Preface: CGI newdsn.exeLogo -Internet Security Systems

CGI newdsn.exe

advICE :Intrusions : 2002542
 FAQ
Oh my gosh, I'm being HACKED!!!
How do I report the hacker to my ISP?
I'm seeing lots of attacks, is this normal?

Summary

Attempt to execute newdsn.exe, which is a program with known vulnerabilities.

Details

The intruder is scanning the web server on the system looking for potential vulnerabilities in the "dynamic content generation" portion of the web server. This feature of the web server runs a separate program to create web pages when users access the site.

There are hundreds of such programs that have security bugs in them. In this instance, a hacker is browsing the web server looking for one of these programs. Most of the hacking you read about in the news is due to hackers exploiting these programs and "defacing" the web site.

More information can be found under cgi-bin exploits.

Defense

If this script is visible to the outside world, you should remove it from the directory.

Remove all dynamic content that isn't absolutely necessary to run the web site. Double-check the scripts that you do use in order to verify that they won't permit a security breach.

 more information
Bugtraq Advisory  
 
BugtraqID: 1818   Microsoft IIS 3.0 newdsn.exe File Creation Vulnerability
 
CVE-1999-0191   IIS newdsn.exe CGI script allows remote users to overwrite files.
 

 parametric information
URLThe suspicious URL.
accessedIndicates whether the URL was successfully accessed.
codeThe HTTP return code.
argThe argument to the GET command (if any).

 
Version appeared:  

Privacy Policy |  Copyright Info