⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 3010.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule: --Sid: 3010-- Summary: This event is generated when an attacker attempts to find the victim'sWindows directory with the RUX the Tick trojan.-- Impact: If successful, the attacker would gain unauthorized access to yoursystem, enabling him to upload and execute file on your computer. Theattacker can use this function to upload additional backdoors to thevictim's sytem and execute them.--Detailed Information:When executed, RUX the Tick opens up its assigned port (default is22222) for communication with the attacker. RUX the Tick has threefunctions: Get Windows Directory, Get System Directory, and Upload AndExecute File. Get Windows Directory and Get System Directory are usedfor reconnaissance. Upload And Execute File is mainly used to upload andrun other backdoors onto the victim's computer.--Affected Systems:	Windows 95/98/ME/NT/2000--Attack Scenarios: The victim must first install the server. Be wary of suspicious filesbecause they often can be backdoors in disguise. Once the victimmistakenly installs the server program, the attacker usually will employan IP scanner program to find the IP addresses of victims that haveinstalled the program. Then the attacker enters the IP address, portnumber (which  is assigned to the server program by the attacker:default is 22222), and presses the connect button and he has access toyour computer.-- Ease of Attack:Simple.-- False Positives:None known--False Negatives:None known-- Corrective Action: Using Windows Task Manager, kill these processes: ruxserver.exe andserver.exe. Use Windows Explorer to find ruxserver.exe and delete the file.Keep your anti-virus programs updated with the latest definitions.--Contributors:Sourcefire Vulnerability Research TeamRicky Macatee <rmacatee@sourcefire.com>-- Additional References:PestPatrol:http://www.pestpatrol.com/PestInfo/R/RUX.ASP--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -