TCP port 80 attacks include:
The following are 5000 series
signatures: 
- 5034—WWW IIS newdsn Attack
(severity 5, access): This signature is triggered when an attempt
is made to run the newdsn.exe command via the http server. The
newdsn.exe sample application installed with Microsoft's Internet
Information Server (IIS) version 3.0 contains a vulnerability that
allows a remote attacker to create arbitrary Microsoft Access
files (*.mdb) on the web server under any arbitrary file name. A
remote attacker can create files on the hard disk of the webserver
and eventually fill it up, thus causing DoS. In addition, a
well-known exploit will cause the web server to become
unresponsive (hang) or generate a General Protection Fault (GPF).
- 5036—WWW Windows Password File
Access Attempt (severity 5, access): This alarm is triggered when
an attempt is made to retrieve either the current or backup copy
of the Windows NT password file through the web server.
- 5038—WWW wwwsql file read bug
(severity 5, access): This alarm is triggered when an attempt is
made to read files in the cgi-bin directory by the www-sql script.
This could indicate that a remote attacker is trying to download
cgi-bin scripts and access otherwise protected directories under
DocumentRoot.
- 5042—WWW CGI Valid Shell Access
(severity 5, access): This signature is triggered when an attempt
is made to access a valid shell or interpreter on the targeted
system. These include the following: bash, tcsh, ash, bsh, csh,
ksh, jsh, zsh, sh, Java and Python interpreters. This may indicate
an attempt to illegally access system resources.
- 5043—WWW Cold Fusion Attack
(severity 5, access): This alarm is triggered when an attempt is
made to access example scripts shipped with Cold Fusion Servers.
Attempts to access the openfile.cfm or exprcalc.cfm scripts could
indicate an attacker is trying to upload files to the target host
or server. Attempts to access displayopenedfile.cfm could indicate
that an attacker is trying to access files on the target host or
server.
- 5049—WWW IIS showcode.asp Access
(severity 3, access): This alarm is triggered whenever an attempt
is made to access the showcode.asp Active Server Page. This script
allows for arbitrary access to any file on the targets file
system.
- 5050—WWW IIS .htr Overflow
(severity 5, access): This signature is triggered when an .htr
buffer overrun attack is detected, indicating a possible attempt
to execute remote commands, or cause a DoS against the targeted
system.
- 5051—WWW Double Byte Code Page
(severity 3, access): The Internet Information Server (IIS)
contains a vulnerability that could allow a web site visitor to
view the source code for selected files on the server, if the
servers default language is set to Chinese, Japanese or Korean.
- 5052—FrontPage Extensions PWD Open
Attempt (severity 5, access): This signature is triggered when an
attempt was made to open a configuration file on a Microsoft's
Personal Webserver (for Windows platforms) or FrontPage extensions
(for UNIX) web server.
- 5053—FrontPage _vti_bin Directory
List Attempt (severity 5, access): This signature is triggered
when an attempt was made to list the directory of binaries from
Microsoft's Personal Webserver (for Windows platforms) or
FrontPage extensions (for UNIX) web server.
- 5055—HTTP Basic Authentication
Overflow (severity 5, access): A buffer overflow can occur on
vulnerable web servers if a very large username and password
combination is used with Basic Authentication.
- 5070—WWW msadcs.dll Access
(severity 5, reconnaissance): This signature is triggered when an
attempt has been made to access the msacds.dll CGI program. This
attempt may indicate a reconnaissance session for a later attack
to exploit the IIS RDS vulnerability. While no attempt to execute
commands or view files was detected, administrators are highly
recommended to check the systems affected to ensure that they have
not been altered.
- 5071—WWW msadcs.dll Attack
(severity 5, access): This signature is triggered when an attempt
has been made to execute commands or view secured filed, with
privileged access. Administrators are highly recommended to check
the affected systems to ensure that they have not been illicitly
modified.
- 5075—WWW IIS Virtualized UNC Bug
(severity 3, access): This signature is triggered when an attempt
has been made to view the source of an ASP file. A bug exists in
certain versions of Microsoft's IIS web server which allow an
attacker to view of the source of ASP, and other files if the IIS
virtual directory they reside in has been mapped to a UNC share.
- 5078—WWW Piranha passwd Attack
(severity 5, access): This signature is triggered when an attempt
has been made to access the vulnerable piranha/secure/passwd.php3
cgi script using suspicious arguments.
|