1
|
Nenalezen zadny zaznam:
|
2
|
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$ne": "qotd"}}, {"Source.Proto" : {"$ne": "ssdp"}}, {"Source.Port" : {"$ne": 123}}, {"Source.Proto" : {"$ne": "ntp"}}, {"Source.Proto" : {"$ne": "domain"}}, {"Source.Proto" : {"$ne": "netbios-ns"}}, {"Source.Port" : {"$ne": 623}}, {"Description": {"$ne": "Scan IPMI"}}, {"Source.Proto" : {"$ne": "chargen"}}]}
|
3
|
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_SNMP': 2644,
|
4
|
|
5
|
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Description" : "Proxy_server"}]}
|
6
|
!!! Vulnerable 'Vulnerable_+++_External_+++_Proxy_+++_Proxy_server': 7
|
7
|
|
8
|
---
|
9
|
|
10
|
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}]}
|
11
|
Name Vulnerable Count >= 3066
|
12
|
|
13
|
---
|
14
|
FILTER: {"$and": [{"Category" : "Abusive.Spam"}, {"Node.Type" : {"$eq" : "External"}}, {"Node.Type" : {"$eq": "Data"}}, {"Node.Type" : {"$eq": "Policy"}}, {"Node.SW" : {"$eq" : "UCEPROT"}}]}
|
15
|
!!! 'Abusive.Spam_+++_Data:External:Policy_+++_*__+++_Backscatter_Report': 30,
|
16
|
LABEL_CZ: Host provozuje nesprávně nakonfigurovaný poštovní server (backscatter)
|
17
|
LABEL_EN: Host contains misconfigured mail server (backscatter)
|
18
|
SEVERITY: 1
|
19
|
URL: https://csirt.cesnet.cz/cs/services
|
20
|
|
21
|
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$eq": "qotd"}}]}
|
22
|
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_QOTD': 317,
|
23
|
Name Vulnerable Count >= 56
|
24
|
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (QOTD)
|
25
|
LABEL_EN: Host contains misconfigured service (QOTD)
|
26
|
SEVERITY: 1
|
27
|
URL: https://csirt.cesnet.cz/cs/services
|
28
|
|
29
|
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$eq": "ssdp"}}]}
|
30
|
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_SSDP': 4505,
|
31
|
Name Vulnerable Count >= 555
|
32
|
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (SSDP)
|
33
|
LABEL_EN: Host contains misconfigured service (SSDP)
|
34
|
SEVERITY: 1
|
35
|
URL: https://csirt.cesnet.cz/cs/services
|
36
|
|
37
|
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"$or": [{"Source.Port" : {"$eq": 123}}, {"Source.Proto" : {"$eq": "ntp"}}]}]}
|
38
|
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_NTP': 5876,
|
39
|
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_NTPMONITOR': 89,
|
40
|
Name Vulnerable Count >= 1414
|
41
|
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (NTP)
|
42
|
LABEL_EN: Host contains misconfigured service (NTP)
|
43
|
SEVERITY: 1
|
44
|
URL: https://csirt.cesnet.cz/cs/services
|
45
|
|
46
|
U sserv-016 bych doplnil k protokolu NTP
|
47
|
'Source': [ {
|
48
|
'Port': [123],
|
49
|
'Proto': ['udp']}],
|
50
|
'_CESNET': { 'EventTemplate': 'sserv-016',
|
51
|
|
52
|
---
|
53
|
|
54
|
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$eq": "domain"}}, {"Source.Type" : {"$eq": "Backscatter"}}]}
|
55
|
!!! Vulnerable 'Vulnerable.Config_+++_External_+++_*__+++_Open_DNS_Resolver': 19,
|
56
|
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_Backscatter_+++_Open_DNS_Resolver': 805,
|
57
|
Name Vulnerable Count >= 175
|
58
|
LABEL_CZ: Host provozuje otevřený DNS resolver
|
59
|
LABEL_EN: Host contains Open DNS Resolver
|
60
|
SEVERITY: 1
|
61
|
URL: https://csirt.cesnet.cz/cs/services
|
62
|
|
63
|
Proto: Domain, Source.Type: Backscatter?
|
64
|
'ID': '1-1476412311.069296-BWdlraQwegG0',
|
65
|
'Node': [ {'Name': 'cz.cesnet.au1.warden_filer', 'Type': ['Relay']},
|
66
|
{ 'Name': 'cz.cesnet.ext.x2',
|
67
|
'SW': ['X2'],
|
68
|
'Type': ['External']}],
|
69
|
'Source': [ { 'IP4': [ { 'ip': b'\x93\xfb\x1b\xfe',
|
70
|
'max': b'\x93\xfb\x1b\xfe',
|
71
|
'min': b'\x93\xfb\x1b\xfe'}],
|
72
|
'Proto': ['udp', 'dns']}],
|
73
|
'_CESNET': { 'EventTemplate': 'x2-004',
|
74
|
'Impact': 'System 147.251.27.254 is ORR and can be '
|
75
|
'misused to DDoS attacks',
|
76
|
'ResolvedAbuses': ['abuse@muni.cz'],
|
77
|
'StorageTime': 1476413642},
|
78
|
'_id': '1-1476412311.069296-BWdlraQwegG0',
|
79
|
|
80
|
---
|
81
|
|
82
|
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$eq": "netbios-ns"}}, {"Source.Type" : {"$eq": "Backscatter"}}]}
|
83
|
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_Backscatter_+++_Scan_NETBIOS': 12713,
|
84
|
Name Vulnerable Count >= 544
|
85
|
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (NETBIOS)
|
86
|
LABEL_EN: Host contains misconfigured service (NETBIOS)
|
87
|
SEVERITY: 1
|
88
|
URL: https://csirt.cesnet.cz/cs/services
|
89
|
|
90
|
Chybi "Source.Proto": ipmi
|
91
|
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Port" : {"$eq": 623}}]}
|
92
|
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_IPMI': 2660,
|
93
|
Name Vulnerable Count >= 291
|
94
|
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (IPMI)
|
95
|
LABEL_EN: Host contains misconfigured service (IPMI)
|
96
|
SEVERITY: 1
|
97
|
URL: https://csirt.cesnet.cz/cs/services
|
98
|
|
99
|
'Description': 'Scan IPMI',
|
100
|
Neznamy port a chybi "Source.Proto": ipmi
|
101
|
'Category': ['Vulnerable.Config'],
|
102
|
'CreateTime': b'\xdb\xa0\xa8 \x00\x00\x00\x00',
|
103
|
'Description': 'Scan IPMI',
|
104
|
'DetectTime': b'\xdb\x9e\xc5\xa1\x00\x00\x00\x00',
|
105
|
'Format': 'IDEA0',
|
106
|
'ID': '1-1475750304.823518-clDvseUpKMaG',
|
107
|
'Node': [ {'Name': 'cz.cesnet.au1.warden_filer', 'Type': ['Relay']},
|
108
|
{ 'Name': 'cesnet.au1',
|
109
|
'SW': ['SSERV'],
|
110
|
'Type': ['External', 'Recon']}],
|
111
|
'Source': [ { 'IP4': [ { 'ip': b'\x9e\xc2\xa0\t',
|
112
|
'max': b'\x9e\xc2\xa0\t',
|
113
|
'min': b'\x9e\xc2\xa0\t'}],
|
114
|
'Port': [2296]}],
|
115
|
'_CESNET': { 'EventTemplate': 'sserv-017',
|
116
|
'Impact': 'System provides open Intelligent Platform '
|
117
|
'Management Interface service',
|
118
|
'ResolvedAbuses': ['abuse@upol.cz'],
|
119
|
'StorageTime': 1475750387},
|
120
|
'_id': '1-1475750304.823518-clDvseUpKMaG',
|
121
|
|
122
|
|
123
|
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$eq": "chargen"}}, {"Source.Type" : {"$eq": "Backscatter"}}]}
|
124
|
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_Backscatter_+++_Scan_CHARGEN': 46,
|
125
|
Name Vulnerable Count >= 10
|
126
|
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (CHARGEN)
|
127
|
LABEL_EN: Host contains misconfigured service (CHARGEN)
|
128
|
SEVERITY: 1
|
129
|
URL: https://csirt.cesnet.cz/cs/services
|
130
|
|
131
|
|