EmergingThreats> Main Web>2002917 (revision 2)EditAttach

alert tcp $HOME_NET any -> any any (msg:"BLEEDING-EDGE EXPLOIT RealVNC? Server Authentication Bypass Successful"; flowbits:isset,BSvnc.null.auth.sent; flow:established; dsize:4; content:"|00 00 00 00|"; depth:4; classtype:successful-admin; flowbits:unset,BSis.vnc.setup; flowbits:unset,BSvnc.auth.offered; reference:url,secunia.com/advisories/20107/; reference:url,archives.neohapsis.com/archives/fulldisclosure/2006-05/0356.html; reference:cve,2006-2369; sid:2002917; rev:3;)


This rule is part of the class succesful-admin. The default priority is therefore 1. Shouldn't it be increased to 2 or maybe 3?

-- CeesElzinga - 03 May 2007


Edit | Attach | Print version | History: r3 < r2 < r1 | Backlinks | Raw View | Raw edit | More topic actions...
Topic revision: r2 - 2007-05-03 - CeesElzinga
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats