WEB_MISC telnet attempt

 

Code: p1231

Severity: Warning

 

Description: This event is generated when an attempt is made to access telnet.exe on a remote web server via a web request.

Impact: Information gathering and system integrity compromise. Possible unauthorized administrative access to the server. Possible execution of arbitrary code of the attackers choosing in some cases.

Corrective: Ensure the system is using an up to date version of the software and has had all vendor supplied patches applied. Check the host logfiles and application logs for signs of compromise.