12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

390 IDS eventsSuspicious activityHTTP WinApache Bat ExecBase Event:Details:Response:Affected:HTTP_CMD_FILE_PIPEA vulnerability was discovered in the batch file handler for Apache on Microsoft Windowsoperating systems.Special characters (such as |) may not be filtered by the batch file handler when a Web request ismade for a batch file. As a result, a remote attacker may be able to execute arbitrary commands onthe host running the vulnerable software. This may be exploited by means of a specially craftedWeb request which contains the arbitrary commands to be executed.Note that Web servers on Microsoft Windows operating systems normally run with SYSTEMprivileges. The consequences of exploitation is that a remote attacker is able to fully compromise ahost running the vulnerable software.The 2.0.x series of Apache for Microsoft Windows ships with a test batch file which may beexploited to execute arbitrary commands. Since this issue is in the batch file handler, any batch filewhich is accessible by means of the Web is appropriate for the purposes of exploitation.This issue has been addressed in Apache 1.3.24 and 2.0.34-BETA for Microsoft Windows operatingsystems. Administrators are advised to upgrade.Apache Software Foundation Apache 1.3.6win32 to 1.3.23win32Apache Software Foundation Apache 2.0.28-BETA win32 and 2.0.32-BETA win32False Positives: The likelihood of a false positive only exists if the piping is used by certain users to performlegitimate requests.<strong>Reference</strong>sCAN-2002-0061<strong>Security</strong> Focus BID: 4335Ident Malformed DataBase Event:Details:Response:Affected:IDENT_BAD_ERRORAn ident error response was detected that contained things other than alpha numerics for theerror. This may indicate a compromised ident server.If seen in sufficient volume or variation, audit of client and server is recommended.No specific targets.False Positives: It is possible this is a non-compliant ident implementation.<strong>Reference</strong>sIdent SpecificationsIdent Malformed DataBase Event:Details:Response:Affected:IDENT_BAD_OSNAMEThe operating system name in an ident response was not one of the allowed values according to theprotocol specification. This may indicate a compromised ident server.If seen in sufficient volume or variation, audit of client and server is recommended.No specific targets.False Positives: It is possible this is a non-compliant ident implementation.<strong>Reference</strong>sIdent Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!