12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IDS eventsIntrusion attempts333PHP mlog AccessBase Event:Details:Response:Affected:HTTP_URL_SIG10An attempt to access the “mlog.phtml” file was detected. The “mlog.phtml” file is an example forthe PHP script language. The default examples lack sufficient checking to the input arguments andmay be exploited to read all the files accessible to the Web server processes. The scan utilityWhisker has been known to attempt access of “mlog.phtml”.Location and audit of client and server is recommended. You should also disable the mlog.phtmlscripts on the server.No specific targets.False Positives: None known.<strong>Reference</strong>s:CVE-1999-0346HTTP SpecificationsPOP3 Buffer OverflowBase Event:Details:POP3_CLIENT_LONG_COMMANDThe POP3 client sent a command that exceeded the maximum permitted length. This violation ofthe standard could indicate an attempt to compromise the protocol.POP3 Buffer OverflowBase Event:Details:POP3_SERVER_LONG_LINEThe POP3 server exceeded maximum permitted line length in a response. This violation of thestandard could indicate an attempt to compromise the protocol.POP3 User “root”Base Event:Details:POP3_USER_ROOTThe POP3 client attempted to log into the POP3 server with the username of “root”. This may be anattempt to access restricted resources or compromise the server.Rlogin Exploit AttemptBase Event:Details:Response:Affected:RLOGIN_FROOT_EXPLOIT_ATTEMPTEDA logon name of “-froot” was used. This flag is passed to the login program to bypass logoncredentials and log in as root on vulnerable hosts.If seen in sufficient volume or variation audit of client and server is recommended. Examination ofthe packet contents may provide some additional information about the particular command.No specific targetsFalse Positives: None known.<strong>Reference</strong>s:CAN-1999-0651Rlogin Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!