Short Name |
PORTMAPPER:INFO:PORTMAP-DUMP |
---|---|
Severity |
Medium |
Recommended |
Yes |
Category |
PORTMAPPER |
Keywords |
DUMP Call |
Release Date |
2003/05/08 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability in Portmapper. Attackers can send a DUMP RPC call to the Portmap daemon to obtain a list of available RPC programs for a host. Attackers can use this list to plan future, more targeted attacks.
Remote intruders could exploit this vulnerability to identify services that are running on a server. Although an intruder does not break into a server at this point, the information gained could be used to execute malicious attacks on the server.