⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 2407.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule:--Sid:2407--Summary:This event is generated when an attempt is made to exploit a known vulnerability on a web server or a web application resident on a webserver.--Impact:Information gathering  and system integrity compromise. This rule generates an event on a request for the util.pl file, part of the CalaCode @mail Webmail system.  Some versions of this software are vulnerable to a cross site scripting attack.--Detailed Information:When accessing the webmail service of @mail, across site scripting bug can be abused in the util.pl file.  Whenaddressing the "settings" bar, Javascript code can be inserted into the"Displayed Name" field.This rule will also trigger on some scripted HTTP vulnerabilityscans.  Many vulnerability assessment tools include a check which willverify whether the util.pl file is available on a web server.  There aremultiple other known vulnerabilities in version 3.64 of the @mail system,and the existance of this file would reveal its presence.--Affected Systems:	@mail version 3.64 and prior--Attack Scenarios:A user can submit malicious Javascript to the "DisplayedName" field.  As usual with most browsers, this script will be executedwithin the security context of the web site.  The session ID of theconnection, which is available from within this security context, can beabused by the attacker to obtain access to the session and the user's e-mail account.--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:Ensure the system is using an up to date version of the software and hashad all vendor supplied patches applied.Check the host logfiles and application logs for signs of compromise.--Contributors:Snort documentation contributed by Maarten Van Horenbeeck, GCIA <maarten@daemon.be>Sourcefire Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -