logoalt Hacker News

Stitch4223today at 2:45 AM1 replyview on HN

One confusing part is that the blue screen is not a reference to BSOD but to the IIS default page with the blue squares. That’s probably jargon.

The article lists all the tricks I’ve collected over the years doing pentesting and then some, with great tool references. The signal to noise ratio is very high and there’s little “here’s why” filler which instead might just be someone’s way of storytelling. The article drones on, but with actual content as there is a lot to tell. It’s even light on features like trace.axd, but does mention them and their purposes.

I found it an entertaining overview of taking apart unassuming IIS servers and the point of “Recon harder. ” is made very well :)

Edit: s/boring/unassuming + added point was made very well


Replies

0x1d7today at 1:54 PM

Yes, it's jargon. Blue screen is that default page. Yellow screen of death is another one, referring to when ASP.NET throws an exception and you have detailed exceptions turned on (which for public sites, you shouldn't).