GEN:SID 1:1242
Message WEB-IIS ISAPI .ida access
Summary This event is generated when an attempt is made to access the .ida Indexing Service ISAPI filter.
Impact Intelligence gathering activity. If an .ida file is erroneously shared from a network share, an error message is returned from a request that contains the share path will be disclosed.
Detailed Information Microsoft Internet Information Service (IIS) installs several Internet Service Application Programming Interface (ISAPI) extensions.  The .ida ISAPI filter provides support for administrative scripts.  Files with the .ida suffix should not be located on network shares.  If an attempt is made to access them from a network share, an error message is returned disclosing the share path.  
Affected Systems Hosts running IIS 4.0
Hosts running IIS 5.0
Attack Scenarios An attacker can attempt to access a file with the .ida suffix in an attempt to receive an error message with disclosure about the share path.
Ease of Attack Simple.
Corrective Action Do not place files with the .ida suffix on a network share.

Additional References Arachnids
http://www.whitehats.com/info/IDS552

CVE
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071

Rule References arachnids: 552
bugtraq: 1065
cve: 2000-0071