HTTP: IIS Host Header DoS
This signature detects attempts to exploit a known vulnerability against Microsoft IIS. Attackers can pass maliciously malformed header values to the host to crash the IIS service.
Extended Description
Microsoft IIS is reported to be prone to a remotely exploitable denial of service. This condition occurs upon receipt of a malformed HOST field in a HTTP request for 'shtml.dll'. It is possible to reproduce this condition by sending a HTTP POST request with a HOST header field that is composed of an excessive number of slashes (/). Further details are not known at this time.
Affected Products
Microsoft iis
References
BugTraq: 5907
CVE: CVE-2002-1908
URL: http://www.securiteam.com/windowsntfocus/6C00C1F5QA.html
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Microsoft
5.0