File: 1200.txt

package info (click to toggle)
snort 2.7.0-20.4
  • links: PTS
  • area: main
  • in suites: lenny
  • size: 34,512 kB
  • ctags: 18,772
  • sloc: ansic: 115,404; sh: 10,893; makefile: 1,372; perl: 487; sql: 213
file content (61 lines) | stat: -rw-r--r-- 1,177 bytes parent folder | download | duplicates (6)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
Rule:

--
Sid:
1200

--
Summary:
This event is generated when an invalid URL response is sent from a
webserver to a client.

--
Impact:
Information gathering and possible Denial of Service (DoS).

--
Detailed Information:
This event is generated when an invalid URL response is sent from a
webserver to a client. It is possible under some circumstances, to cause
a DoS condition by supplying an invalid URL to a web server running an
affected version of Microsoft IIS 4.0. Certain invalid URLs can cause
the system to make an invalid memory request that will in turn stop the
IIS service from running.

--
Affected Systems:
	Microsoft IIS 4.0 on NT systems
	
--
Attack Scenarios:
The attacker would merely need to make a web request using an invalid
URL.

--
Ease of Attack:
Simple. No exploit software required.

--
False Positives:
None known.

--
False Negatives:
None known.

--
Corrective Action:
Upgrade the system to the latest non-affected version of the software.

Apply the appropriate vendor supplied patches.

--
Contributors:
Sourcefire Research Team
Brian Caswell <bmc@sourcefire.com>
Nigel Houghton <nigel.houghton@sourcefire.com>

--
Additional References:

--