Short Name |
TROJAN:MYDOOM:AH-HTTP-INFECT |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
TROJAN |
Keywords |
MyDoom.AH HTTP Infection |
Release Date |
2004/11/11 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects MyDoom.AH/Bofra.B and similar variants attempting to infect a new host using the Internet Explorer IFRAME name overflow vulnerability. MyDoom.AH runs a Web server on port 1639; when a client connects and requests a page, MyDoom.AH sends the malicious payload to the host.
Microsoft Internet Explorer is reported prone to a remote buffer overflow vulnerability. This issue presents itself due to insufficient boundary checks performed by the application and results in arbitrary code execution or a denial of service. This issue does not affect the following Internet Explorer 6 versions: - Internet Explorer 6 for Windows Server 2003 - Internet Explorer 6 for Windows Server 2003 64-Bit Edition and Windows XP 64-Bit Edition Version 2003 - Internet Explorer 6 for Windows XP Service Pack 2