HTTP: IIS Host Header DoS
This signature detects attempts to exploit a known vulnerability against Microsoft IIS. Attackers can pass maliciously malformed header values to the host to crash the IIS service.
Extended Description
Microsoft IIS is reported to be prone to a remotely exploitable denial of service. This condition occurs upon receipt of a malformed HOST field in a HTTP request for 'shtml.dll'. It is possible to reproduce this condition by sending a HTTP POST request with a HOST header field that is composed of an excessive number of slashes (/). Further details are not known at this time.
Affected Products
Microsoft iis
References
BugTraq: 5907
CVE: CVE-2002-1908
URL: http://www.securiteam.com/windowsntfocus/6C00C1F5QA.html
mx-19.3
vmx-19.3
vsrx-19.2
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vmx-19.4
mx-19.4
srxevo-25.4
vsrx-26.2
srx-26.2
srx-branch-26.2
vsrx3bsd-26.2
mx-12.3
srx-12.3
srx-branch-12.3
vsrx-12.3
Microsoft
5.0