12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

374 IDS eventsSuspicious activityAffected:No specific targets.False Positives: It is also possible the client or server is using an unofficial extension or a non-compliantimplementation of FTP.<strong>Reference</strong>sFTP SpecificationsFTP Malformed DataBase Event:Details:Response:Affected:FTPCLI_EXPECTED_ALLORESPA storage or append operation should immediately follow an FTP ALLO command, but somethingelse was sent. It is possible this indicates an attempt to compromise the server.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>sFTP SpecificationsFTP Malformed DataBase Event:Details:Response:Affected:FTPCLI_EXPECTED_CRLFAn FTP command was not properly terminated. According to the RFC, a pair of CR/LF characters isexpected at this point from the FTP client. For example, the CR/LF should appear after the clientissues commands like “CDUP,” “REIN,” “QUIT,” “PASV,” or “ABOR,” which do not take anyarguments, or commands like “STRU,” “MODE,” or “TYPE,” and the legal values for theirarguments. This event is triggered if something else was sent.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is also possible that this is a non-compliant server implementation of FTP.<strong>Reference</strong>sFTP SpecificationsFTP Malformed DataBase Event:Details:Response:Affected:FTPCLI_EXPECTED_LFAn FTP was not properly terminated. According to the RFC, a pair of CR/LF characters is expectedat this point from the FTP client. For example, the CR/LF should appear after the client issuescommands like “CDUP,” “REIN,” “QUIT,” “PASV,” or “ABOR,” which do not take any arguments, orcommands like “STRU,” “MODE,” or “TYPE,” and the legal values for their arguments. This event istriggered if something other than the LF character was sent after the CR character.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is also possible that this is a non-compliant server implementation of FTP.<strong>Reference</strong>sFTP Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!