⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 2251.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule:  --Sid:2251--Summary:This event is generated when an attempt is made to exploit a knownvulnerablity in Microsoft RPCSS service for RPC.--Impact:Denial of Service. Possible execution of arbitrary code leading tounauthorized remote administrative access.--Detailed Information:A vulnerability exists in Microsoft RPCSS Service that handles RPC DCOMrequests such that execution of arbitrary code or a Denial of Service condition can be issued against a host by sending malformed data via RPC.The Distributed Component Object Model (DCOM) handles DCOM requests sentby clients to a server using RPC. A malformed request to the hostrunning the RPCSS service may result in a buffer overflow condition thatwill present the attacker with the opportunity to execute arbitrary codewith the privileges of the local system account. Alternatively theattacker could also cause the RPC service to stop answering RPC requestsand thus cause a Denial of Service condition to occur.--Affected Systems:	Windows NT 4.0 Workstation and Server	Windows NT 4.0 Terminal Server Edition	Windows 2000	Windows XP	Windows Server 2003--Attack Scenarios:An attacker may make a DCERPC bind request followed by a maliciousDCERPC DCOM remote activation request.--Ease of Attack:Simple. Expoit code exists.--False Positives:None known.--False Negatives:None known.--Corrective Action:Apply the appropriate vendor supplied patches.Block access to RPC ports 135, 139, 445 and 593 for both TCP and UDP protocols from external sources using a packet filtering firewall.Disallow the use of RPC over HTTP and HTTPS.--Contributors:Sourcefire Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>-- Additional References:Microsoft:http://www.microsoft.com/technet/security/bulletin/MS03-039.aspeEye:http://www.eeye.com/html/Research/Advisories/AD20030910.html--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -