TAILIEUCHUNG - Intrusion Detection Patterns 2

Take a look at the destination port in the first log entry on the slide. Port 22 means Secure Shell (SSH), right? Not quite, since in this case the transport protocol is UDP, which is not generally used for SSH traffic. A UDP port 22 connection attempt, especially when followed by an almost immediate connection to UDP port 5632 is almost always indicative of a pcAnywhere probe. | Intrusion Detection Patterns 2 Network Vulnerability Scanning Network Mapping IDIC - SANS GIAC LevelTwo 2000 2001 1 Hello and welcome to the second section in a series that examine intrusion detection patterns that we have assembled in the last few years. In the previous section we discussed some of the errors often made by analysts in the heat of the battle and in this section we will concentrate on scanning and mapping activities that have become so common on the Internet. Please turn your attention to the next slide titled pcAnywhere. 1 pcAnywhere Dec 24 18 02 13 cc1014244-a kernel securityalert udp if ef0 from attacker8 1044 to victim on unserved port 22 Dec 24 18 03 15 cc1014244-a kernel securityalert udp if ef0 from attacker8 1046 to victim on unserved port 5632 IDIC - SANS GIAC LevelTwo 2000 2001 2 Take a look at the destination port in the first log entry on the slide. Port 22 means Secure Shell SSH right Not quite since in this case the transport protocol is UDP which is not generally used for SSH traffic. A UDP port 22 connection attempt especially when followed by an almost immediate connection to UDP port 5632 is almost always indicative of a pcAnywhere probe. Take a look at the analysis below performed by Matt Scarborough. Note that different versions of pcAnywhere use different ports when attempting to locate pcAnywhere agents and that it is possible to prevent a pcAnywhere host from answering by modifying an appropriate registry setting. Matt writes Symantec s pcAnywhere client versions and higher can scan a entire subnet for a host by setting the last octet of its host s TCP IP address to 255. Entering multiple subnets is possible. Multiple subnets will be scanned. Trial versions of pcAnywhere are available for download from Symantec. This makes for an attractive hacking tool and might account for some of the increased scans on the following ports. ver - TCP - UDP - 65301 -22 - - - 65301 65301 5631 22 22 5632 - 5631 - .

TỪ KHÓA LIÊN QUAN
TAILIEUCHUNG - Chia sẻ tài liệu không giới hạn
Địa chỉ : 444 Hoang Hoa Tham, Hanoi, Viet Nam
Website : tailieuchung.com
Email : tailieuchung20@gmail.com
Tailieuchung.com là thư viện tài liệu trực tuyến, nơi chia sẽ trao đổi hàng triệu tài liệu như luận văn đồ án, sách, giáo trình, đề thi.
Chúng tôi không chịu trách nhiệm liên quan đến các vấn đề bản quyền nội dung tài liệu được thành viên tự nguyện đăng tải lên, nếu phát hiện thấy tài liệu xấu hoặc tài liệu có bản quyền xin hãy email cho chúng tôi.
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.