⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 finger.rules

📁 Firestorm NIDS是一个性能非常高的网络入侵检测系统 (NIDS)。目前
💻 RULES
字号:
# (C) Copyright 2001, Martin Roesch, Brian Caswell, et al.  All rights reserved.# $Id: finger.rules,v 1.1 2002/08/12 11:42:07 scara Exp $#-------------# FINGER RULES#-------------#alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER cmd_rootsh backdoor attempt"; flow:to_server,established; content:"cmd_rootsh"; classtype:attempted-admin; reference:url,www.sans.org/y2k/TFN_toolkit.htm; reference:url,www.sans.org/y2k/fingerd.htm; sid:320;  rev:5;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER account enumeration attempt"; flow:to_server,established; content:"a b c d e f"; nocase; classtype:attempted-recon; sid:321;  rev:4;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER search query"; flow:to_server,established; content:"search"; reference:cve,CVE-1999-0259; reference:arachnids,375; classtype:attempted-recon; sid:322;  rev:7;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER root query"; flow:to_server,established;  content:"root"; reference:arachnids,376; classtype:attempted-recon; sid:323;  rev:4;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER null request"; flow:to_server,established; content:"|00|"; reference:arachnids,377; classtype:attempted-recon; sid:324;  rev:4;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER remote command \; execution attempt"; flow:to_server,established; content:"|3b|"; reference:cve,CVE-1999-0150; reference:bugtraq,974; reference:arachnids,379; classtype:attempted-user; sid:326;  rev:5;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER remote command pipe execution attempt"; flow:to_server,established; content:"|7c|"; reference:cve,CVE-1999-0152; reference:bugtraq,2220; reference:arachnids,380; classtype:attempted-user; sid:327;  rev:5;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER bomb attempt"; flow:to_server,established; content:"@@"; reference:arachnids,381; reference:cve,CAN-1999-0106; classtype:attempted-dos; sid:328;  rev:5;)# alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER cybercop redirection"; flow:to_server,established; content: "@localhost|0A|"; dsize:11; reference:arachnids,11; classtype:attempted-recon; sid:329;  rev:5;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER redirection attempt"; content: "@"; flow:to_server,established; reference:arachnids,251; reference:cve,CAN-1999-0105; classtype:attempted-recon; sid:330;  rev:5;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER cybercop query"; content: "|0A|     "; flow:to_server,established; depth: 10; reference:arachnids,132; reference:cve,CVE-1999-0612; classtype:attempted-recon; sid:331;  rev:5;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER 0 query"; flow:to_server,established; content:"0"; reference:arachnids,378; reference:arachnids,131; reference:cve,CAN-1999-0197; classtype:attempted-recon; sid:332;  rev:4;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER . query"; flow:to_server,established; content:"."; reference:arachnids,130; reference:cve,CAN-1999-0198; classtype:attempted-recon; sid:333;  rev:4;)alert tcp $EXTERNAL_NET any -> $HOME_NET 79 (msg:"FINGER version query"; flow:to_server,established; content:"version"; classtype:attempted-recon; sid:1541; rev:4;)

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -