⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 4766.txt

📁 This is the snapshot of Snot Latest Rules
💻 TXT
字号:
Rule:--Sid:--Summary:This event is generated when an attempt is made to exploit a known vulnerability in the Microsoft Windows locator service. In particular this rule generates an event when an attempt is made to exploit the function "dcerpc_request" via the "nsi_binding_lookup_begin" command.--Impact:Serious. Execution of arbitrary code leading to unauthorized administrative access to the target host. Denial of Service (DoS) is also possible.--Detailed Information:A vulnerability in the locator service exists due to a programming error which may present an attacker with the opportunity to exploit the service and run code of their choosing on an affected system. The attacker may also cause a DoS condition in the service or possibly gain unauthorized access to the target host.Arguments from a remote RPC call are copied to a local memory buffer without sufficient checks being made on the user supplied data. An attacker can supply code of their choosing by using these arguments to overflow a static buffer causing a possible DoS on the service. Code execution in the context of the administrator account is also possible.In particular this rule generates an event when an attempt is made to exploit the function "dcerpc_request" via the "nsi_binding_lookup_begin" command.--Affected Systems:Microsoft Windows XP SP1 and priorMicrosoft Windows NT Workstation SP6a and priorMicrosoft Windows NT Server SP6a and priorMicrosoft Windows 2000 Server SP3 and priorMicrosoft Windows 2000 Professional SP3 and prior--Attack Scenarios:An attacker can supply data of their choosing as arguments to the RPC call to cause the overflow to occur, prior authentication is not required.--Ease of Attack:Simple. Exploit code exists.--False Positives:None known.--False Negatives:None known.--Corrective Action:Apply the appropriate vendor supplied patches.--Contributors:Sourcefire Vulnerability Research TeamMatt Watchinski <matthew.watchinski@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -