Short Name |
HTTP:IIS:IIS-ADS-BYPASS |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Microsoft IIS Alternate Data Stream Authentication Bypass |
Release Date |
2010/07/08 |
Update Number |
1725 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability against Microsoft IIS. Attackers can bypass security authentication restrictions to access information they would otherwise not have access to.
Microsoft Internet Information Services (IIS) is prone to an authentication-bypass vulnerability because it fails to properly enforce access restrictions on certain requests to a site that requires authentication. An attacker can exploit this issue to gain unauthorized access to protected resources, which may lead to other attacks. This issue affects IIS 5.1; other 5.x versions may also be affected. Please note that this issue does not affect versions 6.x and 7.x.