📄 402.txt
字号:
Rule: --Sid:402--Summary:This event is generated when an ICMP Port Unreachable message was detected.--Impact:Unknown.--Detailed Information:An ICMP Port Unreachable is not an attack, but may indicate that the sourceof the packet was the target of a scan or other malicious activity.An ICMP Port Unreachable (ICMP type 3 code 3) indicates that someone orsomething tried to connect to a port on a system that was not available(i.e., no service was running on that port).This is analagous to RST packets in TCP. Since UDP does not have anequivalent, it relies upon ICMP Port Unreachable for this. This oftenindicates someone was scanning for UDP services.--Affected Systems: All systems --Attack Scenarios:An attacker may use a port scanner to determine possible attack vectorsas a prelude to a directed attack against a system.--Ease of Attack:Simple.--False Positives:This kind of packet is common on networks, and may be generated by simplemisconfigurations on either the source or destination, or service outage.--False Negatives:Not all operating systems will respond with ICMP Port Unreachablemessages when no service is running.--Corrective Action:Examine the activity of the recipient of this packet to see if therecipient was responsible for scanning or other behavior.--Contributors:Original rule writer unknownOriginal document author unkownSourcefire Vulnerability Research TeamNigel Houghton <nigel.houghton@sourcefire.com>--References:RFC 792:http://www.faqs.org/rfcs/rfc792.html--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -