12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

370 IDS eventsSuspicious activityDNS Malformed DataBase Event:Details:Response:Affected:DNS_RUNT_PACKETOver TCP DNS this event indicates that a DNS packet specified a packet length that was shorterthan the DNS packet header.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sDNS SpecificationsFaxSurvey CGI Passwd AccessBase Event:Details:Response:Affected:HTTP_FAXSURVEY_ACCESSHylafax is a popular Fax server software package designed to run on multiple UNIX operatingsystems.Unpatched versions of Hylafax ship with an insecure script, Faxsurvey, which allows for remotecommand execution, with the privileges of the Web server process.This vulnerability is exploited by passing the command as a parameter to the script. See the exploitfor further details.Consequences could include Web site defacement, exploitation of locally accessible vulnerabilitiesto gain further privileges, and so on.Disable the affected script and/or upgrade to a newer version of Hylafax.Hylafax Hylafax 4.0pl2.False Positives: None known.<strong>Reference</strong>s <strong>Security</strong> Focus BID: 2056Hylafax HomepageFinger Malformed DataBase Event:Details:Response:Affected:FINGER_BAD_REQUESTA request was made that wasn't a finger request.If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sFinger Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!