📄 295.txt
字号:
SID:295--Rule:--Summary:This event is triggered when an attempt is made to overflow an imapd server.--Impact:Commands may be run on the IMAP server as the root user, This can lead to a complete compromise of the targeted system--Detailed Information:Failure to check the size of the value passed to the 'AUTHENTICATE' command on certain IMAPD implementations can lead to a buffer overflow. This in turn can allow arbitrary commands to be executed on the server.--Affected Systems: Netscape Messaging Server 3.55 University of Washington imapd 10.234--Attack Scenarios:An attacker may attempt to exploit a vulnerable imapd server, permittingthe execution of arbitrary commands possibly with the privilege of user "root".--Ease of Attack:simple. Sample exploit code is available.--False Positives:None known--False Negatives:None known--Corrective Action:Vendors have provided updated versions, upgrading will resolve this problem--Contributors:Snort documentation contributed by matthew harvey <indexone@yahoo.com>Original Rule Writer UnknownSourcefire Research TeamNigel Houghton <nigel.houghton@sourcefire.com>--References:--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -