TROJAN: Pitfall Telnet Server Identification

This signature detects the banner displayed by the Pitfall telnet server. This server is often used on nonstandard ports as a backdoor. Detecting the banner indicates that the server is infected with the Pitfall Trojan. Using the Pitfall client, attackers can gain unauthorized access to the host computer and execute malicious operations.

Extended Description

Pitfall allows remote attackers unauthorized access and control of infected machines.

Short Name
TROJAN:MISC:PITFALL-TELNET-ID
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
TROJAN
Keywords
CVE-1999-0660 Identification Pitfall Server Telnet
Release Date
01/09/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/1991
False Positive
Unknown
CVSS Score

8.8

Found a potential security threat?