12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

350 IDS eventsIntrusion attemptsAffected:Hosts running SNMP agents or managers.False Positives: None known.<strong>Reference</strong>s:RFC 1155 - SNMP v1 SpecificationsRFC 1157 - SNMP v1 SpecificationsRFC 1212 - SNMP v1 SpecificationsRFC 1901 - SNMP v2c SpecificationsRFC 1902 - SNMP v2c SpecificationsRFC 1903 - SNMP v2c SpecificationsRFC 1904 - SNMP v2c SpecificationsRFC 1905 - SNMP v2c SpecificationsRFC 1906 - SNMP v2c SpecificationsRFC 1907 - SNMP v2c SpecificationsRFC 1908 - SNMP v2c SpecificationsRFC 2571 - SNMP v3 SpecificationsRFC 2572 - SNMP v3 SpecificationsRFC 2573 - SNMP v3 SpecificationsRFC 2574 - SNMP v3 SpecificationsRFC 2575 - SNMP v3 SpecificationsSNMP FAQTelnet LD ExploitBase Event:Details:Response:Affected:TELNET_LD_ENVIRONMENTLD environment variables were detected in a Telnet session. LD environment variables are used tofool insecure remote hosts into loading alternatives to system libraries. This may be an attempt tocompromise the victim system.Location and audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>s:Can-1999-0073http://www.whitehats.com (arachNIDS #367)Telnet SpecificationsTelnet RESOLV ExploitBase Event:Details:Response:TELNET_RESOLV_ENVIRONMENTAn attempt was made to influence the resolver libraries on the remote host through the passing ofRESOLVE* environment variables. This event is very similar to the TELNET_LD_ENVIRONMENTevent. LD environment variables are used to fool insecure remote hosts into loading alternatives tosystem libraries. This is an attempt to compromise the victim system.Location and audit of client and server is recommended.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!