📄 2090.txt
字号:
Rule:--Sid:2090--Summary:This event is generated when an attempt is made to exploit a known vulnerability in Microsoft Internet Information Server is detected.--Impact:System compromise, web site defacement, loss of data, execution of code.--Detailed Information:A vulnerability exists in a component used by the Microsoft Internet Information Server 5.0 implementation of WebDAV. A specially crafted overly long URI when processed by the server, triggers a buffer overflow in ntdll.dll which results in a system compromise of the targeted host.The exploit only affects versions of IIS 5.0 running on Microsoft Windows 2000 prior to service pack 3. WebDAV is enabled by default on that platform.This event indicates that the vulnerability scanner nessus may have been used against a target server.--Affected Systems:Microsoft Internet Information Server 5.0 WebDAV on Windows 2000 prior to Service Pack 3.--Attack Scenarios:The attacker is using a publicly available exploit script.--Ease of Attack:Simple--False Positives:None Known--False Negatives:None Known--Corrective Action:Apply the appropriate vendor supplied patch or service pack.Disable WebDAV services.--Contributors:Sourcefire Vulnerability Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:Microsoft:http://www.microsoft.com/security/encyclopedia/details.aspx?name=Win32/Gaobothttp://www.microsoft.com/security/encyclopedia/details.aspx?name=Win32/Nachihttp://www.microsoft.com/security/encyclopedia/details.aspx?name=win32/rbothttp://www.microsoft.com/security/encyclopedia/details.aspx?name=Win32/SdbotCERT:http://www.cert.org/advisories/CA-2003-09.htmlCVE:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0109Microsoft Corporation:http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms03-007.asphttp://www.microsoft.com/security/security_bulletins/ms03-007.asp--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -