Rule Category

SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.

Alert Message

SERVER-OTHER Microsoft Frontpage administrators.pwd access

Rule Explanation

This event is generated when an attempt is made to access a file with Microsoft Personal Server administration information. Impact: If successful, the attacker can log into the system and modify web content, as well as modify other users' credentials. Details: On systems running Microsoft Personal Web Server the file administrators.pwd contains usernames and encrypted passwords for users who can author contents and administer this server. The attacker can guess the exact URL of this file and request it, hence gaining this information. Ease of Attack: Simple. No exploit software required.

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives

Contributors

Original Rule Writer Unknown Snort documentation contributed by Chaos <c@aufbix.org> Cisco Talos Nigel Houghton

Rule Groups

No rule groups

CVE

Rule Vulnerability

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2002-1717
Loading description