From 97d5f8f28d0fc5780dbeb19599dee2c5776613a2 Mon Sep 17 00:00:00 2001 From: BlackLight Date: Wed, 15 Sep 2010 14:10:01 +0200 Subject: [PATCH] New correlation rules, now installing doc and share stuff --- corr_rules/1-1924-8.xml | 14 ++++++++++++++ corr_rules/1-579-10.xml | 14 ++++++++++++++ 2 files changed, 28 insertions(+) create mode 100644 corr_rules/1-1924-8.xml create mode 100644 corr_rules/1-579-10.xml diff --git a/corr_rules/1-1924-8.xml b/corr_rules/1-1924-8.xml new file mode 100644 index 0000000..3963b99 --- /dev/null +++ b/corr_rules/1-1924-8.xml @@ -0,0 +1,14 @@ + + + + + 1.1924.8 + RPC mountd UDP export request + +
HostExists(+DST_ADDR+)
+
HasService(+DST_ADDR+, +DST_PORT+)
+
HasRemoteAccess(+SRC_ADDR+, +DST_ADDR+)
+ + HasNfsAccess(+SRC_ADDR+, +DST_ADDR+) +
+ diff --git a/corr_rules/1-579-10.xml b/corr_rules/1-579-10.xml new file mode 100644 index 0000000..186bd6a --- /dev/null +++ b/corr_rules/1-579-10.xml @@ -0,0 +1,14 @@ + + + + + 1.579.10 + RPC portmap mountd request UDP + +
HostExists(+DST_ADDR+)
+
HasService(+DST_ADDR+, +DST_PORT+)
+
HasRemoteAccess(+SRC_ADDR+, +DST_ADDR+)
+ + HasNfsAccess(+SRC_ADDR+, +DST_ADDR+) +
+