6.4 3000 Series—TCP Signatures
6.4.10 Legacy Web Attack signatures (cont.)
  • 3217—php view file Bug (severity 5, access): This signature is triggered when someone attempts to use the PHP cgi-bin program to view a file. This may indicate an attempt to illegally access system resources.
  • 3218—SGI wrap bug (severity 5, access): This signature is triggered by any attempt to view or list files using the program called wrap. This was distributed with the IRIX Web Server.
  • 3219—php buffer overflow (severity 5, access): This signature is triggered when an oversized query is sent to the php cgi-bin program. This represents an attempt to overflow a buffer and gain system access.
  • 3220—IIS Long URL Crash (severity 1, DoS): This signature is triggered when a large URL has been passed to a web server in an attempt to crash the system.
  • 3221—View Source CGI Bug (severity 3, access): This signature is triggered when someone attempts to use the cgi-viewsource script to view files above the http root directory.
  • 3222—MLOG/MYLOG CGI Bug (severity 3, access): This signature is triggered when someone attempts to use the PHP scripts mlog or mylog to view files on a machine.
  • 3223—Handler CGI Bug (severity 3, access): This signature is triggered when someone attempts to use the cgi-handler script to execute commands.
  • 3224-Webgais Bug (severity 3, access): This signature is triggered when someone attempts to use the webgais script to run arbitrary commands.
  • 3225—WebSendmail Bug (severity 3, access): This signature is triggered when someone attempts to use the script websendmail to read the password file on a machine.
  • 3226—Webdist Bug (severity 3, access): This signature is triggered when an attempt is made to use the webdist program.
  • 3227—Htmlscript Bug (severity 3, access): This signature is triggered when an attempt is made to view files above the html root directory.
  • 3228—Performer Bug (severity 3, access): This signature is triggered when an attempt is made to view files above the html root directory.
  • 3229—WebSite win-c-sample buffer overflow (severity 5, access): This signature is triggered when an attempt is made to access the win-c-sample program distributed with WebSite servers.
  • 3230—WebSite uploader (severity 3, access): This signature is triggered when an attempt is made to access the uploader program distributed with WebSite servers.
  • 3231—Novell convert bug (severity 5, access): This signature is triggered when a user has attempted to use the convert.bas program included with Novell's web server to illegally view files.
  • 3232—finger attempt (severity 3, access): This signature is triggered when an attempt is made to run the finger.pl program via the http server.
  • 3233—Count Overflow (severity 5, access): This signature is triggered when an attempt is made to overflow a buffer in the cgi Count program.