这怎么就报 “主机发起命令注入攻击:OS_Command_Injection_Attempt_in_Cooike”了????
误报吧?
<188>Jan 10 13:52:19 2021 H3C %%10IPS/4/IPS_IPV4_INTERZONE: Protocol(1001)=TCP; Application(1002)=MangGuoTV; SrcIPAddr(1003)=10.157.137.7; SrcPort(1004)=58702; DstIPAddr(1007)=101.133.195.196; DstPort(1008)=80; RcvVPNInstance(1042)=--; SrcZoneName(1025)=Trust; DstZoneName(1035)=Trust; UserName(1113)=10.157.137.7; PolicyName(1079)=ips; AttackName(1088)=OS_Command_Injection_Attempt_in_Cooike; AttackID(1089)=36985; Category(1090)=Vulnerability; Protection(1091)=ApplicationSoftware; SubProtection(1092)=Other; Severity(1087)=MEDIUM; Action(1053)=Permit & Logging & Capture; CVE(1075)=--; BID(1076)=--; MSB(1077)=--; HitDirection(1115)=original; RealSrcIP(1100)=; SubCategory(1124)=CommandInjection; CapturePktName(1116)=ips_10.157.137.7_20210110_135219343232_36985.pcap; HttpHost(1117)= ***.***; HttpFirstLine(1118)=; PayLoad(1135)= mh_ur=BwUHBAUEBAUTYXQHBQcFBAUGBQQAAAYBBwUFBgAPBQ8EAw0BBw8FDwQMAwQEAw8FDwQDDQEHDwUPBwcNBgECDwcFBwQFBAYFamF0BwUHBAUEBQEEAgYGBwYFBwcMDwUPBQ8FDwcCBg8FDwUPBQ8HAgYPBwUHBAUHBQBqYXQHBQc
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论