185.txt

来自「snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具」· 文本 代码 · 共 73 行

TXT
73
字号
Rule:--Sid:185--Summary:CDK is a Trojan Horse offering the attacker control of the victim host. This event is generated when an attacker connects to a victim server.--Impact:Possible theft of data and control of the targeted machine leading to acompromise of all resources the machine is connected to.--Detailed Information:This Trojan affects the following operating systems:	Windows 95	Windows 98	Windows ME	Windows NT	Windows 2000	Windows XP--Attack Scenarios:This Trojan may be delivered to the target in a number of ways. Thisevent is indicative of an existing infection being activated. Initialcompromise can be in the form of a Win32 installation program that mayuse the extension ".jpg" or ".bmp" when delivered via e-mail forexample.--Ease of Attack:This is Trojan activity, the target machine may already be compromised.Updated virus definition files are essential in detecting this Trojan.--False Positives:None Known--False Negatives:None Known--Corrective Action:Restore a previously known good copy of the registry.A reboot of the infected machine is recommended.--Contributors:Original Rule Writer Max Vision <vision@whitehats.com>Sourcefire Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>Original rule written by Paul Bobby <paul.bobby@lmco.com>Sourcefire Research TeamNigel Houghton <nigel.houghton@sourcefire.com>--Additional References:Whitehats arachNIDShttp://www.whitehats.com/info/IDS263--

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?