HTTP: Unix File /etc/passwd Probe

This signature detects attempts to access the main password file. If the server does not use shadowed passwords, attackers can compromise user passwords through brute force or add themselves to the system.

Extended Description

Successful exploitation of the vulnerability could enable a remote attacker to gain a user list to be used in a brute force attack.

Short Name
HTTP:UNIX-FILE:ETC-PASSWD
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
/etc/passwd CVE-2010-1711 CVE-2014-5115 CVE-2024-23334 File Probe Unix
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3796
False Positive
Unknown
CVSS Score

5.0

4.3

Found a potential security threat?