⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 1337.txt

📁 This is the snapshot of Snot Latest Rules
💻 TXT
字号:
Rule:--Sid:1337--Summary:Attempted chgrp command access via web--Impact:Attempt to change group permissions on a webserver.--Detailed Information:This is an attempt to change file permissions on a machine. Using thiscommand anattacker may change the permissions of a file to suit hisown needs,make a file readable, writeable or excutable to other groupsthat wouldotherwise not have these special permissions.--Attack Scenarios:The attacker can make a standard HTTP request that contains '/bin/chgrp'in the URIwhich can then change file permissions of files present onthe host.Thiscommand may also be requested on a command line shouldthe attacker gainaccess to the machine.--Ease of Attack:Simple HTTP request.--False Positives:None Known--False Negatives:None Known--Corrective Action:Webservers should not be allowed to view or execute files and binariesoutside of it'sdesignated web root or cgi-bin.Whenever possible,sensitive filesand certain areas of the filesystem should have thesystem immutableflag set to negate the use of the chgrp command. OnBSD derived systems,setting the systems runtime securelevel alsoprevents the securelevelfrom being changed. (note: the securelevel canonly beincreased)--Contributors:Sourcefire Research Team-- Additional References:sid: 1336sid: 1338man chgrpman chmod--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -