6.4 3000 Series—TCP Signatures
6.4.9 Legacy Web Attack signatures
TCP port 80 attacks include:
  • Access
  • Informational
  • DoS

The following are Web Attack signatures:

  • 3200—phf attack (severity 5, access): This signature is triggered when the phf attack is detected. This may indicate an attempt to illegally access system resources.
  • 3201—General cgi-bin attack (severity 5, access): This signature is triggered when any cgi-bin script attempts to retrieve the file /etc/passwd. This may indicate an attempt to illegally access system resources, in particular the /etc/passwd file. This may be the prelude to a more serious attack.
  • 3202—-.url file requested (severity 5, access): This signature is triggered when a user attempts to get any .url file. A flaw in Microsoft Internet Explorer may allow illegal access to system resources when files of type .url are accessed via the HTTP GET command.
  • 3203—.lnk file requested (severity 5, access): This signature is triggered when a user attempts to get any .lnk file. A flaw in Microsoft Internet Explorer may allow illegal access to system resources when files of type .lnk are accessed via the HTTP GET command.
  • 3204—.bat file requested (severity 5, access): This signature is triggered when a user attempts to get any .bat file. A flaw in Microsoft Internet Explorer may allow illegal access to system resources when files of type .bat are accessed via the HTTP GET command.
  • 3205—HTML file has .url link (severity 1, access): This signature is triggered when a file has a .url link. This signature will warn before a user has a chance to click on the potentially damaging link. CIDS signature 3202 will alarm on any attempt to click on the link, but it may do its damage before any defensive action can be taken. A flaw in Microsoft Internet Explorer may allow illegal access to system resources when files of type .url are accessed via the HTTP GET command.
  • 3206—HTML file has .lnk link (severity 1, access): This signature is triggered when a file has a .lnk link. This signature will warn before a user has a chance to click on the potentially damaging link. CIDS signature 3203 will alarm on any attempt to click on the link, but it may do its damage before any defensive action can be taken. A flaw in Microsoft Internet Explorer may allow illegal access to system resources when files of type .lnk are accessed via the HTTP GET command.
  • 3207—HTML file has .bat link (severity 1, access): This signature is triggered when a file has a .bat link. This signature will warn before a user has a chance to click on the potentially damaging link. CIDS signature 3204 will alarm on any attempt to click on the link, but it may do its damage before any defensive action can be taken. A flaw in Microsoft Internet Explorer may allow illegal access to system resources when files of type .bat are accessed via the HTTP GET command.
  • 3208—campas attack (severity 5, access): This signature is triggered when an attempt is made to pass commands to the CGI program campas. A problem in the CGI program campas, that is included in the NCSA Web Server distribution, allows an attacker to execute commands on the host machine. These commands will execute at the privilege level of the HTTP server.
  • 3209—glimpse server attack (severity 5, access): This alarm is triggered when an attempt is made to pass commands to the perl script GlimpseHTTP. These could allow an attacker to execute commands on the host machine. GlimpseHTTP is an interface to the Glimpse search tool.
  • 3210—IIS View Source Bug (severity 3, access): If a request to a Microsoft Internet Information Server is formatted in a certain way, executable files are read instead of being executed. This can reveal executable scripts and sensitive database information including passwords. An attacker may be able to analyze these scripts for vulnerabilities. This signature is triggered when a request is made to an HTTP server attempting to view the source.
  • 3211—IIS Hex View Source Bug (severity 1, access): If a request to a Microsoft IIS server is formatted in a certain way, executable files are read instead of being executed. This can reveal executable scripts and sensitive database information including passwords. An attacker may be able to analyze these scripts for vulnerabilities. This signature is triggered when a request is made to an HTTP server attempting to view the source.
  • 3212—NPH-TEST-CGI Bug (severity 3, access): This signature is triggered when an attempt is made to view directory listings with the script nph-test-cgi. Some HTTP servers include this script, which can be used to list directories on a server. It is a test script and should be removed on an operational server.
  • 3213—TEST-CGI Bug (severity 3, access): This signature is triggered when an attempt is made to view directory listings with the script test-cgi. Some HTTP servers contain this script, which can be used to list directories on a server. It is a test script and should be removed on an operational server.
  • 3214—IIS DOT DOT VIEW Bug (severity 1, access): This signature is triggered by any attempt to view files above the chrooted directory using Microsoft's Internet Information Server. This can result in viewing files that were not intended to be publicly accessible. The chroot directory is supposed to be the topmost directory to which HTTP clients have access.
  • 3215—IIS DOT DOT EXECUTE Bug (severity 5, access): This signature is triggered by any attempt to cause Microsoft's Internet Information Server to execute commands.
  • 3216—IIS DOT DOT DENIAL Bug (severity 5, DoS): This signature is triggered when an attempt is made to crash an IIS server by requesting a URL beginning ../..