- 5081—WWW WinNT cmd.exe (severity
5, access): This signature is triggered when the use of the
Windows NT cmd.exe is detected in a URL. A malicious user could
cause severe damage to the system hosting the web site. Malicious
users could add, change or delete data, run code already on the
server, or upload new code to the server and run it.
- 5085—WWW IIS Source Fragment
(severity 3, access): This signature is triggered when a URL
ending in "+.htr" is detected. A remote attacker could
view the contents of ASP, ASA, and other file types on the web
server, which may contain sensitive information such as usernames
and passwords.
- 5087—WWW Sun Java Server Access
(severity 3, access): This signature is triggered when an attempt
to access URLs like http://server/pservlet.html or http://server/servlet/sunexamples.
RealmDumpServlet
are detected. A remote attacker can identify users and file
permissions on the web server. This knowledge could be used to
perform additional probes or attacks to gain further access to the
web server.
- 5090—WWW FrontPage htimage.exe
Access (severity 3, reconnaissance): This signature is triggered
when the FrontPage CGI program is accessed with a filename
argument ending with "0,0". This file is associated with
three known vulnerabilities when it is on Windows servers. It will
allow identification of the web root path, possibly cause a DoS
when run with a very large argument, and allow access to files on
the web server.
- 5091—WWW Cart32 Remote Admin
Access (severity 3, reconnaissance/access): This signature is
triggered when an attempt is made to access the vulnerable
cart32.exe cgi script with suspicious arguments:
/cart32.exe/cart32clientlist or /c32web.exe/changeadminpassword. A
remote user can change the administrative password without knowing
the previous password. The remote user could also obtain
information such as username, password, and credit card numbers.
- 5097—WWW FrontPage MS-DOS Device
Attack (severity 5, access): This alarm is triggered when a URL is
requested using the shtml.exe component of FrontPage that includes
an MS-DOS device name. A DoS can result from this URL request.
- 5103—WWW SuSE Apache CGI Source
Attack (severity 3, recon): This signature is triggered when an
attempt to access the /cgi-bin-sdb directory of a web server is
detected. An attacker could view the contents of CGI scripts /
programs that may contain sensitive information, like database
usernames and passwords.
- 5107—WWW Mandrake Linux/perl
Access (severity 3, recon): This signature is triggered when an
attempt to access the URL path /perl directly has been detected.
The /perl directory is used by mod_perl to store Perl scripts
which can be executed by the web server. By accessing this
directory, a remote user is able to obtain a directory listing.
The knowledge of a script's presence may allow more sophisticated
attacks to occur.
- 5108—WWW Netegrity SiteMinder
Access (severity 3, access): This signature is triggered when an
unauthorized attempt to access protected content on a website
managed by Netegrity Site Minder using an authentication bypass
method is detected. Looks for strings like "/$/somefile.ccc"
in a URL. A remote attacker can read and execute protected content on the web site administered by Site Minder.
- 5111—WWW Solaris Answerbook2
Access (severity 3, recon): This signature is triggered when an
attempt to add a user to the AnswerBook interface is detected.
- 5112—WWW Solaris Answerbook 2
Attack (severity 5, access): This signature is triggered when an
ttempt to execute an unauthorized command using the access /
error rotation feature of the administrative interface of
AnswerBook 2 is detected. A remote attacker can create an
AnswerBook administrator account without providing any
authentication information allowing the attacker to gain the
ability to execute arbitrary commands with the privileges of the
web server.
- 5114—WWW IIS Unicode Attack
(severity 5, access): This signature is triggered when an attempt
to exploit the Unicode ../ directory traversal vulnerability is
detected. An attacker could add, change or delete data, run code
already on the server, or upload new code to the server and run
it.
|
|