HTTP: IIS URL-Encoded Header Evasion

This signature detects attempts to exploit a known vulnerability in Microsoft IIS Web server. Attackers can encode HTTP headers in a URL request; when IIS parses the URL, it accepts the URL data as valid HTTP headers. Attackers can use this exploit to evade detection.

Extended Description

Successful exploitation could enable the the attacker to bypass filter security systems and intrusion detection systems, and possibly allow the execution of arbitrary commands on the vulnerable IIS server.

Short Name
HTTP:IIS:HDR-EVASION
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Evasion Header IIS URL-Encoded
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?