HTTP: Binary Data in HTTP-Header

This signature detects binary client-to-server data on an HTTP connection. Normally, HTTP connections should not permit binary data (except for file uploads that can be blocked). However, Web servers using characters outside the ASCII character set and Web e-mail systems can send and receive binary data. Administrators should evaluate their networks accordingly.

Extended Description

The presence of binary data in an HTTP request may indicate an attempt to exploit a vulnerability in an HTTP server and launch an attack.

Short Name
HTTP:REQERR:BIN-DATA-HEADER
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Binary CVE-2004-0385 Data HTTP-Header in
Release Date
08/13/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3725
False Positive
Occasionally
CVSS Score

10.0

Found a potential security threat?