12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsIntrusion attempts305Affected:No specific targets.False Positives: None known.<strong>Reference</strong>s:CAN-1999-0660http://www.whitehats.com (arachNIDS #406)FTP SpecificationsDirect Perl AccessBase Event:Details:Response:Affected:HTTP_URL_SIG5The HTTP request URL attempted direct access of the Perl executable. This usually represents anattempt to execute arbitrary code on the target system.Location and audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>s:CAN-1999-0509http://www.whitehats.com (arachNIDS #219)HTTP SpecificationsDNS Exploit AttemptBase Event:Details:Response:Affected:DNS_BAD_COMPRESSIONThere was a pointer in a label to the DNS packet header. This represents a mal-formed DNS packetand a possible exploitation attempt of the TSIG bug.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>s:DNS SpecificationsDNS Exploit AttemptBase Event:Details:Response:Affected:DNS_BAD_LABEL_LENGTHThe DNS label length used in host name construction specified an illegal value. This can representa possible DNS bug exploit attempt.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>s:DNS Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!