12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsIntrusion attempts323IRC WormBase Event:Details:Response:Affected:IRCCLISER_EL15BMP_WORMDetection of the “el15bmp” worm. This is a signature detection event for a well known IRC worm.If seen in sufficient volume or variation and other suspicious factors exist audit of client and serveris recommended. Examination of the packet contents may provide some additional informationabout the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>s:IRC SpecificationsIRC WormBase Event:Details:Response:Affected:IRCCLISER_LIFESTAGES_WORMThe life stages worm. This is a signature detection event for a well known IRC worm. The patterndetected is “dccsend life_stages.txt.shs”If seen in sufficient volume or variation and other suspicious factors exist audit of client and serveris recommended. Examination of the packet contents may provide some additional informationabout the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>s:IRC SpecificationsIRC WormBase Event:Details:Response:Affected:IRCCLISER_LOA_WORMDetection of the “loa” worm. This is a signature detection event for a well known IRC worm.If seen in sufficient volume or variation and other suspicious factors exist audit of client and serveris recommended. Examination of the packet contents may provide some additional informationabout the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>s:IRC SpecificationsIRC WormBase Event:Details:Response:Affected:IRCCLISER_LUCKY_WORMDetection of the “lucky” worm. This is a signature detection event for a well known IRC worm.If seen in sufficient volume or variation and other suspicious factors exist audit of client and serveris recommended. Examination of the packet contents may provide some additional informationabout the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>s:IRC Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!