Quantcast
Channel: Security
Viewing all articles
Browse latest Browse all 1881

HTTP 401 for WebDAV client (Windows)

$
0
0

I am trying to map a drive letter in Windows to a public web server (for custom Lenovo driver updates repository). In order for that to be possible, I learnt the web site needs to have WebDAV module enabled. When browsing anonymously the local test web site in IIS via browser, it's fine to browse the directories and GET files.


#Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Referer) cs-host sc-status sc-substatus sc-win32-status sc-bytes cs-bytes time-taken

2020-03-11 09:51:32 W3SVC2 tyrael 127.0.0.2 GET /database.xsd - 80 - 127.0.0.1 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/80.0.3987.132+Safari/537.36 http://127.0.0.2/ 127.0.0.2 200 0 0 1378 605 0


I can also map a drive letter to the URL (e.g. http://127.0.0.2) and it appears in Windows Explorer and browseable. BUT, when I attempt to open/copy any file through Windows, it fails with apparently HTTP 401 errors.


2020-03-11 09:59:01 W3SVC2 tyrael 127.0.0.2 PROPFIND /database.xsd - 80 - 127.0.0.1 HTTP/1.1 Microsoft-WebDAV-MiniRedir/10.0.18363 - 127.0.0.2 207 0 0 1049 170 0
2020-03-11 09:59:01 W3SVC2 tyrael 127.0.0.2 GET /database.xsd - 80 - 127.0.0.1 HTTP/1.1 Microsoft-WebDAV-MiniRedir/10.0.18363 - 127.0.0.2 401 0 5 220 179 0
2020-03-11 09:59:01 W3SVC2 tyrael 127.0.0.2 GET /database.xsd - 80 - 127.0.0.1 HTTP/1.1 Microsoft-WebDAV-MiniRedir/10.0.18363 - 127.0.0.2 401 0 5 220 179 0
2020-03-11 09:59:01 W3SVC2 tyrael 127.0.0.2 GET /database.xsd - 80 - 127.0.0.1 HTTP/1.1 Microsoft-WebDAV-MiniRedir/10.0.18363 - 127.0.0.2 401 0 5 220 179 0
2020-03-11 09:59:01 W3SVC2 tyrael 127.0.0.2 GET /database.xsd - 80 - 127.0.0.1 HTTP/1.1 Microsoft-WebDAV-MiniRedir/10.0.18363 - 127.0.0.2 401 0 5 220 179 0


What condition is causing the Windows WebDAV client to fail authorisation on GET files? Anonymous access seems all allowed from actual browsers.


Viewing all articles
Browse latest Browse all 1881

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>