796.txt
来自「This is the snapshot of Snot Latest Rule」· 文本 代码 · 共 66 行
TXT
66 行
Rule: --Sid:796--Summary:This rule has been placed in deleted.rules. It has been superceded bysid 721.--Impact:Mail worms may spread rapidly because users execute them.--Detailed Information:Windows systems are often configured not to display file extensions.By adding a second extension, users get confused and think that anexecutable is an EXCEL spreadsheet - e.g. businnesplan.xls.vbs gets displayed asbusinessplan.xls but is a visual basic script and not an EXCEL spreadsheet.--Affected Systems: --Attack Scenarios:Famous worms (ILOVEYOU, KOURNIKOVA) are based on this method. Warning:An EXCEL spreadsheet is in now way more secure than a visual basic script.Wrongly configured antivirus software my ignore this files andlet a macro virus pass.--Ease of Attack:Very easy. One needs to attach a file and hope that it gets executed.--False Positives:None KnownCould be an error on sender's side.--False Negatives:None Known---Corrective Action:Use antivirus software. Configure mail clients securely, especially whenusing windows desktops. Educate your mail users. Deny all attachments atthe gateway if you can.--Contributors:Original rule writer unknownSnort documentation contributed by tobias.haecker@to.comSourcefire Vulnerability Research TeamNigel Houghton <nigel.houghton@sourcefire.com>--Additional References:See websites of antivirus companies.--
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?