12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IDS eventsIntrusion attempts325Affected:No specific targets.False Positives: None known.<strong>Reference</strong>s:CVE-2000-0711HTTP SpecificationsMalformed LDAP TrafficBase Event:Details:LDAP_ASN1_NESTEDSEQUENCE_OVERFLOWAn element of ASN.1 encoded LDAP data overran the size specified by one of its parent datasequence.<strong>Reference</strong>s: LDAP RFC 2251LDAP RFC 2252LDAP RFC 2253LDAP RFC 2254LDAP RFC 2255Malformed LDAP TrafficBase Event:Details:LDAP_ANS1_UNEXPECTED_DATA_AFTER_SEQUENCEA sequence of LDAP ASN.1 encoded data elements failed to terminate even after all the expectedelements had been seen.<strong>Reference</strong>s: LDAP RFC 2251LDAP RFC 2252LDAP RFC 2253LDAP RFC 2254LDAP RFC 2255Microsoft FrontPage PWSBase Event:Details:Response:Affected:HTTP_URL_SIG15An attempt to exploit the double-dot bug in Microsoft FrontPage Personal Web Server was detected.This attack may allow an attacker to access system files on an unpatched Web server.Response typically includes application of a vendor patch to the victim system.Microsoft FrontPage serversFalse Positives: None known.<strong>Reference</strong>s:HTTP SpecificationsMountd Exploit AttemptBase Event:Details:Response:RPC_MOUNTD_LONG_DIRNAMEThe directory name that you are trying to mount is longer than 512 bytes.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!