📄 1437.txt
字号:
Rule:--Sid:1437--Summary:This event is generated when network traffic indicating the use of amultimedia application is detected.--Impact:This may be a violation of corporate policy since these applications canbe used to bypass security measures designed to restrict the flow ofcorporate information to destinations external to the corporation.--Detailed Information:Multimedia client applications can be used to view movies and listen tomusic files. Some also include file sharing facilities. Use of theseprograms may constitute a violation of company policy.Clients may also contain vulnerabilities that can give an attacker anattack vector for delivering Trojan horse programs and viruses.This rule detects the following Windows Media file types: File extension MIME type .wmz application/x-ms-wmz .wmd application/x-ms-wmd .wma audio/x-ms-wma .wax audio/x-ms-wax .wmv audio/x-ms-wmv .asf video/x-ms-asf .asx video/x-ms-asf .wvx video/x-ms-wvx .wm video/x-ms-wm .wmx video/x-ms-wmx--Affected Systems: All Windows systems running Windows Media player applications--Attack Scenarios:A user can download files from a source external to the protectednetwork that may contain malicious code hidden in the file giving anattacker the opportunity to gain access to a host inside the protectednetwork.--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:--Contributors:Sourcefire Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:Microsoft Windows Media file types:http://support.microsoft.com/default.aspx?scid=kb;en-us;288102--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -