6.6 5000 Series―Web Signatures
6.6.2 HTTP signatures (cont.)
  • 5081—WWW WinNT cmd.exe (severity 5, access): This signature is triggered when the use of the Windows NT cmd.exe is detected in a URL. A malicious user could cause severe damage to the system hosting the web site. Malicious users could add, change or delete data, run code already on the server, or upload new code to the server and run it.
  • 5085—WWW IIS Source Fragment (severity 3, access): This signature is triggered when a URL ending in "+.htr" is detected. A remote attacker could view the contents of ASP, ASA, and other file types on the web server, which may contain sensitive information such as usernames and passwords.
  • 5087—WWW Sun Java Server Access (severity 3, access): This signature is triggered when an attempt to access URLs like http://server/pservlet.html or http://server/servlet/sunexamples. RealmDumpServlet are detected. A remote attacker can identify users and file permissions on the web server. This knowledge could be used to perform additional probes or attacks to gain further access to the web server.
  • 5090—WWW FrontPage htimage.exe Access (severity 3, reconnaissance): This signature is triggered when the FrontPage CGI program is accessed with a filename argument ending with "0,0". This file is associated with three known vulnerabilities when it is on Windows servers. It will allow identification of the web root path, possibly cause a DoS when run with a very large argument, and allow access to files on the web server.
  • 5091—WWW Cart32 Remote Admin Access (severity 3, reconnaissance/access): This signature is triggered when an attempt is made to access the vulnerable cart32.exe cgi script with suspicious arguments: /cart32.exe/cart32clientlist or /c32web.exe/changeadminpassword. A remote user can change the administrative password without knowing the previous password. The remote user could also obtain information such as username, password, and credit card numbers.
  • 5097—WWW FrontPage MS-DOS Device Attack (severity 5, access): This alarm is triggered when a URL is requested using the shtml.exe component of FrontPage that includes an MS-DOS device name. A DoS can result from this URL request.
  • 5103—WWW SuSE Apache CGI Source Attack (severity 3, recon): This signature is triggered when an attempt to access the /cgi-bin-sdb directory of a web server is detected. An attacker could view the contents of CGI scripts / programs that may contain sensitive information, like database usernames and passwords.
  • 5107—WWW Mandrake Linux/perl Access (severity 3, recon): This signature is triggered when an attempt to access the URL path /perl directly has been detected. The /perl directory is used by mod_perl to store Perl scripts which can be executed by the web server. By accessing this directory, a remote user is able to obtain a directory listing. The knowledge of a script's presence may allow more sophisticated attacks to occur.
  • 5108—WWW Netegrity SiteMinder Access (severity 3, access): This signature is triggered when an unauthorized attempt to access protected content on a website managed by Netegrity Site Minder using an authentication bypass method is detected. Looks for strings like "/$/somefile.ccc" in a URL. A remote attacker can read and execute protected content on the web site administered by Site Minder.
  • 5111—WWW Solaris Answerbook2 Access (severity 3, recon): This signature is triggered when an attempt to add a user to the AnswerBook interface is detected.
  • 5112—WWW Solaris Answerbook 2 Attack (severity 5, access): This signature is triggered when an ttempt to execute an unauthorized command using the access / error rotation feature of the administrative interface of AnswerBook 2 is detected. A remote attacker can create an AnswerBook administrator account without providing any authentication information allowing the attacker to gain the ability to execute arbitrary commands with the privileges of the web server.
  • 5114—WWW IIS Unicode Attack (severity 5, access): This signature is triggered when an attempt to exploit the Unicode ../ directory traversal vulnerability is detected. An attacker could add, change or delete data, run code already on the server, or upload new code to the server and run it.