12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

372 IDS eventsSuspicious activityFTP Malformed DataBase Event:Details:Response:Affected:FTP_BAD_PORT_CMD_IPNUMAn invalid IP address argument to the FTP PORT command was detected. This could indicate anattempt to compromise the server.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is also possible the client or server is using an unofficial extension or a non-compliantimplementation of FTP.<strong>Reference</strong>sFTP SpecificationsFTP Malformed DataBase Event:Details:Response:Affected:FTP_BAD_RANDOM_COMMANDA FTP command was sent to the server that was not composed of alphabetic characters. No FTPcommands should be composed of non-alphabetic characters. This may indicate a compromisedserver.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is possible this is a client or server using an unofficial extension or non-compliantimplementation.<strong>Reference</strong>sFTP SpecificationsFTP Malformed DataBase Event:Details:Response:Affected:FTP_INVALID_UTF8Invalid UTF-8 character encoding has been detected in an FTP session. Bytes in a UTF-8 characterafter the character length specification fall into a limited range; this event is recorded if theseencoding characters fall outside that range. It is possible this indicates an attempt to compromisethe server.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is possible this is a non-compliant UTF-8 encoding implementation.<strong>Reference</strong>sFTP Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!