12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

342 IDS eventsIntrusion attemptsStatd Exploit AttemptBase Event:Details:Response:Affected:RPC_STATD_LONG_HOSTNAMEThis event is triggered If the host name specified in an RPC statd request is over 512 bytes.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>s:CVE-1999-0018RPC SpecificationsSuspicious SNMP TrafficBase Event:Details:Response:Affected:SNMP_ERROR_DATA_AFTER_MESSAGE_ENDAdditional data was found in a connection after the end of an otherwise normal SNMP message.Location and audit of victim is recommended.Hosts running SNMP agents or managers.False Positives: None known.<strong>Reference</strong>s:RFC 1155 - SNMP v1 SpecificationsRFC 1157 - SNMP v1 SpecificationsRFC 1212 - SNMP v1 SpecificationsRFC 1901 - SNMP v2c SpecificationsRFC 1902 - SNMP v2c SpecificationsRFC 1903 - SNMP v2c SpecificationsRFC 1904 - SNMP v2c SpecificationsRFC 1905 - SNMP v2c SpecificationsRFC 1906 - SNMP v2c SpecificationsRFC 1907 - SNMP v2c SpecificationsRFC 1908 - SNMP v2c SpecificationsRFC 2571 - SNMP v3 SpecificationsRFC 2572 - SNMP v3 SpecificationsRFC 2573 - SNMP v3 SpecificationsRFC 2574 - SNMP v3 SpecificationsRFC 2575 - SNMP v3 SpecificationsSNMP FAQSuspicious SNMP TrafficBase Event:Details:Response:SNMP_ERROR_INDEX_PAST_END_OF_MSGThe error index pointed to a VarBind pair that does not exist in the current SNMP message.Location and audit of victim is recommended.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!