990.txt
来自「This is the snapshot of Snot Latest Rule」· 文本 代码 · 共 54 行
TXT
54 行
Rule:--Sid:990--Summary:This event is generated when an attempt is made to access a file with '_vti_inf' in the name.--Impact:Information gathering. This attack can leak the version number and scripting paths of Microsoft FrontPage.--Detailed Information:Microsoft FrontPage provides software for web designers to generate and administer web pages. The file '_vti_inf.html' contains FrontPage configuration information of version number and scripting paths that is normally used by a FrontPage client to communicate with the server. An attacker can craft a URL to access this file to disclose the version number and scripting paths.--Affected Systems:Microsoft Internet Information Server with Frontpage extensions--Attack Scenarios:An attacker can craft a URL to access the '_vti_inf' file to learn the version and scripting paths of FrontPage.--Ease of Attack:Simple.--False Positives:None Known.--False Negatives:None Known.--Corrective Action:Apply patches and upgrade to most current version of FrontPage.--Contributors:Original rule writer unknownModified by Brian Caswell <bmc@sourcefire.com>Sourcefire Vulnerability Research TeamJudy Novak <judy.novak@sourcefire.com>--Additional References:--
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?