12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsIntrusion attempts307Affected:No specific targets.False Positives: None known.<strong>Reference</strong>s:HTTP SpecificationsFinger BackdoorBase Event:Details:Response:Affected:FINGER_CDK_BACKDOORAttempt to access the well known CDK back door on the finger port was detected.Location and audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>s:Can-1990-0660http://www.whitehats.com (arachNIDS #263)Finger SpecificationsFinger BackdoorBase Event:Details:Response:Affected:FINGER_CMD_ROOTSH_BACKDOORAttempt to access the well known back door on the finger port was detected.Location and audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>s:Finger SpecificationsFinger Exploit AttemptBase Event:FINGER_ILLEGAL_METACHARDetails: An attempt was made to finger something with a common shell meta char (for example, “&” or “;”)which is used to pass commands through to the executing shell. Affects EMC DG/UX 5.4 4.11MU02.Response:Affected:If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>s:Can-1990-0612http://www.whitehats.com (arachNIDS #380)Finger SpecificationsFTP Bad UsernameBase Event:Details:Response:FTPCLI_USER_BINFTP client logon attempt was made using a “bad” user name (bin). This may indicate an attempt tocompromise the FTP server.If seen in sufficient volume or variation audit of client is recommended.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!