Successful Shell Attack Detected - Unix Failed 'tcpdump' Command

High Nessus Network Monitor Plugin ID 6157

Synopsis

A successful shell attack was detected.

Description

A failed 'tcpdump' command occurred in a TCP session normally used for a standard service.

Solution

The command activity observed is indicative of a possible compromise. Consider performing a full audit of the system to investigate further.

See Also

http://www.tcpdump.org

Plugin Details

Severity: High

ID: 6157

File Name: 6157.prm

Family: Generic

Published: 2012/01/06

Modified: 2015/06/01

Dependencies: 1442, 1000, 1967, 1803, 2004, 2005, 1086, 1144, 1146, 1148, 1149, 1150, 1151, 1120, 1133, 1134, 1135

Risk Information

Risk Factor: High