📄 493.txt
字号:
Rule:--Sid: 493--Summary: This event is generated when an attempt is made to access the psyBNC IRC"bouncer".--Impact: --Detailed Information:The psyBNC IRC bouncer was designed to hold a connection to an IRC server. As partof the connection process, a psyBNC server will respond with"Welcome!psyBNC@lam3rz.de".--Affected Systems: All systems using psyBNC.--Attack Scenarios:The psyBNC server itself is not necessarily a risk in itself, but this may be aviolation of corporate policy. Furthermore, psyBNC has found it's way into a large numberof rootkits, both as an IRC bouncer and as remote control agent for dDOS networks.--Ease of Attack:Simple. Any user can install psyBNC.--False Positives:None Known--False Negatives:A modified psyBNC server will not respond with "Welcome!psyBNC@lam3rz.de" and couldeasily evade this rule.SSL encryption between client and server is possible.--Corrective Action:Check the originating host IP and source port and investigate the possibility of alistening psyBNC server and possible system comprimise.--Contributors:Original rule writer unknownOriginal document author unkownSourcefire Vulnerability Research TeamNigel Houghton <nigel.houghton@sourcefire.com>Jon Hart <warchild@spoofed.org>-- Additional References:psyBNC:http://www.psychoid.lam3rz.de/http://www.psychoid.net/--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -