QuestionQ466

Managing Application Security

John is a professional Ethical Hacker assigned to test the security of www.we-are-secure.com. He writes the following Snort rule:

Question Image

This rule can help him protect the We-are-secure server from the __________.

  • A I LOVE YOU virus
  • B Nimda virus
  • C Chernobyl virus
  • D Melissa virus
Explanation

Snort SID 1002 detects HTTP attempts to access cmd.exe on a Microsoft IIS server, indicating exploitation of IIS weaknesses. The Nimda worm spread through vulnerable IIS web servers using this type of IIS command-execution attack.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!