⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 2305.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule:--Sid:2305--Summary:This event is generated when an attempt is made to access the scriptchatbox.php on a web server running a PHP application.--Impact:Denial of Service (DoS).--Detailed Information:This event is generated when an attempt is made to access the scriptchatbox.php on a web server. This application does not perform stringent checks when validating data supplied by the user in the Name field ofthe script. HTML or script code supplied via that field may cause aDenial of Service condition to occur.--Affected Systems:	All systems running E107 versions 0.545 and 0.603, other versions may	also be affected--Attack Scenarios:The attacker could supply some offending HTML code into the name fieldand cause the DoS.--Ease of Attack:Simple.Proof of concept exists, in the name field enter:<script type=javascript>alert('foo')</script>--False Positives:None known.--False Negatives:None known.--Corrective Action:Ensure the system is using an up to date version of the software and hashad all vendor supplied patches applied.--Contributors:Sourcefire Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -