⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 607.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule: --Sid: 607--Summary: This event is generated when an attempt to login using the "bin" account is made.--Impact: An attacker may have gained the ability to initiate a remote interactive session on the server.--Detailed Information: This event is generated when a connection using the "bin" account via  "rsh" is attempted. This activity is indicative of attempts to abuse hosts using a default configuration. Some UNIX systems used to ship with "bin" account enabled and no password required. Similarly, the "rshd" service was also enabled. This allowed an attacker to connect to the machine and establish an interactive session using the "bin" account.--Attack Scenarios: An attacker finds a machine with default account "bin" and "rshd" service running and connects to it, then escalates his privileges to "root"--Ease of Attack: Simple, no exploit software required--False Positives: None Known--False Negatives: If a local username is not the same as the remote one ("bin"), the rule will not generate an event.--Corrective Action: Investigate logs on the target host for further details and more signs of suspicious activityUse ssh for remote access instead of rlogin.--Contributors: Original rule by Max Vision <vision@whitehats.com> modified from a signature written by Ron GulaSnort documentation contributed by Anton Chuvakin <http://www.chuvakin.org>Sourcefire Research TeamNigel Houghton <nigel.houghton@sourcefire.com>-- Additional References:Arachnids:http://www.whitehats.com/info/IDS384CVE:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-1999-0651--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -