Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:IIS:ASP-SEARCH-PROBE

Severity

Low

Recommended

No

Category

HTTP

Keywords

IIS search htr

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: IIS ASP Search Probe


This signature detects requests for the bdir.htr script that can be used to view directory structure information on the server.

Extended Description

Microsoft Internet Information Server (IIS) 3.0 came with a series of remote administration scripts installed in /scripts/iisadmin off the web root directory. ism.dll is required for processing these scripts, and version 3.0 of IIS came with an ism.dll containing an authentication scheme to prevent unauthorized access. If an IIS 3.0 installation is upgraded to IIS 4.0 without removing these scripts, they can be accessed remotely without authentication due to changes in the authentication methods used by IIS 4.0. One of these scripts, bdir.htr, still functions under the IIS 4.0 server - and can be used by a remote attacker to obtain information about the server's directory structure. The script displays a directory listing of a directory specified as part of a request - but only directory names are displayed. Although privilege elevation cannot be accomplished directly by exploiting this script, the information about the server's directory structure thus obtained could potentially be used in mounting further attacks.

Affected Products

  • Microsoft IIS 3.0
  • Microsoft IIS 4.0

References

  • BugTraq: 2280

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out