3272.txt
来自「This is the snapshot of Snot Latest Rule」· 文本 代码 · 共 60 行
TXT
60 行
Rule: --Sid: 3272-- Summary: This event is generated when activity relating to the mydoom trojan isdetected in network data.-- Impact: Serious. This is an indication that a Trojan horse program is active ona system.--Detailed Information:The trojan is capable of allowing an attacker to take control of thesystem and execute commands of their choosing. The attacker can alsoupload files of their choosing to the victim host.--Affected Systems: Windows 95/98/ME/NT/2000--Attack Scenarios: The attacker would first need to install the trojan on the systemvia another attack vector. Once installed the attacker is able tocontrol the system.-- Ease of Attack: Simple.-- False Positives:None known--False Negatives:None known-- Corrective Action: Use the appropriate anti-virus application to remove the trojan from thesystem--Contributors:Sourcefire Vulnerability Research TeamRicky Macatee <rmacatee@sourcefire.com> Nigel Houghton <nigel.houghton@sourcefire.com>-- Additional References:--
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?