12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

322 IDS eventsIntrusion attemptsIRC BackdoorBase Event:Details:Response:Affected:IRCCLISER_EL15SPY_NOTIFICATIONThis is a signature detection event for a well known IRC worm (EL15SPY). This event indicates thenotification of an infected client (IP, server, and port).If seen in sufficient volume or variation and other suspicious factors exist audit of client and serveris recommended. Examination of the packet contents may provide some additional informationabout the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>s:IRC SpecificationsIRC BackdoorBase Event:Details:Response:Affected:IRCCLISER_JOINED_BO_OWNEDSomeone joined an IRC channel with the name bo_owned. This is a signature of a well known IRCback door.If seen in sufficient volume or variation and other suspicious factors exist audit of client and serveris recommended. Examination of the packet contents may provide some additional informationabout the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>s:IRC SpecificationsIRC WormBase Event:Details:Response:Affected:IRCCLISER_AZACO_WORMDetection of the “azaco” worm. This is a signature detection event for a well known IRC worm.If seen in sufficient volume or variation and other suspicious factors exist audit of client and serveris recommended. Examination of the packet contents may provide some additional informationabout the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>s:IRC SpecificationsIRC WormBase Event:Details:Response:Affected:IRCCLISER_CLAWFINGER_WORMDetection of the “clawfinger” worm. This is a signature detection event for a well known IRC worm.If seen in sufficient volume or variation and other suspicious factors exist audit of client and serveris recommended. Examination of the packet contents may provide some additional informationabout the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>s:IRC Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!