📄 7032.txt
字号:
Rule: --Sid: 7032-- Summary: This event is generated when GoToMyPC service is started on a local machine which then attempts to query the central GoToMyPC broker servers. The GoToMyPC service provides access to a local machine from remote locations which may violate a corporate security policy.-- Impact: This may be a violation of corporate policy since some applications can be used to bypass security measures designed to restrict the flow of corporate information to destinations external to the corporation. In some instances this event may indicate behavior contrary to best security practices.--Detailed Information:When the GoToMyPC service is started on a (local) machine, it communicates it's availability to the central GoToMyPC broker servers at port 8200. This rule looks for one of the steps in this communication setup, in particular, the request for the PingServlet (which acts as the heartbeat/polling application). GoToMyPC is a product of Citrix.--Affected Systems:All systems--Attack Scenarios: Violation of corporate security policy can manifest serious risk to company assets.-- Ease of Attack: Simple.-- False Positives:None known.--False Negatives:None known.-- Corrective Action: Ensure adherence to best security practices and strict adherence to corporate policy--Contributors:Scott Austin <scott.austin@sourcefire.com>-- Additional References:GoToMyPChttp://www.gotomypc.com/howItWorks.tmpl--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -