⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 493.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule:--Sid: 493--Summary: This event is generated when an attempt is made to access the psyBNC IRC"bouncer".--Impact: --Detailed Information:The psyBNC IRC bouncer was designed to hold a connection to an IRC server.  As partof the connection process, a psyBNC server will respond with"Welcome!psyBNC@lam3rz.de".--Affected Systems: All systems using psyBNC.--Attack Scenarios:The psyBNC server itself is not necessarily a risk in itself, but this may be aviolation of corporate policy. Furthermore, psyBNC has found it's way into a large numberof rootkits, both as an IRC bouncer and as remote control agent for dDOS networks.--Ease of Attack:Simple. Any user can install psyBNC.--False Positives:None Known--False Negatives:A modified psyBNC server will not respond with "Welcome!psyBNC@lam3rz.de" and couldeasily evade this rule.SSL encryption between client and server is possible.--Corrective Action:Check the originating host IP and source port and investigate the possibility of alistening psyBNC server and possible system comprimise.--Contributors:Original rule writer unknownOriginal document author unkownSourcefire Vulnerability Research TeamNigel Houghton <nigel.houghton@sourcefire.com>Jon Hart <warchild@spoofed.org>-- Additional References:psyBNC:http://www.psychoid.lam3rz.de/http://www.psychoid.net/--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -