TCP port 80 attacks include:
The following are Web Attack
signatures: 
- 3200—phf attack (severity 5,
access): This signature is triggered when the phf attack is
detected. This may indicate an attempt to illegally access system
resources.
- 3201—General cgi-bin attack
(severity 5, access): This signature is triggered when any cgi-bin
script attempts to retrieve the file /etc/passwd. This may
indicate an attempt to illegally access system resources, in
particular the /etc/passwd file. This may be the prelude to a more
serious attack.
- 3202—-.url file requested
(severity 5, access): This signature is triggered when a user
attempts to get any .url file. A flaw in Microsoft Internet
Explorer may allow illegal access to system resources when files
of type .url are accessed via the HTTP GET command.
- 3203—.lnk file requested
(severity 5, access): This signature is triggered when a user
attempts to get any .lnk file. A flaw in Microsoft Internet
Explorer may allow illegal access to system resources when files
of type .lnk are accessed via the HTTP GET command.
- 3204—.bat file requested
(severity 5, access): This signature is triggered when a user
attempts to get any .bat file. A flaw in Microsoft Internet
Explorer may allow illegal access to system resources when files
of type .bat are accessed via the HTTP GET command.
- 3205—HTML file has .url link
(severity 1, access): This signature is triggered when a file has
a .url link. This signature will warn before a user has a chance
to click on the potentially damaging link. CIDS signature 3202
will alarm on any attempt to click on the link, but it may do its
damage before any defensive action can be taken. A flaw in
Microsoft Internet Explorer may allow illegal access to system
resources when files of type .url are accessed via the HTTP GET
command.
- 3206—HTML file has .lnk link
(severity 1, access): This signature is triggered when a file has
a .lnk link. This signature will warn before a user has a chance
to click on the potentially damaging link. CIDS signature 3203
will alarm on any attempt to click on the link, but it may do its
damage before any defensive action can be taken. A flaw in
Microsoft Internet Explorer may allow illegal access to system
resources when files of type .lnk are accessed via the HTTP GET
command.
- 3207—HTML file has .bat link
(severity 1, access): This signature is triggered when a file has
a .bat link. This signature will warn before a user has a chance
to click on the potentially damaging link. CIDS signature 3204
will alarm on any attempt to click on the link, but it may do its
damage before any defensive action can be taken. A flaw in
Microsoft Internet Explorer may allow illegal access to system
resources when files of type .bat are accessed via the HTTP GET
command.
- 3208—campas attack (severity 5,
access): This signature is triggered when an attempt is made to
pass commands to the CGI program campas. A problem in the CGI
program campas, that is included in the NCSA Web Server
distribution, allows an attacker to execute commands on the host
machine. These commands will execute at the privilege level of the
HTTP server.
- 3209—glimpse server attack
(severity 5, access): This alarm is triggered when an attempt is
made to pass commands to the perl script GlimpseHTTP. These could
allow an attacker to execute commands on the host machine.
GlimpseHTTP is an interface to the Glimpse search tool.
- 3210—IIS View Source Bug
(severity 3, access): If a request to a Microsoft Internet
Information Server is formatted in a certain way, executable files
are read instead of being executed. This can reveal executable
scripts and sensitive database information including passwords. An
attacker may be able to analyze these scripts for vulnerabilities.
This signature is triggered when a request is made to an HTTP
server attempting to view the source.
- 3211—IIS Hex View Source Bug
(severity 1, access): If a request to a Microsoft IIS server is
formatted in a certain way, executable files are read instead of
being executed. This can reveal executable scripts and sensitive
database information including passwords. An attacker may be able
to analyze these scripts for vulnerabilities. This signature is
triggered when a request is made to an HTTP server attempting to
view the source.
- 3212—NPH-TEST-CGI Bug (severity
3, access): This signature is triggered when an attempt is made to
view directory listings with the script nph-test-cgi. Some HTTP
servers include this script, which can be used to list directories
on a server. It is a test script and should be removed on an
operational server.
- 3213—TEST-CGI Bug (severity 3,
access): This signature is triggered when an attempt is made to
view directory listings with the script test-cgi. Some HTTP
servers contain this script, which can be used to list directories
on a server. It is a test script and should be removed on an
operational server.
- 3214—IIS DOT DOT VIEW Bug
(severity 1, access): This signature is triggered by any attempt
to view files above the chrooted directory using Microsoft's
Internet Information Server. This can result in viewing files that
were not intended to be publicly accessible. The chroot directory
is supposed to be the topmost directory to which HTTP clients have
access.
- 3215—IIS DOT DOT EXECUTE Bug
(severity 5, access): This signature is triggered by any attempt
to cause Microsoft's Internet Information Server to execute
commands.
- 3216—IIS DOT DOT DENIAL Bug
(severity 5, DoS): This signature is triggered when an attempt is
made to crash an IIS server by requesting a URL beginning ../..
|