📄 710.txt
字号:
Rule:--Sid:710--Summary:This event is generated after an attempted login to a telnet server using the username OutOfBox.--Impact:Unauthorized remote access.--Detailed Information:Some SGI machines are shipped with an easy setup group of scripts toassist the user when setting up the host. This group of programs iscalled EZsetup and may install some passwordless default accounts on the machine.This event is generated when an attempt is made to login to a serverusing the username OutOfBox via Telnet. This is a default account on someSGI based machines. The password may also be OutOfBox or it may not havea password assigned.Repeated events from this rule may indicate a determined effort to guessthe password for this account.--Affected Systems: SGI Telnet servers.--Attack Scenarios:An attacker may attempt to connect to a telnet server using the usernameOutOfBox.--Ease of Attack:Simple--False Positives:None known.--False Negatives:None known.--Corrective Action:Disable the OutOfBox account.Choose the most secure options when using EZsetup.Use ssh as an alternative to TelnetBlock inbound telnet access if it is not required.--Contributors:Original Rule Writer UnknownSourcefire Research TeamNigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -