TMS zl Module IPS/IDS Signature Reference Guide RLX.10.2.2.94

ProCurve TMS zl Module IPS/IDS Signature
Reference Guide Version RLX.10.2.2.94
68
Signature Description: Microsoft IIS(Internet Information Server) is a group of Internet servers including Hypertext
Transfer Protocol service and a File Transfer Protocol service. It was developed by Microsoft. This signature detects an
attempt made to exploit potential weaknesses in a host running Microsoft IIS. A successful exploitation of this
vulnerability allows an attacker to access sensitive information on the vulnerable system. This signature specifically
detects "shell.exe" pattern in the traffic sent to the http server. This signature detects access to root.exe.
Signature ID: 387
IIS Sample File bin.exe vulnerability
Threat Level: Warning
Industry ID: CVE-2000-0539 CVE-2000-0540 Bugtraq: 1386 Nessus: 11003,10444,10996
Signature Description: Microsoft IIS(Internet Information Server) is a group of Internet servers including Hypertext
Transfer Protocol service and a File Transfer Protocol service. It was developed by Microsoft. This signature detects an
attempt made to exploit potential weaknesses in a host running Microsoft IIS. A successful exploitation of this
vulnerability allows an attacker to access sensitive information on the vulnerable system. This signature specifically
detects "shell.exe" pattern in the traffic sent to the http server. This signature detects access to bin.exe.
Signature ID: 388
IIS Sample File shell.exe vulnerability
Threat Level: Warning
Industry ID: CVE-2000-0540 Bugtraq: 1386 Nessus: 11003,10444,10996
Signature Description: Microsoft IIS(Internet Information Server) is a group of Internet servers including Hypertext
Transfer Protocol service and a File Transfer Protocol service. It was developed by Microsoft. This signature detects an
attempt made to exploit potential weaknesses in a host running Microsoft IIS. A successful exploitation of this
vulnerability allows an attacker to access sensitive information on the vulnerable system. This signature specifically
detects "shell.exe" pattern in the traffic sent to the http server. This signature detects access to shell.exe.
Signature ID: 389
IIS Sample File hack.exe vulnerability
Threat Level: Warning
Industry ID: CVE-2000-0539 CVE-2000-0540 Bugtraq: 1386 Nessus: 11003,10444,10996
Signature Description: Microsoft IIS(Internet Information Server) is a group of Internet servers including Hypertext
Transfer Protocol service and a File Transfer Protocol service. It was developed by Microsoft. This signature detects an
attempt made to exploit potential weaknesses in a host running Microsoft IIS. A successful exploitation of this
vulnerability allows an attacker to access sensitive information on the vulnerable system. This signature specifically
detects "hack.exe" pattern in the traffic sent to the http server.
Signature ID: 390
IIS Sample File nc.exe vulnerability
Threat Level: Warning
Industry ID: CVE-2000-0540 Bugtraq: 1386 Nessus: 11003,10444,10996
Signature Description: Microsoft IIS(Internet Information Server) is a group of Internet servers including Hypertext
Transfer Protocol service and a File Transfer Protocol service. It was developed by Microsoft. This signature detects an
attempt made to exploit potential weaknesses in a host running Microsoft IIS. A successful exploitation of this
vulnerability allows an attacker to access sensitive information on the vulnerable system. This signature specifically
detects "nc.exe" pattern in the traffic sent to the http server.