12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsSuspicious activity373FTP Malformed DataBase Event:Details:Response:Affected:FTP_LONG_COMMANDAn FTP command was sent which was longer than eight bytes. No FTP commands should be longerthan eight bytes. This may indicate a compromised server.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is possible this is a client or server using an unofficial extension or non-compliantimplementation.<strong>Reference</strong>sFTP SpecificationsFTP Malformed DataBase Event:Details:Response:Affected:FTP_PORT_CMD_TOO_MANY_ARGSInvalid arguments to the FTP PORT command was detected. This could indicate an attempt tocompromise the server.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is also possible the client or server is using an unofficial extension or a non-compliantimplementation of FTP.<strong>Reference</strong>sFTP SpecificationsFTP Malformed DataBase Event:Details:Response:Affected:FTP_RNTO_WITHOUT_RNFRAn FTP RNTO command was detected without a corresponding RNFR command. This is unusualbehavior.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>sFTP SpecificationsFTP Malformed DataBase Event:Details:Response:FTP_UNRECOGNIZED_COMMANDAn unrecognized FTP command was sent to the FTP server. This could indicate a compromisedserver.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!