12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IDS eventsIntrusion attempts303Bad Hex CharacterBase Event:Details:Response:Affected:HTTP_BAD_ESCAPE_SEQUENCEThe IDS component detected a % character (indicating a 2 digit hex byte follows) in a pathnameand the next two characters were not valid hex digits. This may be an attempt to exploit the IIStraversal bug.Location and audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>s:HTTP SpecificationsBad UTF-8 Hex CharacterBase Event:Details:Response:Affected:HTTP_URL_OVERLONG_DOTThe IDS component detected an incorrect (too long) representation of a dot (.) character. This maybe an attempt to exploit an IIS server.Location and audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>s:HTTP SpecificationsBFTP SITE CHOWN BOBase Event:Details:Response:BFTP_SITE_CHOWN_BUFFER_OVERFLOWIn bftpd, an FTP daemon, there is a buffer overflow in the first parameter passed to the SITECHOWN command.WorkaroundIn /etc/bftpd.conf replaceENABLE_SITE=yeswithENABLE_SITE=noAffected: Max-Wilhelm Bruker bftpd 1.0.13False Positives: None known.<strong>Reference</strong>s: <strong>Security</strong> Focus BID: 2120CVE-2001-0065

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!