Win.ini file transferred using HTTP POST

http-win.ini-transfer (8576) The risk level is classified as MediumMedium Risk

Description:

An attempt has been made to remotely access the system's WIN.INI file using a Web form. This attack may be trying to reconfigure the system, such as configuring a Trojan Horse to run when the system is restarted.

Many Trojan Horse programs and worms modify or access the WIN.INI file. One of the best known examples is the ExploreZip worm.

Platforms Affected:

  • Microsoft, Windows
  • Microsoft, Windows 2000
  • Microsoft, Windows 95
  • Microsoft, Windows 98
  • Microsoft, Windows NT 4.0
  • Various vendors, HTTP

Remedy:

Verify that your antivirus and intrusion detection software is up-to-date. Should your system become infected with a worm, virus, or Trojan Horse program, refer to your antivirus vendor's documentation to determine how to disinfect and repair your system.

Consequences:

File Manipulation

References:

Reported:

Not available

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.

For corrections or additions please email xforce@iss.net

Return to the main page