Пример атаки
Угрозы, уязвимости и атаки
Статистика выявления уязвимостей
Классификация атак в IP- сетях
Top 10
Linux Buffer Overflows Wu-ftp BO IMAP BO Qpopper BO Overwrite stack Common script kiddie exploits Poor coding standards
Top 10
Уязвимости BIND BIND qinv Compile flag turned on by default, activated buffer-overflow, client request to server, script kiddie BIND nxt Server to server response, buffer handling overflowable, more advanced Exposure outside firewall In.Named binary
RPC (Remote Procedure Calls) rpc.cmsd (sun-rpc.cmsd) rpc-statd (sun-rpc-statd) Sadmin (sol-sadmind-amslverify-bo) Amd (amd-bo) Mountd (linux-mountd-bo) Major script kiddie fodder Helped Enabled DDOS
File Sharing Netbios NFS Impact is Affecting Cable Modem and DSL Users Sensitive info – I.e., Banking account Backdoor install + + Rhosts для Unix - серверов
Электронная почта Sendmail Pipe Attack (smtp-pipe) Sendmail MIMEbo “root access” (sendmail-mime-bo2) Incoming viruses, LOVE Many localhost getroot exploits for sendmail Attacks may by-pass firewalls that allow incoming email directly to internal
E-business Web Applications NetscapeGetBo (netscape-get-bo) “control server” HttpIndexserverPath (http-indexserver-path) “path info” Frontpage Extensions (frontpage-ext) “readable passwords” FrontpagePwdAdministrators (frontpage-pwd-administrators) “reveal pwd”
Top 10
Open Databases Oracle default account passwords Oracle setuid root oratclsh SQL Server Xp_sprintf buffer overflow SQL Server Xp_cmdshell extended
IIS (Microsoft Internet Information Server) RDS HTR Malformed header Htdig Remote Shell Execution PWS File Access CGI Lasso “read arbitrary files” PHP3 safe mode metachar remote execution PHP mlog.html read files
Слабые пароли Бюджеты по умолчанию Routers Servers No set Passwords for admin/root accounts SNMP with public/private community strings set
Атаки «Denial of Service» Trinity TFN TFN2k Trin00 Stacheldraht FunTime Windows platform (W9x/2K/NT) Preprogrammed for specific time and target All are distributed for maximum effect