File: 1043.txt

package info (click to toggle)
snort 2.7.0-20.4
  • links: PTS
  • area: main
  • in suites: lenny
  • size: 34,512 kB
  • ctags: 18,772
  • sloc: ansic: 115,404; sh: 10,893; makefile: 1,372; perl: 487; sql: 213
file content (65 lines) | stat: -rw-r--r-- 1,657 bytes parent folder | download | duplicates (6)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
Rule:
--
Sid:
1043
--
Summary:
This event is generated when an attempt is made to access the file 
'viewcode.asp' on a web server.
--
Impact:
If successful, this attack will display the contents of any file on the 
server.   In addition, it has been reported that this tool is vulnerable
to a denial of service attack.
--
Detailed Information:
'viewcode.asp' is a utility that ships with various Microsoft products 
and is meant to allow web site administrators to view the code of active
server pages during development.   As it will display the contents of 
any file on the server, it should not be present on a production system,
but is installed by default with some products or as an option on 
others.

Also, the tool may be vulnerable to a denial of service attack.

--
Affected Systems:
	Microsoft Site Server 3.0
	Microsoft Site Server 3.0 Commerce Edition
	Microsoft Commercial Internet System 2.0
	Microsoft BackOffice Server 4.0
	Microsoft BackOffice Server 4.5
	Microsoft Internet Information Server 4.0

--
Attack Scenarios:
An attacker can use this tool to steal data or to gather user 
names/passwords and other information that could facilitate other types 
of attack.
--
Ease of Attack:
Simple. No exploit software required.
--
False Positives:
None.
--
False Negatives:
None.
--
Corrective Action:
Remove any copies of 'viewcode.asp' from your server.
--
Contributors:
Original Rule Writer Unknown
Snort documentation contributed by Kevin Peuhkurinen

-- 
Additional References:

Insecure.org
http://www.insecure.org/sploits/ms.backoffice.source.html

Microsoft
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q231368&sd=tech

--