12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IDS eventsOperational events353Web Phorum BackdoorBase Event:Details:Response:Affected:HTTP_REQMSGHDR_SIG1An indicator of a Web Phorum backdoor was detected in an HTTP header. The cookie“php_auth_user=boogieman” granted administrator access to the Phorum, potentially even to thesystem.Location and audit of client and server is recommended. If you intended to be using this productyou should contact the vendor for any applicable updates.No specific targets.False Positives: None known.<strong>Reference</strong>s:HTTP SpecificationsOperational eventsSensor Data Read ErrorBase Event:Details:SENSOR_SNIFF_DATA_BADA sensor has failed to properly parse its data file. The sensor will not start up if it cannot properlyparse this file.Sensor Device Open FailureBase Event:Details:SENSOR_IFDEVOPEN_FAILUREA sensor has failed to open an interface device. Check to make sure that the device name wasproperly entered in the console.Sensor Error On ExitBase Event:Details:SENSOR_ERROREXIT_FAILUREA sensor has exited with a non-zero error code. This may indicate a problem with the system orconfiguration.Sensor Memory Allocation ErrorBase Event:Details:SENSOR_MALLOC_FAILUREA sensor has failed to allocate needed memory on start-up. Possible causes are the system does nothave the recommended minimum amount of RAM or that extraneous processes are running.Sensor Portmap Read ErrorBase Event:Details:SENSOR_PORTMAP_BADA sensor has failed to properly parse the port mapping configuration file. The sensor will not startup if it cannot properly parse this file.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!