SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.
SERVER-OTHER Microsoft Frontpage administrators.pwd access
This event is generated when an attempt is made to access a file with Microsoft Personal Server administration information. Impact: If successful, the attacker can log into the system and modify web content, as well as modify other users' credentials. Details: On systems running Microsoft Personal Web Server the file administrators.pwd contains usernames and encrypted passwords for users who can author contents and administer this server. The attacker can guess the exact URL of this file and request it, hence gaining this information. Ease of Attack: Simple. No exploit software required.
No information provided
No public information
No known false positives
Original Rule Writer Unknown Snort documentation contributed by Chaos <c@aufbix.org> Cisco Talos Nigel Houghton
No rule groups
CVE-2002-1717 |
Loading description
|