Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:IIS:MALFORMED-HTR-REQUEST

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

IIS 4.0/5.0 Malformed .htr Request (AuthChangeUrl)

Release Date

2003/04/22

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: IIS 4.0/5.0 Malformed .htr Request (AuthChangeUrl)


This signature detects attempts to exploit a known vulnerability against Microsoft Internet Information Server (IIS). IIS versions 4.0 and 5.0 are vulnerable. Attackers can send malformed .htr requests that can cause a denial-of-service (DoS) condition.

Extended Description

The virtual directory within IIS 4.0 and 5.0 contains .htr files which permits users to change passwords remotely. If a user initiates a password change request containing malformed data, the server CPU becomes fully utilized until the administrator performs a reboot to regain normal functionality. The patch available for this issue creates a similar vulnerability which is exploited by appending %3F+.htr to a request.

Affected Products

  • Microsoft IIS 4.0
  • Microsoft IIS 4.0 Alpha
  • Microsoft IIS 5.0

References

  • BugTraq: 1191
  • CVE: CVE-2000-0304
  • URL: http://www.microsoft.com/technet/security/bulletin/ms00-031.mspx

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out