Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

FTP:DOS:ASTERISK

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

FTP

Keywords

Excessive Wildcard Denial of Service

Release Date

2003/05/08

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

FTP: Excessive Wildcard Denial of Service


This signature detects denial-of-service (DoS) attempts against Microsoft FTP Service in Microsoft IIS 4.0, 5.0 and Wu-FTP. Attackers who have previously established an FTP session can send glob characters within a maliciously crafted NLST request to crash the server.

Extended Description

Due to a flaw in the pattern-matching function used by FTP commands, denial of service attacks can be successfully launched. If a user submits an FTP command along with a filename containing specially placed wildcard sequences, the pattern-matching function will not allocate sufficent memory. Resulting in IIS experiencing denial of service condition.

Affected Products

  • Microsoft IIS 4.0
  • Microsoft IIS 5.0

References

  • BugTraq: 2717
  • CVE: CVE-2005-0256
  • URL: http://www.idefense.com/application/poi/display?id=207&type=vulnerabilities&flashstatus=true

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out