12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

358 IDS eventsSignaturesSMTP ProbingBase Event:Details:Response:Affected:SMTP_CLIENT_CYBERCOP_SECURITY_SCANA Cybercop SMTP scan was detected.Location and audit of client is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>s:CAN-1999-0531http://www.whitehats.com (arachNIDS #371)http://www.whitehats.com (arachNIDS #372)SMTP ProbingBase Event:Details:Response:Affected:SMTP_ROOT_INFO_GATHERING_ATTEMPTAn attempt to gather information about the root account through EXPN was detected.The EXPN command should be either disabled or restricted on the server. If seen in volume orvariation location and audit of client is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>sCVE-1999-0531http://www.whitehats.com (arachNIDS #31)SMTP SpecificationsSignaturesBD DeepThroat ActivityBase Event:Details:Response:Affected:DeepThroat is a backdoor program that affects Microsoft Windows 9x and NT machines. It includesan FTP server and various controls that allow malicious actions, such as passwords theft andremote screenshot captures.DeepThroat consists of a client program called “DeepThroat Remote Control” which is run on aremote computer to gain access to any computer on the network. In this case, an executable serverprogram must be installed on the victim’s computer to permit remote access to the victim’scomputer in a manner similar to Netbus, BackOrifice and other internet “Remote administration”Trojan horses.Users should keep current on virus definitions and continue to monitor for DeepThroat on thenetwork using a commercial intrusion detection system (IDS).Microsoft Windows 9x and NT Machines.False Positives: None known.<strong>Reference</strong>sCAN-1999-0660

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!