⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 1941.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule:--Sid:1941--Summary:This event is generated by an attempt to exploit a buffer overflow in TFTP file handling routines.--Impact:Implementation Dependent.  Several implementations of TFTP are vulnerable to abuffer overflow when processing long TFTP get requests.  This could allowarbitrary code execution or result in a Denial of Service condition.--Detailed Information:Insufficient bounds checking on requested filenames results in a simple toexploit buffer overflow condition.  This condition can be exploited by makinga request for an overly long file name.Affected Systems:	Cisco IOS 11.1	Cisco IOS 11.2	Cisco IOS 11.3	ATFTP 0.6.0 and 0.6.1.1--Attack Scenarios:Attackers with access to TFTP can exploit this condition remotely byrequesting an overly long file name.--Ease of AttackDepending on the configuration of the TFTP server this vulnerability can be exploited with a simple script.  Currently several exploits exist in the wild.--False Positives:Requests for legitimate file names of 100 or more bytes will trigger this rule. --False NegativesCurrently this rule checks for the existance of a file name of 100 or more bytes.  Vulnerable TFTP implemenations that experience faults with file names less than 100 bytes will not trigger this rule.--Corrective ActionCisco:For Cisco IOS 11.1, 11.2, 11.3 it is recommended that the TFTP service be disabled.  Cisco does not plan on releasing a patch for this problem.It may also be possible to mitigate this problem by creating an alias for all filenames being served via the TFTP service.  Example:tftp-server flash rsp-jv-mz.111-24a alias CiscoIOS AFTP:    Debian Upgrade atftp_0.6.0woody1_alpha.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_alpha.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_alpha.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_alpha.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftp_0.6.0woody1_arm.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_arm.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_arm.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_arm.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftp_0.6.0woody1_i386.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_i386.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_i386.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_i386.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftp_0.6.0woody1_ia64.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_ia64.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_ia64.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_ia64.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftp_0.6.0woody1_hppa.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_hppa.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_hppa.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_hppa.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftp_0.6.0woody1_m68k.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_m68k.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_m68k.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_m68k.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftp_0.6.0woody1_mips.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_mips.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_mips.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_mips.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftp_0.6.0woody1_mipsel.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_mipsel.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_mipsel.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_mipsel.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftp_0.6.0woody1_powerpc.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_powerpc.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_powerpc.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_powerpc.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftp_0.6.0woody1_s390.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_s390.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_s390.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_s390.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftp_0.6.0woody1_sparc.deb    http://security.debian.org/pool/updates/main/a/atftp/atftp_0.6.0woody1_sparc.deb    Debian GNU/Linux 3.0 alias woody.    Debian Upgrade atftpd_0.6.0woody1_sparc.deb    http://security.debian.org/pool/updates/main/a/atftp/atftpd_0.6.0woody1_sparc.deb    Debian GNU/Linux 3.0 alias woody.--ContributorsOriginal rule writer unknownSourcefire Research TeamMatthew Watchinski matt.watchinski@sourcefire.com--Reference: Bugtraq:http://www.securityfocus.com/bid/5328CVE:CAN-2002-0813--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -