File: 2044.txt

package info (click to toggle)
snort 2.7.0-20.4
  • links: PTS
  • area: main
  • in suites: lenny
  • size: 34,512 kB
  • ctags: 18,772
  • sloc: ansic: 115,404; sh: 10,893; makefile: 1,372; perl: 487; sql: 213
file content (64 lines) | stat: -rw-r--r-- 1,285 bytes parent folder | download | duplicates (4)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
Rule:

--
Sid:
2044

--
Summary:
The Point to Point Tunneling Protocol (PPTP) is used to connect client 
machines to internal corporate resources using a Virtual Private Network
(VPN) across a public network such as the Internet via an encrypted 
session.


--
Impact:
Possible loss of data from an internal network to an unknown external 
source.

--
Detailed Information:
This event indicates that a PPTP session from an internal resource to an
unknown external source has been attempted. This may be an indication of
an attempt to initialize an encrypted session for nefarious purposes.

An internal user may try to use an encrypted tunnel to evade possible 
detection when transferring files from an internal resource to an 
unauthorized eternal party.

--
Affected Systems:
All systems allowing PPTP connections from an internal to external 
source.

--
Attack Scenarios:
The user only needs to initiate a connection to an external source.

--
Ease of Attack:
Simple

--
False Positives:
None Known

--
False Negatives:
None Known

--
Corrective Action:
Disallow PPTP transactions from the internal LAN to external sources.

--
Contributors:
Sourcefire Research Team
Brian Caswell <bmc@sourcefire.com>
Nigel Houghton <nigel.houghton@sourcefire.com>

--
Additional References:

--