⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 3064.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule: --Sid: 3064-- Summary: This event is generated when an attempt is made by the victim to send aconnection confirmation to the attacker using the CrazzyNet trojan.-- Impact: If connected, the attacker could remotetly execute a multitude of functionsresulting in a full compromise of the victim's machine.--Detailed Information:CrazzyNet uses port 17499. CrazzyNet has a number of functions. Each function isassociated with an attack signal stringthat is sent to the victim. Be suspicious of the following strings:Format: Function Name - String To Look ForAdd Line To File - addlinOverwrite File With Added Line - ovwlinAdd Icon To Desktop - addicoBeep Sound - sndbepChange Windows Control Text - chgawcChange Resolution - chgresChat - chatwyGet Clipboard Text - clpgetCrazy Mouse On - crazym;1Crazy Mouse Off - crazym;0Delete File/Directory - deleteRemove Windows Functions - remwma;0Download File - getfilDisable Ctl-Alt-Del - discad;0Enable Ctl-Alt-Del - discad;1Disable Windows Startup - wndsas;0Enable Windows Startup - wndsas;1Find Files - findfiFormat - formatGet Colors - getcolGet Computer Name - getconSet Computer Name - setconGet Date - gettadSet Date - settadGet Internet Explorer Start Page - getiesSet Internet Explorer Start Page - chgiesGet Mouse Position - getposSet Mouse Position - setmseGet Clients Connected - geticcGet Computer Information - getinfHide Picture - hidpicList Installed Programs - asplstKeylogger - keylog;1Kill Mouse - kilmseList Files And Directories - nextdrList ICQ - icqlstList Of Apps - lstappMake Directory - makdirMonitor On - onmoniMonitor Off - ofmoniGet Mouse Double Click Time - getdclSet Mouse Double Click Time - setdclOpen CD - opencdClose CD - closcdPing - *ICMP Packet* Echo this string of dataPlay Sound - playsdPrint Text - printtRefresh File Listing - refdirRun File - runfilScreen Dump - screenGet Screensaver - getfonSet Screensaver - setscrEnable Scrolling Text - scrollDisable Scrolling Text - sscrolSend To URL - senurlSend Key - runkeySend Message - msgboxSet Clipboard Text - clpsetSet Desktop Image - chgdesShow Clock - sclock;1Hide Clock - sclock;0Show Desktop Icons - deskic;1Hide Desktop Icons - deskic;0Show Start Bar - startb;1Hide Start Bar - startb;0Show Task Bar - sotaskHide Task Bar - hitaskShow Task Bar Icons - staskb;1Hide Task Bar Icons - staskb;0Show Picture - shopicStart CD loop - cdloop;1Stop CD loop - cdloop;0Steal Passwords - geticpSwap Mouse Buttons On - swpmse;1Swap Mouse Buttons Off - swpmse;0Terminate Application - terappGet Text Box Cursor Blink Rate - getretSet Text Box Cursor Blink Rate - setretUpload File - uplfilChange Volume - volumeWarp On - warponWarp Off - warpofList Windows - wndlst-Affected Systems:Windows 95/98/ME/NT/2000--Attack Scenarios: The victim must first install the server. Be wary of suspicious files becausethey often can be backdoors in disguise. Once the victim has unknowingly installed the server, the attacker will usuallyemploy an IP scanner tool to find vulnerable systems. Once an IP is found, the attacker simply has to make the connection.-- Ease of Attack: Easy. Simply a matter of pressing the connect button once the victim hasinstalled the server.-- False Positives:None known--False Negatives:None known-- Corrective Action:CrazzyNet copies itself to C:\WINDOWS\Registry32.exeDelete the registry key Reg32=Registry32.exe found inHKCUU\Software\Microsoft\Windows\CurrentVersion\Run Delete Registry32.exe from Win.ini and System.iniIf found, delete Registry32.exe and server.exeMake sure to keep your virus definitions updated on your anti-virus software.--Contributors:Original Rule Writer: Ricky Macatee <rmacatee@sourcefire.com> Sourcefire Research Team-- Additional References:Pestpatrol:http://www.pestpatrol.com/PestInfo/C/CrazzyNet.asp--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -