Project

General

Profile

Feature #2903 » vulnerable.txt

Radomír Orkáč, 10/17/2016 09:58 PM

 
1
Nenalezen zadny zaznam:
2
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$ne": "qotd"}}, {"Source.Proto" : {"$ne": "ssdp"}}, {"Source.Port" : {"$ne": 123}}, {"Source.Proto" : {"$ne": "ntp"}}, {"Source.Proto" : {"$ne": "domain"}}, {"Source.Proto" : {"$ne": "netbios-ns"}}, {"Source.Port" : {"$ne": 623}}, {"Description": {"$ne": "Scan IPMI"}}, {"Source.Proto" : {"$ne": "chargen"}}]}
3
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_SNMP': 2644,
4

    
5
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Description" : "Proxy_server"}]}
6
!!! Vulnerable 'Vulnerable_+++_External_+++_Proxy_+++_Proxy_server': 7
7

    
8
---
9

    
10
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}]}
11
Name Vulnerable Count >= 3066
12

    
13
---
14
FILTER: {"$and": [{"Category" : "Abusive.Spam"}, {"Node.Type" : {"$eq" : "External"}}, {"Node.Type" : {"$eq": "Data"}}, {"Node.Type" : {"$eq": "Policy"}}, {"Node.SW" : {"$eq" : "UCEPROT"}}]}
15
!!! 'Abusive.Spam_+++_Data:External:Policy_+++_*__+++_Backscatter_Report': 30,
16
LABEL_CZ: Host provozuje nesprávně nakonfigurovaný poštovní server (backscatter)
17
LABEL_EN: Host contains misconfigured mail server (backscatter)
18
SEVERITY: 1 
19
URL: https://csirt.cesnet.cz/cs/services
20

    
21
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$eq": "qotd"}}]}
22
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_QOTD': 317,
23
Name Vulnerable Count >= 56
24
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (QOTD)
25
LABEL_EN: Host contains misconfigured service (QOTD)
26
SEVERITY: 1 
27
URL: https://csirt.cesnet.cz/cs/services
28

    
29
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$eq": "ssdp"}}]}
30
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_SSDP': 4505,
31
Name Vulnerable Count >= 555
32
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (SSDP)
33
LABEL_EN: Host contains misconfigured service (SSDP)
34
SEVERITY: 1 
35
URL: https://csirt.cesnet.cz/cs/services
36

    
37
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"$or": [{"Source.Port" : {"$eq": 123}}, {"Source.Proto" : {"$eq": "ntp"}}]}]}
38
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_NTP': 5876,
39
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_NTPMONITOR': 89,
40
Name Vulnerable Count >= 1414
41
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (NTP)
42
LABEL_EN: Host contains misconfigured service (NTP)
43
SEVERITY: 1 
44
URL: https://csirt.cesnet.cz/cs/services
45

    
46
U sserv-016 bych doplnil k protokolu NTP
47
    'Source': [   { 
48
                      'Port': [123],
49
                      'Proto': ['udp']}],
50
    '_CESNET': {   'EventTemplate': 'sserv-016',
51

    
52
---
53

    
54
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$eq": "domain"}}, {"Source.Type" : {"$eq": "Backscatter"}}]}
55
!!! Vulnerable 'Vulnerable.Config_+++_External_+++_*__+++_Open_DNS_Resolver': 19,
56
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_Backscatter_+++_Open_DNS_Resolver': 805,
57
Name Vulnerable Count >= 175
58
LABEL_CZ: Host provozuje otevřený DNS resolver
59
LABEL_EN: Host contains Open DNS Resolver
60
SEVERITY: 1 
61
URL: https://csirt.cesnet.cz/cs/services
62

    
63
Proto: Domain, Source.Type: Backscatter?
64
    'ID': '1-1476412311.069296-BWdlraQwegG0',
65
    'Node': [   {'Name': 'cz.cesnet.au1.warden_filer', 'Type': ['Relay']},
66
                {   'Name': 'cz.cesnet.ext.x2',
67
                    'SW': ['X2'],
68
                    'Type': ['External']}],
69
    'Source': [   {   'IP4': [   {   'ip': b'\x93\xfb\x1b\xfe',
70
                                     'max': b'\x93\xfb\x1b\xfe',
71
                                     'min': b'\x93\xfb\x1b\xfe'}],
72
                      'Proto': ['udp', 'dns']}],
73
    '_CESNET': {   'EventTemplate': 'x2-004',
74
                   'Impact': 'System 147.251.27.254 is ORR and can be '
75
                             'misused to DDoS attacks',
76
                   'ResolvedAbuses': ['abuse@muni.cz'],
77
                   'StorageTime': 1476413642},
78
    '_id': '1-1476412311.069296-BWdlraQwegG0',
79

    
80
---
81

    
82
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$eq": "netbios-ns"}}, {"Source.Type" : {"$eq": "Backscatter"}}]}
83
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_Backscatter_+++_Scan_NETBIOS': 12713,
84
Name Vulnerable Count >= 544
85
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (NETBIOS)
86
LABEL_EN: Host contains misconfigured service (NETBIOS)
87
SEVERITY: 1 
88
URL: https://csirt.cesnet.cz/cs/services
89

    
90
Chybi "Source.Proto": ipmi 
91
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Port" : {"$eq": 623}}]}
92
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_*__+++_Scan_IPMI': 2660,
93
Name Vulnerable Count >= 291
94
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (IPMI)
95
LABEL_EN: Host contains misconfigured service (IPMI)
96
SEVERITY: 1 
97
URL: https://csirt.cesnet.cz/cs/services
98

    
99
'Description': 'Scan IPMI',
100
Neznamy port a chybi "Source.Proto": ipmi 
101
    'Category': ['Vulnerable.Config'],
102
    'CreateTime': b'\xdb\xa0\xa8 \x00\x00\x00\x00',
103
    'Description': 'Scan IPMI',
104
    'DetectTime': b'\xdb\x9e\xc5\xa1\x00\x00\x00\x00',
105
    'Format': 'IDEA0',
106
    'ID': '1-1475750304.823518-clDvseUpKMaG',
107
    'Node': [   {'Name': 'cz.cesnet.au1.warden_filer', 'Type': ['Relay']},
108
                {   'Name': 'cesnet.au1',
109
                    'SW': ['SSERV'],
110
                    'Type': ['External', 'Recon']}],
111
    'Source': [   {   'IP4': [   {   'ip': b'\x9e\xc2\xa0\t',
112
                                     'max': b'\x9e\xc2\xa0\t',
113
                                     'min': b'\x9e\xc2\xa0\t'}],
114
                      'Port': [2296]}],
115
    '_CESNET': {   'EventTemplate': 'sserv-017',
116
                   'Impact': 'System provides open Intelligent Platform '
117
                             'Management Interface service',
118
                   'ResolvedAbuses': ['abuse@upol.cz'],
119
                   'StorageTime': 1475750387},
120
    '_id': '1-1475750304.823518-clDvseUpKMaG',
121

    
122

    
123
"filter": {"$and": [{"DetectTime" : {"$gte" : "{gte}"}}, {"DetectTime" : {"$lte" : "{lte}"}}, {"Category" : "Vulnerable.Config"}, {"Source.Proto" : {"$eq": "chargen"}}, {"Source.Type" : {"$eq": "Backscatter"}}]}
124
!!! Vulnerable 'Vulnerable.Config_+++_External:Recon_+++_Backscatter_+++_Scan_CHARGEN': 46,
125
Name Vulnerable Count >= 10
126
LABEL_CZ: Host provozuje nesprávně nakonfigurovanou službu (CHARGEN)
127
LABEL_EN: Host contains misconfigured service (CHARGEN)
128
SEVERITY: 1 
129
URL: https://csirt.cesnet.cz/cs/services
130

    
131

    
(3-3/7)