12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsIntrusion attempts321Intel NOPsBase Event:Details:Response:Affected:HTTP_BODY_SIG1Intel NOP instructions were detected inside the body of an HTTP request. This indicates a possibleattempted buffer overflow attack.Location and audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>s:HTTP SpecificationsIntel NOPsBase Event:Details:Response:Affected:HTTP_REQMSGHDR_SIG0Intel NOP instructions have been detected in an HTTP header. This represents a possible bufferoverflow attempt.Location and audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>s:HTTP SpecificationsIntel NOPsBase Event:Details:Response:Affected:HTTP_RESPMSGHDR_SIG0Intel NOP instructions have been detected in an HTTP header. This represents a possible bufferoverflow attempt.Location and audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>s:CAN-1999-0660HTTP SpecificationsIRC BackdoorBase Event:Details:Response:Affected:IRCCLISER_EL15SPY_ANSWERThis is a signature detection event for a well known IRC worm (EL15SPY). The characteristicanswer to a bait string “are_u” is sent (“EL15_send_kisses_to_U_:)__come_on!”).If seen in sufficient volume or variation and other suspicious factors exist audit of client and serveris recommended. Examination of the packet contents may provide some additional informationabout the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>s:IRC Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!