Successful Shell Attack Detected - Windows 'dir' Command Execution

High Nessus Network Monitor Plugin ID 6180

Synopsis

A successful shell attack was detected.

Description

The results of a Windows directory listing command occurred in a TCP session normally used for a standard service. This may indicate a successful compromise of this service has occurred.

Solution

The command activity observed is indicative of a possible compromise. Consider performing a full audit of the system to investigate further.

Plugin Details

Severity: High

ID: 6180

Family: Generic

Published: 2012/01/06

Modified: 2018/07/11

Dependencies: 1442, 1000, 1967, 1803, 2004, 2005, 1086, 1144, 700231, 700232, 1146, 1148, 1149, 1150, 1151, 1120, 1133, 1134, 1135

Risk Information

Risk Factor: High

Vulnerability Information

CPE: cpe:/o:microsoft:windows