我们目前正在建立McAfee暹粒。使用签名ID设置了一些规则。下面是经常触发的警报:
Summary: Signature ID 'Suspicious - Remote Shell Communication with Suspicious Host - Event or Flow' (47-4000180) match found The following events were found
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Source IP = 93.116.127.108 // below is the list of source IPs
Destination IP = 135.10.194.xxx //(xxx-changes)
93.116.127.108
106.186.31.135
106.184.2.29
61.150.126.243
46.151.52.231
122.52.49.214
169.228.66.91
60.248.45.40
106.184.2.29
106.186.31.135
47.18.82.224
71.6.146.186
106.186.31.135
175.193.11.61
106.186.31.135
Source Port = 38974
Destination Port = 23
pass 1
Source User = Root (Always)
Destination User = (Blank always)
Source Geolocation=Chisinau, Chisinau, Moldova, unknown
Destination Geolocation=*****************, United States, ********
Eventcount = 1
First Event - 04/11/2016 23:19:52
Last Event - 04/11/2016 23:19:52
Message - Suspicious - Remote Shell Communication with Suspicious Host - Event or Flow
Application - telnet
Average Severity = 75
Signature ID = 47-4000180请帮助我理解,为什么我要得到这个,应该做些什么来解决这个问题。
发布于 2016-05-19 19:06:18
似乎有人正试图强行向您的主机强制用户名/密码或其他恶意连接。无论哪种方式,您都不应该让telnet打开,因为它非常不安全。您需要立即禁用主机上的端口23。
https://security.stackexchange.com/questions/123539
复制相似问题