12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

306 IDS eventsIntrusion attemptsDNS Exploit AttemptBase Event:Details:Response:Affected:DNS_LONG_NAMEA DNS query was made with a host name over 255 chars; this is outside of the RFC spec.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>s:CVE-1999-0275CVE-1999-0299CVE-1999-0405DNS SpecificationsDNS Exploit AttemptBase Event:Details:Response:Affected:DNS_LONG_NXT_RDLENThere was a NXT record in a DNS packet which had an RDLEN well over the values normally used.This is an indication of an attempt to exploit the NXT BIND overflow.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>s:CVE-1999-0833DNS SpecificationsDNS Inverse QueryBase Event:Details:Response:Affected:DNS_IQUERYDNS inverse query. Once upon a time they were used to look up IPs, but they are not used anymore.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>s:CVE-1999-0009DNS SpecificationsEarly UTF-8 Char EndBase Event:Details:Response:HTTP_EARLY_UTF8_ENDAn early end to what appears as a UTF-8 character was detected. This may be an attempt to exploitthe IIS traversal bug.Location and audit of client and server is recommended.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!