⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 2003.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule:  --Sid:2003--Summary:This event is generated when an attempt is made by the "Slammer" worm to compromise a Microsoft SQL Server.--Impact:A worm targeting a vulnerability in the MS SQL Server 2000 Resolution Service was released on January 25th, 2003.  The worm attempts to exploit a buffer overflow in the Resolution Service.  Because of the nature of the vulnerability, the worm is able to attempt to compromise other machines very rapidly.--Detailed Information:The Monitor Service provided by MS SQL and MSDE uses unchecked clientprovided data in an SQL version check function.The worm attempts to exploit a buffer overflow in this version request.If the worm sends too many bytes in the request that triggers the version check, then a buffer overflow condition is triggered resulting in a potential compromise of the SQL Server.--Affected Systems:This vulnerability is present in unpatched MS SQL Servers.  The following unpatched services containing MS SQL or Microsoft Desktop Engine (MSDE) may potentially be compromised by this worm:* SQL Server 2000 (Developer, Standard, and Enterprise Editions)* Visual Studio .NET (Architect, Developer, and Professional Editions)* ASP.NET Web Matrix Tool* Office XP Developer Edition* MSDN Universal and Enterprise subscriptions--Attack Scenarios:This is worm activity.--Ease of Attack:Exploits for this vulnerability have been publicly published.A worm has been written that automatically exploits this vulnerability.--False Positives:None known.--False Negatives:None known.--Corrective Action:Block external access to the MS SQL services on port 1433 and 1434 if possible.Patches from Microsoft are available that fix this vulnerability.  The patches are available fromwww.microsoft.com/technet/security/bulletin/MS02-039.asp--Contributors:Sourcefire Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>-- Additional References:--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -