Application attacks include:
- Reconnaissance
- Access
- DoS
The following are RPC attack
signatures: 
- 6100—RPC port registration
(severity 5, access): This signature is triggered when attempts
are made to register new RPC services on a target host. Port
registration is the method used by new services to report to the
portmapper that they are present and to gain access to a port,
this is then advertised by the portmapper. This should not be
allowed from a remote host. No known exploit of this function
exists. This does not preclude the possibility that exploits do
exist outside of the realm of Cisco Systems' knowledge domain.
- 6101—RPC port unregistration
(severity 5, DoS): This signature is triggered when attempts are
made to unregister existing RPC services on a target host. Port
unregistration is the method used by services to report to the
portmapper that they are no longer present and to remove them from
the active port map. This should not be allowed from a remote
host. No known exploit of this function exists. This does not
preclude the possibility that exploits do exist outside of the
realm of Cisco Systems' knowledge domain.
- 6102—RPC dump (severity 5,
reconnaissance): This signature is triggered when an RPC dump
request is issued to a target host. This is a procedure that may
be used to determine the presence and port location of RPC
services being provided by a system. It is indicative that your network may be under reconnaissance.
- 6103—Proxied RPC request (severity
1 access): This signature is triggered when a proxied RPC request
is sent to the portmapper of a target host. It is a method for requesting RPC services by having a portmapper act as your proxy.
This may indicate an attempt to gain unauthorized access to
system resources and should not be allowed from hosts outside your
network.
- 6110—RSTAT (severity 5,
reconnaissance): This signature is triggered when RPC requests are
made to many ports for the RSTATD program.
- 6111—RUSERS (severity 5,
reconnaissance): This signature is triggered when RPC requests are
made to many ports for the RUSERSD program.
- 6112—NFS (severity 5,
reconnaissance): This signature is triggered when RPC requests are
made to many ports for the NFS program.
- 6113—MOUNT (severity 5,
reconnaissance): This signature is triggered when RPC requests are
made to many ports for the MOUNTD program.
- 6114—YPPASSW (severity 5,
reconnaissance): This signature is triggered when RPC requests are
made to many ports for the YPPASSWDD program.
- 6115—SELECTION SV (severity 5,
reconnaissance): This signature is triggered when RPC requests are
made to many ports for the SELECTION_SVC program.
- 6116—REX (severity 5,
reconnaissance): This signature is triggered when RPC requests are
made to many ports for the REXD program.
- 6117—STATU (severity 5,
reconnaissance): This signature is triggered when RPC requests are
made to many ports for the STATUS program.
- 6118—TTDB (severity 5,
reconnaissance): This signature is triggered by an attempt to
access the tooltalk database daemon on multiple ports on a single
host.
|