New IIS attacks - TrafficScript to the rescueI've just seen an article on The Register about a new exploit in the wild. Microsoft IIS FTP service is vulnerable to a new exploit, see: Microsoft Security Advisory (975191). Fortunately you can quickly protect your FTP server with just a few lines of TrafficScript. TrafficScript Request RuleThe TrafficScript below will detect common exploit attempts, deny them from reaching the FTP service, and log a warning in your event log.
You will need to configure this rule as a request rule, and set it to run "every time". The issue stems from a problem in the IIS Globbing functionality, and is exploitable by even anonymous users as long as they have read access to a directory. Web Application ProtectionAlthough this particular problem is with the FTP service, it is important to protect all of the services you provide by using a multi-layered approach to security. The most common target, and most ubiquitous on the internet at large is the Web Server. At Zeus we highly recommend that you think about deploying a Web Application Firewall (WAF) to protect your public facing web services. Recently Zeus launched a new plugin which provides ZXTM with WAF functionality. See ZXTM AFM for more information. |
Recently...
Other Resources
|





