GPEN · Question #459
Based on the partial appdefstrig rile listed below, which port scan signature is classified by AMap as harmful?
The correct answer is C. http-trace. In AMap's appdefstrig file, port scan signatures are assigned threat classifications, and http-trace is flagged as harmful due to its known exploitation potential.
Question
Based on the partial appdefstrig rile listed below, which port scan signature is classified by AMap as harmful?
Exhibit
Options
- Asmtp
- Bnetbios-session
- Chttp-trace
- Dms-remote-desktop-protocol
How the community answered
(55 responses)- A7% (4)
- B18% (10)
- C71% (39)
- D4% (2)
Why each option
In AMap's appdefstrig file, port scan signatures are assigned threat classifications, and http-trace is flagged as harmful due to its known exploitation potential.
SMTP is a standard mail transfer protocol that AMap identifies as informational; it is not classified as harmful in the default signature file because its presence alone does not indicate exploitation.
NetBIOS Session service is a common Windows networking protocol that AMap detects and flags for awareness but does not classify as harmful by default.
The HTTP TRACE method is classified as harmful in AMap because it can be leveraged in Cross-Site Tracing (XST) attacks, where a malicious script sends a TRACE request that echoes back HTTP headers including session cookies, enabling credential theft. AMap's appdefstrig file assigns risk levels to identified application signatures, and http-trace receives a 'harmful' designation because its functionality directly exposes sensitive data when exploited.
MS Remote Desktop Protocol may be noted as a sensitive service, but it is not specifically assigned a 'harmful' classification in AMap's default appdefstrig signature definitions.
Concept tested: AMap application signature threat classification
Topics
Community Discussion
No community discussion yet for this question.
