729.txt
来自「snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具」· 文本 代码 · 共 63 行
TXT
63 行
Rule:--Sid:729--Summary:This event is generated when network traffic indicating the use of amultimedia application is detected.--Impact:This may be a violation of corporate policy since these applications canbe used to bypass security measures designed to restrict the flow ofcorporate information to destinations external to the corporation.--Detailed Information:Multimedia client applications can be used to view movies and listen tomusic files. Some also include file sharing facilities. Use of theseprograms may constitute a violation of company policy.Clients may also contain vulnerabilities that can give an attacker anattack vector for delivering Trojan horse programs and viruses.--Affected Systems: All systems running multimedia applications--Attack Scenarios:A user can download files from a source external to the protectednetwork that may contain malicious code hidden in the file giving anattacker the opportunity to gain access to a host inside the protectednetwork.--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:--Contributors:Sourcefire Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?