27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Successful Shell Attack Detected - Unix Failed 'tcpdump' Command<br />

<strong>PVS</strong> ID: 6157 FAMILY: Generic RISK: HIGH NESSUS ID:Not Available<br />

Description: A failed 'tcpdump' command occurred in a TCP session normally used for a standard<br />

service.<br />

realtimeonly<br />

Solution: The command activity observed is indicative of a possible compromise. Consider<br />

performing a full audit of the system to investigate further.<br />

CVE Not available<br />

Successful Shell Attack Detected - Unix Failed 'which' Command<br />

<strong>PVS</strong> ID: 6158 FAMILY: Generic RISK: HIGH NESSUS ID:Not Available<br />

Description: A failed 'which' command occurred in a TCP session normally used for a standard service.<br />

realtimeonly<br />

Solution: The command activity observed is indicative of a possible compromise. Consider<br />

performing a full audit of the system to investigate further.<br />

CVE Not available<br />

Successful Shell Attack Detected - Unix Failed 'which' Command<br />

<strong>PVS</strong> ID: 6159 FAMILY: Generic RISK: HIGH NESSUS ID:Not Available<br />

Description: A failed 'which' command occurred in a TCP session normally used for a standard service.<br />

realtimeonly<br />

Solution: The command activity observed is indicative of a possible compromise. Consider<br />

performing a full audit of the system to investigate further.<br />

CVE Not available<br />

Successful Shell Attack Detected - Unix SSH Initial Connetion Detection<br />

<strong>PVS</strong> ID: 6160 FAMILY: Generic RISK: HIGH NESSUS ID:Not Available<br />

Description: An SSH session was observed which may be an initial connection which may also be<br />

present in a command line shell of a successful buffer overflow.<br />

realtimeonly<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Solution: The command activity observed is indicative of a possible compromise. Consider<br />

performing a full audit of the system to investigate further.<br />

Family Internet Services 1681

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!