HTTP: Invalid GZIP Transaction

This anomaly is triggered if a mismatch is detected between the indicated value "gzip" in the Content-encoding header and the actual data. The type of payload should start from the pattern "1f 8b" and if it doesn't, it may be an attempt by malware to obfuscate the payload and it will be detected by this anomaly.

References

CVE: CVE-2004-0797

Short Name
HTTP:INVALID:GZIP-TRANSACTION
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2004-0797
Release Date
06/23/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Frequently
CVSS Score

2.1

Found a potential security threat?