⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 151.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule:  --Sid:151--Summary:This rule has been placed in deleted.rules--Impact:A remote attacker with DeepThroat access has almost full control of thetrojaned machine, including file manipulation and download, keystrokelogging, password scavenging, and reboot. Additionally, the trojan includes a port redirector, and IRC bot, and a tool to scan for other DeepThroatinfected machines. There are also prank-type annoyances.--Detailed Information:DeepThroat is a full-featured remote access trojan.It contains many kiddietools, including window enumeration and manipulation; file searchinglaunching and deletion; remote graphics display sound playing and wallpaperalteration; remote website launching and file download; shell alteration (e.g. hiding systray or Start button), CD-ROM open/closing, mouse button swapping; screen resolution change, display on/off; password scavenging andscreen capturing. It also includes a remotely activated FTP server, a keystrokelogger, an IRC bot, a port redirector, and a tool to scan for other DeepThroat servers. Using these tools, an attacker can not only take control of the infected machine, but can use it as a relay to attack others or scanfor more infected machines from within your network.  By default, DeepThroat sends its control commands to port 2140 on the trojaned machine.--Affected Systems: --Attack Scenarios:Users must be actively enticed into installing the trojan, using any of thenormal social-engineering means. Alternatively, an attacker with physicalaccess to the machine could simply install it himself.--Ease of Attack:Very simple. This is a point-and-click tool. The toughest part is convincing a user to install it, and it could certainly be bound to another binary for easier social-engineering.--False Positives:None Known--False Negatives:None Known--Corrective Action:Mitigation:Block UDP port 2140 (standard DeepThroat control port), if possible TCP port 21(standard DeepThroat FTP server), and TCP port 999 (DeepThroat keyboard logger). DeepThroat may be set up to run on other ports than those listed above. Removal is the only sure mitigation.Removal:Scan with an anti-virus tool and follow the removal instructions.--Contributors:Original rule writer unknownOriginal document author unkownSourcefire Vulnerability Research TeamNigel Houghton <nigel.houghton@sourcefire.com>pbsarnac@ThoughtWorks.com	Initial ResearchJosh Gray			Edits-- Additional References:Packet dump:0000  00 50 56 ff ae cb 00 50  56 fe 18 10 08 00 45 000010  00 1e 30 02 00 00 80 11  b4 71 c0 a8 ea 84 c0 a80020  ea 85 ea 60 08 5c 00 0a  85 8e 31 33 02 b0 c0 a80030  ea 84 00 8a 00 bb 00 00  20 46 48 45            --

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -