6.6 5000 Series―Web Signatures
6.6.1 HTTP signatures
TCP port 80 attacks include:
  • Access
  • Informational
  • DoS

The following are 5000 series signatures:

  • 5034—WWW IIS newdsn Attack (severity 5, access): This signature is triggered when an attempt is made to run the newdsn.exe command via the http server. The newdsn.exe sample application installed with Microsoft's Internet Information Server (IIS) version 3.0 contains a vulnerability that allows a remote attacker to create arbitrary Microsoft Access files (*.mdb) on the web server under any arbitrary file name. A remote attacker can create files on the hard disk of the webserver and eventually fill it up, thus causing DoS. In addition, a well-known exploit will cause the web server to become unresponsive (hang) or generate a General Protection Fault (GPF).
  • 5036—WWW Windows Password File Access Attempt (severity 5, access): This alarm is triggered when an attempt is made to retrieve either the current or backup copy of the Windows NT password file through the web server.
  • 5038—WWW wwwsql file read bug (severity 5, access): This alarm is triggered when an attempt is made to read files in the cgi-bin directory by the www-sql script. This could indicate that a remote attacker is trying to download cgi-bin scripts and access otherwise protected directories under DocumentRoot.
  • 5042—WWW CGI Valid Shell Access (severity 5, access): This signature is triggered when an attempt is made to access a valid shell or interpreter on the targeted system. These include the following: bash, tcsh, ash, bsh, csh, ksh, jsh, zsh, sh, Java and Python interpreters. This may indicate an attempt to illegally access system resources.
  • 5043—WWW Cold Fusion Attack (severity 5, access): This alarm is triggered when an attempt is made to access example scripts shipped with Cold Fusion Servers. Attempts to access the openfile.cfm or exprcalc.cfm scripts could indicate an attacker is trying to upload files to the target host or server. Attempts to access displayopenedfile.cfm could indicate that an attacker is trying to access files on the target host or server.
  • 5049—WWW IIS showcode.asp Access (severity 3, access): This alarm is triggered whenever an attempt is made to access the showcode.asp Active Server Page. This script allows for arbitrary access to any file on the targets file system.
  • 5050—WWW IIS .htr Overflow (severity 5, access): This signature is triggered when an .htr buffer overrun attack is detected, indicating a possible attempt to execute remote commands, or cause a DoS against the targeted system.
  • 5051—WWW Double Byte Code Page (severity 3, access): The Internet Information Server (IIS) contains a vulnerability that could allow a web site visitor to view the source code for selected files on the server, if the servers default language is set to Chinese, Japanese or Korean.
  • 5052—FrontPage Extensions PWD Open Attempt (severity 5, access): This signature is triggered when an attempt was made to open a configuration file on a Microsoft's Personal Webserver (for Windows platforms) or FrontPage extensions (for UNIX) web server.
  • 5053—FrontPage _vti_bin Directory List Attempt (severity 5, access): This signature is triggered when an attempt was made to list the directory of binaries from Microsoft's Personal Webserver (for Windows platforms) or FrontPage extensions (for UNIX) web server.
  • 5055—HTTP Basic Authentication Overflow (severity 5, access): A buffer overflow can occur on vulnerable web servers if a very large username and password combination is used with Basic Authentication.
  • 5070—WWW msadcs.dll Access (severity 5, reconnaissance): This signature is triggered when an attempt has been made to access the msacds.dll CGI program. This attempt may indicate a reconnaissance session for a later attack to exploit the IIS RDS vulnerability. While no attempt to execute commands or view files was detected, administrators are highly recommended to check the systems affected to ensure that they have not been altered.
  • 5071—WWW msadcs.dll Attack (severity 5, access): This signature is triggered when an attempt has been made to execute commands or view secured filed, with privileged access. Administrators are highly recommended to check the affected systems to ensure that they have not been illicitly modified.
  • 5075—WWW IIS Virtualized UNC Bug (severity 3, access): This signature is triggered when an attempt has been made to view the source of an ASP file. A bug exists in certain versions of Microsoft's IIS web server which allow an attacker to view of the source of ASP, and other files if the IIS virtual directory they reside in has been mapped to a UNC share.
  • 5078—WWW Piranha passwd Attack (severity 5, access): This signature is triggered when an attempt has been made to access the vulnerable piranha/secure/passwd.php3 cgi script using suspicious arguments.