27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

DNS Tunneling Client Detection (HTTP)<br />

<strong>PVS</strong> ID: 4970 FAMILY: Policy RISK: INFO NESSUS ID:Not Available<br />

Description: The remote client appears to be tunneling traffic over a DNS server. There are a number of<br />

DNS tunneling clients that allow internal hosts to bypass firewall and proxy inspection. As<br />

an example, consider the following observed DNS query: %L<br />

realtime<br />

Solution: Manually inspect both traffic and client to ensure that such usage is in alignment with<br />

existing policies and guidelines.<br />

CVE Not available<br />

DNS Tunneling Server Detection (HTTP)<br />

<strong>PVS</strong> ID: 4971 FAMILY: Policy RISK: INFO NESSUS ID:Not Available<br />

Description: The remote client appears to be a server that is used to tunnel traffic. There are a number of<br />

DNS tunneling clients that allow internal hosts to bypass firewall and proxy inspection. As<br />

an example, consider the following observed DNS query: %P\n\nFollowed by the<br />

following DNS response: %L<br />

realtime<br />

Solution: Manually inspect both traffic and client to ensure that such usage is in alignment with<br />

existing policies and guidelines.<br />

CVE Not available<br />

DNS Tunneling Server Detection (HTTP)<br />

<strong>PVS</strong> ID: 4972 FAMILY: Policy RISK: INFO NESSUS ID:Not Available<br />

Description: The remote client appears to be a server that is used to tunnel traffic. There are a number of<br />

DNS tunneling clients that allow internal hosts to bypass firewall and proxy inspection. As<br />

an example, consider the following observed DNS query: %P\n\nFollowed by the<br />

following DNS response: %L<br />

realtime<br />

Solution: Manually inspect both traffic and client to ensure that such usage is in alignment with<br />

existing policies and guidelines.<br />

CVE Not available<br />

Synergy Protocol Server Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 4973 FAMILY: Generic RISK: INFO NESSUS ID:Not Available<br />

Family Internet Services 1313

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!