[Snort-sigs] Notes webadmin.ntf access via replicaID

David Bouscasse bouscasse_david at ...174...
Fri Nov 2 01:06:07 EST 2001


alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80
(msg:"WEB-MISC Notes webadmin.ntf access";flags: A+;
uricontent:"8025674c0060D206"; nocase;
classtype:attempted-recon; sid:????; rev:1;)

The bug description is available at
http://www.nextgenss.com and has been submited at
bugtraq the 31st of octubre. 

As far as I tested it, if the template is empty or if
the admin views are controled by correct ACLs, there
is no way to modify the web content. But hey... it's a
bug :)


Do You Yahoo!? -- Une adresse @yahoo.fr gratuite et en français !
Yahoo! Courrier : http://courrier.yahoo.fr

More information about the Snort-sigs mailing list