📄 2925.txt
字号:
Rule: --Sid: 2925-- Summary: This event is generated when an image fitting the profile of a web bughas been detected in network traffic.-- Impact: Information disclosure.--Detailed Information:Web bugs are 1x1 pixel image files that are found in web pages or HTMLemail. These are often used to monitor and track a users activity on theweb. Information such as the browsers IP address, cookie information,time, browser version and other user identifiable charateristics can becollected using web bugs.This rule identifies an image that conforms to the usual size and formatof a web bug.--Affected Systems: All.--Attack Scenarios: An attacker can use this type of image in an HTML email or on a webpage to gather information about the host and user. Since these imagescan be not only small but transparent, they are almost undetectable inHTML pages.-- Ease of Attack: Simple.-- False Positives:None known.--False Negatives:None known.-- Corrective Action: Disallow the use of HTML emailUse a web proxy server to strip all web bug images from serverresponses.--Contributors: Sourcefire Vulnerability Research TeamAlex Kirk <alex.kirk@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>-- Additional References:--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -