD.EXE install module \u002Fname:test \u002Fimage:\"c:\\test\\IIS-Backdoor.dll\" \u002Fadd:true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to delete the module is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\system32\\inetsrv\\APPCMD.EXE uninstall module test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using the IIS Administration Tool for interface operations\u003C\u002Fh4>\u003Cp>Run inetmgr.exe to enter the IIS Manager\u003C\u002Fp>\u003Cp>Select Modules, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019811108_1_760e6532f7-1.jpeg\">\u003C\u002Fp>\u003Cp>After entering, select Configure Native Modules..., then select Register..., as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019822902_2_1421ab4f51-1.jpeg\">\u003C\u002Fp>\u003Cp>Fill in the Name and Path, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019833530_3_e7ddbbebde-1.jpeg\">\u003C\u002Fp>\u003Cp>After successful addition, the newly added content is displayed on the Modules page, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019853643_4_20e942f409-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Function Testing\u003C\u002Fh3>\u003Cp>The configuration file for IIS-Raid is saved in Functions.h, including the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#define COM_HEADER \"X-Chrome-Variations\"\u003Cbr>#define PASS_FILE \"C:\\\\Windows\\\\Temp\\\\creds.db\"\u003Cbr>#define PASSWORD \"SIMPLEPASS\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>COM_HEADER is the header name used for communication between the backdoor and the controller\u003C\u002Fp>\u003Cp>PASS_FILE is the location where the dump command reads the file\u003C\u002Fp>\u003Cp>PASSWORD defines the password that will be used for authentication to the backdoor\u003C\u002Fp>\u003Ch4>(1) Connect to the backdoor\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python .\u002Fiis_controller.py --url http:\u002F\u002F192.168.18.138\u002F --password SIMPLEPASS\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019864613_5_a5c510d0f9-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Test functionality\u003C\u002Fh4>\u003Cp>Execute the cmd command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cmd whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019868303_6_b54c2428cc-1.jpeg\">\u003C\u002Fp>\u003Cp>Execute the dump command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dump\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default reads the contents of the file C:\\\\Windows\\\\Temp\\\\creds.db\u003C\u002Fp>\u003Cp>Test as shown in Figure 3-3\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019871554_7_8b09eacbd4-1.jpeg\">\u003C\u002Fp>\u003Cp>Execute shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>inject shellcode.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>shellcode.txt stores the base64-encrypted shellcode, loaded by first creating the process C:\\\\Windows\\\\System32\\\\credwiz.exe, then injecting\u003C\u002Fp>\u003Cp>Test as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019875534_8_a743f33ec9-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Using the IIS module as a backdoor has the following characteristics:\u003C\u002Fp>\u003Cul>\u003Cli>Requires obtaining administrator privileges on the IIS server first\u003C\u002Fli>\u003Cli>Payload in DLL form\u003C\u002Fli>\u003Cli>Launched through module installation\u003C\u002Fli>\u003Cli>DLL resides in w3wp.exe process\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Detect whether IIS has been backdoored by checking Modules\u003C\u002Fp>\u003Cp>Two specific methods:\u003C\u002Fp>\u003Ch4>1. Using APPCMD.EXE command-line tool\u003C\u002Fh4>\u003Cp>Command to view installed modules:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\system32\\inetsrv\\APPCMD.EXE list module\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Using IIS Administration Tool for GUI operation\u003C\u002Fh4>\u003Cp>Run inetmgr.exe to enter IIS Manager\u003C\u002Fp>\u003Cp>Select Modules\u003C\u002Fp>\u003Cp>Note: Module-related DLLs can only be found in w3wp.exe process after successful module loading\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the functionality of IIS modules, demonstrates bypassing firewalls using IIS module features, tests the open-source tool IIS-Raid, and shares recommendations for defense and detection.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1688,"Onedaysec",5,"published","2026-02-02T08:20:05.021Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass Firewalls with IIS Module Backdoor Exploitation","IIS module backdoor, firewall bypass, IIS-Raid, C++ module, C# module, APT34 RGDoor, server management, detection defense",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],114,113,112,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.352Z","2026-07-23T16:01:01.721Z","draft","2026-07-23T16:03:45.233Z"]