6.7 6000 Series—Cross-Protocol Signatures
6.7.5 RPC attack signatures (cont.)
The following are more RPC attack signatures: -
  • 6150—ypserv (severity 1 access): This signature is triggered when a request is made to the portmapper for the YP server daemon (ypserv) port. The ypserv daemon is responsible for looking up information maintained in NIS maps. This may indicate an attempt to gain unauthorized access to system resources.
  • 6151—ypbind (severity 1 access): This signature is triggered when a request is made to the portmapper for the YP bind daemon (ypbind) port. The ypbind daemon is responsible for maintaining the information needed for a client process to communicate with a ypserv process. This may indicate an attempt to gain unauthorized access to system resources.
  • 6152—yppasswd (severity 1 access): This signature is triggered when a request is made to the portmapper for the YP password daemon (yppasswdd) port. The YP password daemon allows users to remotely modify password files. This may indicate an attempt to gain unauthorized access to system resources.
  • 6153—ypupdated (severity 1 access): This signature is triggered when a request is made to the portmapper for the YP update daemon (ypupdated) port. The YP update daemon is responsible for updating local NIS maps. This may indicate an attempt to gain unauthorized access to system resources.
  • 6154—ypxfrd (severity 1 access): This signature is triggered when a request is made to the portmapper for the YP transfer daemon (ypxfrd) port. The YP transfer daemon is responsible for transferring NIS information on behalf of ypserv. This may indicate an attempt to gain unauthorized access to system resources.
  • 6155—mountd (severity 1 access): This signature is triggered when a request is made to the portmapper for the mount daemon (mountd) port. This is the NFS daemon that is responsible for processing mount requests. This may indicate an attempt to gain unauthorized access to system resources.
  • 6175—rexd (severity 3, access): This signature is triggered when a request is made to the portmapper for the remote execution daemon (rexd) port. The remote execution daemon is the server responsible for remote program execution. This may indicate an attempt to gain unauthorized access to system resources.
  • 6180—rexd attempt (severity 5, access): This signature is triggered when a call to the rexd program is made. The remote execution daemon is the server responsible for remote program execution. This may indicate an attempt to gain unauthorized access to system resources.
  • 6190—statd (severity 5, access): This signature is triggered when a large statd request is sent. This could be an attempt to overflow a buffer and gain access to system resources.
  • 6191—ttdb (severity 5, access): This signature is triggered when an attempt is made to overflow an internal buffer in the tooltalk rpc program.
  • 6192—mountd (severity 5, access): This signature is triggered by an attempt to overflow a buffer in the RPC mountd application. This may result in unauthorized access to system resources.
  • 6193—cmsd (severity 5, access): This signature fires when an attempt is made to overflow an internal buffer in the Calendar Manager Service Daemon, rpc.cmsd. This vulnerability can allow a remote attacker to gain root access.
  • 6194—sadmind (severity 5, access): This signature fires when a call to RPC program number 100232 procedure 1 with a UDP packet length > 1024 bytes is detected. This vulnerability can allow a remote attacker to gain root access.
  • 6195—amd (severity 5, access): The trigger for this signature is an RPC call to the berkeley automounter daemons rpc program (300019) procedure 7 with a UDP length > 1024 or a TCP stream length > 1024. The TCP stream length is defined by the contents of the two bytes preceding the RPC header in a TCP packet. This vulnerability can allow a remote attacker to gain root access.