The following are more RPC attack
signatures:
-
- 6150—ypserv (severity 1 access):
This signature is triggered when a request is made to the
portmapper for the YP server daemon (ypserv) port. The ypserv
daemon is responsible for looking up information maintained in NIS
maps. This may indicate an attempt to gain unauthorized access to
system resources.
- 6151—ypbind (severity 1 access):
This signature is triggered when a request is made to the
portmapper for the YP bind daemon (ypbind) port. The ypbind daemon
is responsible for maintaining the information needed for a client
process to communicate with a ypserv process. This may indicate an
attempt to gain unauthorized access to system resources.
- 6152—yppasswd (severity 1 access):
This signature is triggered when a request is made to the
portmapper for the YP password daemon (yppasswdd) port. The YP
password daemon allows users to remotely modify password files.
This may indicate an attempt to gain unauthorized access to system
resources.
- 6153—ypupdated (severity 1
access): This signature is triggered when a request is made to the
portmapper for the YP update daemon (ypupdated) port. The YP
update daemon is responsible for updating local NIS maps. This may
indicate an attempt to gain unauthorized access to system
resources.
- 6154—ypxfrd (severity 1 access):
This signature is triggered when a request is made to the
portmapper for the YP transfer daemon (ypxfrd) port. The YP
transfer daemon is responsible for transferring NIS information on
behalf of ypserv. This may indicate an attempt to gain
unauthorized access to system resources.
- 6155—mountd (severity 1 access):
This signature is triggered when a request is made to the
portmapper for the mount daemon (mountd) port. This is the NFS
daemon that is responsible for processing mount requests. This may
indicate an attempt to gain unauthorized access to system
resources.
- 6175—rexd (severity 3, access):
This signature is triggered when a request is made to the
portmapper for the remote execution daemon (rexd) port. The remote
execution daemon is the server responsible for remote program
execution. This may indicate an attempt to gain unauthorized
access to system resources.
- 6180—rexd attempt (severity 5,
access): This signature is triggered when a call to the rexd
program is made. The remote execution daemon is the server
responsible for remote program execution. This may indicate an
attempt to gain unauthorized access to system resources.
- 6190—statd (severity 5, access):
This signature is triggered when a large statd request is sent.
This could be an attempt to overflow a buffer and gain access to
system resources.
- 6191—ttdb (severity 5, access):
This signature is triggered when an attempt is made to overflow an
internal buffer in the tooltalk rpc program.
- 6192—mountd (severity 5, access):
This signature is triggered by an attempt to overflow a buffer in
the RPC mountd application. This may result in unauthorized access
to system resources.
- 6193—cmsd (severity 5, access):
This signature fires when an attempt is made to overflow an
internal buffer in the Calendar Manager Service Daemon, rpc.cmsd.
This vulnerability can allow a remote attacker to gain root
access.
- 6194—sadmind (severity 5, access):
This signature fires when a call to RPC program number 100232
procedure 1 with a UDP packet length > 1024 bytes is detected.
This vulnerability can allow a remote attacker to gain root
access.
- 6195—amd (severity 5, access): The
trigger for this signature is an RPC call to the berkeley
automounter daemons rpc program (300019) procedure 7 with a UDP
length > 1024 or a TCP stream length > 1024. The TCP stream
length is defined by the contents of the two bytes preceding the
RPC header in a TCP packet. This vulnerability can allow a remote
attacker to gain root access.
|
|