Short Name |
HTTP:IIS:PROPFIND |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
HTTP |
Keywords |
IIS Malformed PROPFIND Remote DoS |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability in Microsoft IIS 5.0. Attackers can send malicious "PROPFIND" requests to the server to crash it.
Microsoft Internet Information Services has been reported vulnerable to a denial of service. When WebDAV receives excessively long requests to the 'PROPFIND' or 'SEARCH' variables, the IIS service will fail. All current web, FTP, and email sessions will be terminated. IIS will automatically restart and normal service will resume. ** It has been reported that if a WebDAV request with a certain number of bytes is received, the Inetinfo service will remain alive but cease serving requests. This will cause the IIS server to stop serving requests until the service is manually restarted. This vulnerability was initially described in BID 7728 and is now being assigned its own BID.