This is the snapshot of Snot Latest Rules

源代码在线查看: 681.txt

软件大小: 17049 K
上传用户: nassdaq
关键词: snapshot Latest Rules This
下载地址: 免注册下载 普通下载 VIP

相关代码

				Rule:  								--				Sid: 				681								-- 								Summary: 				This event is generated when a command is issued to an SQL database				server that may result in a serious compromise of the data stored on				that system.								-- 				Impact: 				Serious. An attacker may have gained administrator access to the system.								--				Detailed Information:				This event is generated when an attacker issues a special command to an				SQL database that may result in a serious compromise of all data stored				on that system.								Such commands may be used to gain access to a system with the privileges				of an administrator, delete data, add data, add users, delete users,				return sensitive information or gain intelligence on the server software				for further system compromise.				 				This connection can either be a legitimate telnet connection or the				result of spawning a remote shell as a consequence of a successful				network exploit. 								--				Affected Systems:					Microsoft SQL Servers								--								Attack Scenarios: 				Simple. These are SQL database commands.								-- 								Ease of Attack: 				Simple.								-- 								False Positives: 				This event may be generated by a database administrator logging in and				issuing database commands from a location outside the protected network.								--				False Negatives:				None Known								-- 								Corrective Action: 				Disallow direct access to the SQL server from sources external to the				protected network.								Ensure that this event was not generated by a legitimate session then				investigate the server for signs of compromise								Look for other events generated by the same IP addresses.								--				Contributors: 				Original Rule Writer Unknown				Sourcefire Vulnerability Research Team				Nigel Houghton 								-- 				Additional References:								Microsoft MSDN:				http://msdn.microsoft.com/library/en-us/tsqlref/ts_xp_aa-sz_4jxo.asp								--							

相关资源