12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IDS eventsSuspicious activity389Affected:No specific targets.False Positives: None known.<strong>Reference</strong>sHTTP SpecificationsHTTP URL Directory TraversalBase Event:Details:Response:Affected:HTTP_URL_DIRECTORY_TRAVERSALMicrosoft IIS 4.0 and 5.0 are both vulnerable to double dot “../” directory traversal exploitation ifthe extended UNICODE character representations are used in substitution for “/” and “\”.Unauthenticated users may access any known file in the context of the IUSR_machinenameaccount. The IUSR_machinename account is a member of the Everyone and Users groups bydefault. Therefore, you can delete, modify, or execute any file on the same logical drive as any Webaccessiblefile, which is accessible to these groups.Successful exploitation would yield the same privileges as a user who could successfully log on tothe system, without any credentials, to a remote user.It was discovered that a Windows 98 host running the Microsoft Personal Web Server is alsosubject to this vulnerability (March 18, 2001).The Code Blue Worm exploited this vulnerability.UPDATE: We believe that an aggressive worm is in the wild that actively exploits this vulnerability.The patch released with the advisory MS00-057 eliminates this vulnerability. Users who havealready applied this patch do not need to take further action.Otherwise, the patch is available at the following locations:For Microsoft IIS 4.0:Microsoft Q269862Microsoft Q269862For Microsoft IIS 4.0alpha:Microsoft Q269862Microsoft Q269862For Microsoft IIS 5.0:Microsoft Q269862For Microsoft Personal Web Server 4.0:David Raitzer pws_patch.zipNo specific targets.False Positives: None known.<strong>Reference</strong>s <strong>Security</strong> Focus BID: 1806<strong>Security</strong> Focus BID: 2708CVE-2001-0333CVE-2000-0884F-Secure Computer Virus Information Pages: CodeBlueFW: ISSalert: ISS Alert: Code Blue WormTROJ_BLUECODE.A

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!