snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具

源代码在线查看: 3011.txt

软件大小: 771 K
上传用户: lihuitao1987
关键词: snort Snort 2.4 入侵检测
下载地址: 免注册下载 普通下载 VIP

相关代码

				Rule: 								--				Sid: 				3011				-- 				Summary: 				This event is generated when an attempt is made to find the System				directory on a target host with the RUX the Tick Trojan.								-- 				Impact: 				If successful, the attacker would gain unauthorized access to the system,				to upload and execute file on the target system. The attacker can use				this function to upload additional backdoors to the victim's system and				execute them.								--				Detailed Information:				When executed, RUX the Tick opens up its assigned port (default is				22222) for communication with the attacker. RUX the Tick has three				functions: Get Windows Directory, Get System Directory, and Upload And				Execute File. Get Windows Directory and Get System Directory are used				for reconnaissance. Upload And Execute File is mainly used to upload and				run other backdoors onto the victim's computer.								--				Affected Systems:					Windows 95/98/ME/NT/2000								--				Attack Scenarios: 				The victim must first install the server. Be wary of suspicious files				because they often can be backdoors in disguise. Once the victim				mistakenly installs the server program, the attacker usually will employ				an IP scanner program to find the IP addresses of victims that have				installed the program. Then the attacker enters the IP address, port				number (which  is assigned to the server program by the attacker:				default is 22222), and presses the connect button and he has access to				the computer.								-- 								Ease of Attack: 				Simple.								-- 				False Positives:				None known								--				False Negatives:				None known								-- 				Corrective Action: 				Using Windows Task Manager, kill these processes: ruxserver.exe and server.exe.				Use Windows Explorer to find ruxserver.exe and delete the file.								Keep anti-virus programs updated with the latest definitions.								--				Contributors:				Sourcefire Research Team				Ricky Macatee 								-- 				Additional References:								PestPatrol:				http://www.pestpatrol.com/PestInfo/R/RUX.ASP								--							

相关资源