📄 1253.txt
字号:
Rule:--Sid:1253--Summary:This event is generated after a sucessful exploit of the BSD derived Telnet daemon.--Impact:Remote root access. This may or may not indicate a successful root compromise of a telnet server.--Detailed Information:This event is generated after a possible sucessful attempt to compromisea server running a BSD derived version of Telnet. A buffer overflowcondition exists that may present an attacker with the opportunity toexecute code of their choosing.The attacker does not need to login to the server to exploit thisvulnerability, only a connection to the server is needed.--Affected Systems: Multiple Vendor Telnet servers running versions of telnetd derived from the BSD telnet daemon.--Attack Scenarios:An attacker may utilize one of the available exploit scripts.--Ease of Attack:Simple. Exploit scripts are publicly available. This vulnerability mayalso be exploited by a worm.--False Positives:None known.--False Negatives:None known.--Corrective Action:Consider using Secure Shell instead of telnet.Block inbound telnet access if it is not required.--Contributors:Sourcefire Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -