HTTP: Microsoft IIS 5 NTLM and Basic Authentication Bypass

This signature detects attempts to bypass IIS 5 Basic or NTLM Authentication. A successful attacker could gain access to protected documents and code.

Extended Description

Index Server can be used to cause IIS to display the source of .asp and possibly other server-side processed files. By appending a space (%20) to the end of the filename specified in the 'CiWebHitsFile' variable, and setting 'CiHiliteType' to 'Full' and 'CiRestriction' to 'None', it is possible to retrieve the unprocessed source of the file. This is possible on any machine with Index Server installed, even those with no normal .htw files, because the virtual file null.htw is stored in memory and the .htw extension is mapped by default to webhits.dll .

Affected Products

Microsoft index_server

Short Name
HTTP:IIS:IIS-BYPASS
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
5 Authentication Basic Bypass CVE-2000-0302 IIS Microsoft NTLM and bid:1084
Release Date
06/04/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Microsoft

CVSS Score

5.0

Found a potential security threat?