Short Name |
SSH:MISC:UNIX-ID-RESP |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
SSH |
Release Date |
2003/10/15 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects the output of the "id" command. Attackers use the id command after a successful attack to determine which users they have access to. Typically, when this command is present in an SSH session, a successful attack has already occurred.
An attacker could send commands to gage the level of access granted and then begin using the compromised system.