|
The following are TCP application
signatures:
- Capture password file:
- 2101—FTP "RETR
passwd" (severity 5, access): This signature is
triggered by a string "passwd" issued during
an FTP session. It may indicate someone attempting to
retrieve the password file from a machine in order to
crack it and gain unauthorized access to system
resources.
- Attempt loadmodule Attack
- 2301—Telnet
"IFS=/" (severity 5, access): This signature
is triggered by an attempt to change the IFS to / is
done during a telnet session. This may indicate an
attempt to gain unauthorized access to system
resources.
- 51301—Rlogin
"IFS=/" (severity 5, access): This signature
is triggered when an attempt to change the IFS to / is
done during a rlogin session. This may indicate an
attempt to gain unauthorized access to system
resources.
- Enable unrestricted
r-service access
- 2303—Telnet "+
+" (severity 1, access): This signature is
triggered by string "+ +" issued during a
telnet session.
- 51303—Rlogin "+
+" (severity 1, access): This signature is
triggered by string "+ +" issued during a
rlogin session.
- Access UNIX shadow password
file
- 2302—Telnet
"/etc/shadow" (severity 5, access): This
signature is triggered by a string
"/etc/shadow" issued during a Telnet
session. This may indicate an attempt to gain
unauthorized access to system resources.
- 51302—Rlogin
"/etc/shadow" (severity 5, access): This
signature is triggered on a string
"/etc/shadow" issued during a rlogin
session. This may indicate an attempt to gain
unauthorized access to system resources.
|