Rule Category

SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.

Alert Message

SERVER-OTHER Microsoft Frontpage author.exe access

Rule Explanation

This event is generated when an attempt is made to use a Frontpage client to connect and/or publish content to a web server with Frontpage Server Extensions-enabled. Impact: An attacker can modify web content, access privileged files or modify other users' privileges on the Frontpage-enabled virtual host. Details: Microsoft Frontpage is a web-content managing and publishing application, which also comes with server extensions for Microsoft IIS and Apache web servers. The extensions enable the servers to display dynamic content, as well as perform certain levels of web-server administration. Ease of Attack: After gaining the login credentials the attack is trivial.

What To Look For

No information provided

Known Usage

No public information

False Positives

Known false positives, with the described conditions

If FrontPage authoring is allowed from resources external to the protected network this rule will generate an event.

Contributors

Original Rule Writer Unknown Snort documentation contributed by Chaos <c@aufbix.org> Cisco Talos Nigel Houghton

Rule Groups

No rule groups

CVE

Rule Vulnerability

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2002-1717
Loading description