12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

360 IDS eventsSignaturesHTTP IIS ISAPI ExtensionBase Event:Details:Response:The worm uses a buffer overflow vulnerability in the idq.dll, which runs at the System securitylevel, when handling URL requests. Once an attacker establishes a session on the Web server andcauses a buffer to overflow, that attacker could perform virtually any function on that server.Contact Microsoft for the latest patches.Affected: Microsoft IIS 4.0 and 5.0Microsoft Personal Web Server 4.0Microsoft Index Server 2.0Indexing Service in Windows 2000False Positives: This signature can produce false positives when users give commands with tilde (~) characters.<strong>Reference</strong>s <strong>Security</strong> Focus BID: 2880CVE-2001-0500Microsoft <strong>Security</strong> Bulletin: MS01-033Symantec <strong>Security</strong> Response: CodeRed WormHTTP MDAC IIS Component QueryBase Event:Details:Response:HTTP_MDAC_QUERYMicrosoft Data Access Components (MDAC) contains a buffer overflow vulnerability in a RemoteData Services (RDS) component. The server side RDS component affected is called the RDS DataStub, while the client side is called the Data Space control.Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code, or atthe very least, cause a denial-of-service.Contact Microsoft for the latest patches.Affected: Microsoft Data Access Components (MDAC) 2.1Microsoft Data Access Components (MDAC) 2.5Microsoft Data Access Components (MDAC) 2.6Microsoft Internet Explorer 5.01Microsoft Internet Explorer 5.5Microsoft Internet Explorer 6.0False Positives: None known.<strong>Reference</strong>sCAN-2002-1142Microsoft <strong>Security</strong> Bulletin: MS02-065CERT Advisory: CA-2002-33

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!