6.7 6000 Series—Cross-Protocol Signatures
6.7.4 RPC attack signatures
Application attacks include:
  • Reconnaissance
  • Access
  • DoS

The following are RPC attack signatures:

  • 6100—RPC port registration (severity 5, access): This signature is triggered when attempts are made to register new RPC services on a target host. Port registration is the method used by new services to report to the portmapper that they are present and to gain access to a port, this is then advertised by the portmapper. This should not be allowed from a remote host. No known exploit of this function exists. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 6101—RPC port unregistration (severity 5, DoS): This signature is triggered when attempts are made to unregister existing RPC services on a target host. Port unregistration is the method used by services to report to the portmapper that they are no longer present and to remove them from the active port map. This should not be allowed from a remote host. No known exploit of this function exists. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 6102—RPC dump (severity 5, reconnaissance): This signature is triggered when an RPC dump request is issued to a target host. This is a procedure that may be used to determine the presence and port location of RPC services being provided by a system. It is indicative that your network may be under reconnaissance.
  • 6103—Proxied RPC request (severity 1 access): This signature is triggered when a proxied RPC request is sent to the portmapper of a target host. It is a method for requesting RPC services by having a portmapper act as your proxy. This may indicate an attempt to gain unauthorized access to system resources and should not be allowed from hosts outside your network.
  • 6110—RSTAT (severity 5, reconnaissance): This signature is triggered when RPC requests are made to many ports for the RSTATD program.
  • 6111—RUSERS (severity 5, reconnaissance): This signature is triggered when RPC requests are made to many ports for the RUSERSD program.
  • 6112—NFS (severity 5, reconnaissance): This signature is triggered when RPC requests are made to many ports for the NFS program.
  • 6113—MOUNT (severity 5, reconnaissance): This signature is triggered when RPC requests are made to many ports for the MOUNTD program.
  • 6114—YPPASSW (severity 5, reconnaissance): This signature is triggered when RPC requests are made to many ports for the YPPASSWDD program.
  • 6115—SELECTION SV (severity 5, reconnaissance): This signature is triggered when RPC requests are made to many ports for the SELECTION_SVC program.
  • 6116—REX (severity 5, reconnaissance): This signature is triggered when RPC requests are made to many ports for the REXD program.
  • 6117—STATU (severity 5, reconnaissance): This signature is triggered when RPC requests are made to many ports for the STATUS program.
  • 6118—TTDB (severity 5, reconnaissance): This signature is triggered by an attempt to access the tooltalk database daemon on multiple ports on a single host.