5708.txt

来自「This is the snapshot of Snot Latest Rule」· 文本 代码 · 共 53 行

TXT
53
字号
Rule:--Sid:5708--Summary:This event is generated when network traffic that indicates a file has been uploaded to a location inside the protected network via http.--Impact:Unknown. Possible policy violation.--Detailed Information:This event indicates that a file has been uploaded to a location inside the protected network via http. This may indicate that an attacker is trying to upload code that could be executed or used in conjunction with another attack.--Affected Systems:All systems	--Attack Scenarios:An attacker may upload code of their choosing to a webserver and then execute that code at a later date to further compromise the system.--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:Refer to company policy on the uploading of documents to internal sources.--Contributors:Sourcefire Vulnerability Research TeamAlex Kirk <alex.kirk@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?