⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 715.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule:--Sid:715--Summary:This event is generated when a telnet server sends an error message regarding a failed user attempt to issue the 'su' command to get root privileges. --Impact:Failed root access.  This attack occurs when a user attempts to get root privileges using the su command.--Detailed Information:An attacker may attempt to gain root privileges by issuing the su command.  This implies that the attacker has successfully connected to the telnet server with an account other than root. A failed attempt will cause an error message to be generated indicating that the user is not a member of an authorized group to obtain root privileges.--Affected Systems:All telnet servers.--Attack Scenarios:At attacker may attempt to gain root privileges on a telnet server.--Ease of Attack:Simple--False Positives:It is remotely possible that a legitimate user with multiple user accounts may attempt to issue su command from the wrong account.--False Negatives:None known.--Corrective Action:Use ssh instead of telnet to prevent su passwords from being sniffed.Tightly restric su access to authorized users.Block inbound telnet access if it is not required.--Contributors:Original rule writer unknownDocumented by Steven Alexander<alexander.s@mccd.edu>Sourcefire Research TeamJudy Novak <judy.novak@sourcefire.com>--Additional References:--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -