📄 1638.txt
字号:
Rule:--Sid:1638--Summary:This event is generated when a scan for the version of an ssh daemon isdetected.--Impact:Information gathering.--Detailed Information:This event indicates that an attempt has been made to scan a host. Inparticular an attempt has been made to scan for the version of the sshdaemon on the target host.This may be the prelude to an attack. Scanners are used to ascertainwhich ports a host may be listening on, whether or not the ports arefiltered by a firewall and if the host is vulnerable to a particularexploit.--Affected Systems: Any host using the ssh daemon.--Attack Scenarios:An attacker can determine if a vulnerable version of ssh is being usedon a host, then proceed to exploit that vulnerablity.--Ease of Attack:Simple.--False Positives:A scanner may be used in a security audit.--False Negatives:If the scanning tool does not send an identification string this rulewill not generate an event.--Corrective Action:Determine whether or not the scan was legitimate then look for otherevents concerning the attacking IP address.Check the host for signs of compromise.--Contributors:Sourcefire Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -