12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

376 IDS eventsSuspicious activityAffected:No specific targets.False Positives: None known.<strong>Reference</strong>sFTP SpecificationsFTP Malformed DataBase Event:Details:Response:Affected:FTPSER_UNKNOWN_RESPONSE_FROMUNKNOWNServer sent something that didn’t start with a numeric, which is outside the FTP protocolspecification. It is possible this indicates an attempt to compromise the server.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>sFTP SpecificationsHSRP Buffer OverflowBase Event:Details:<strong>Reference</strong>sHSRP_OVERLONG_PACKETThe HSRP datagram exceeded the length mandated by the RFC, indicating a possible bufferoverflow attack. This violation of the standard could indicate an attempt to compromise theprotocol.HSRP SpecificationsHSRP CoupBase Event:Details:<strong>Reference</strong>sHSRP_COUPAn HSRP Coup message indicates that a new router has assumed the role of the active router. Thismay indicate a change in router status. If seen in sufficient volume, it may indicate a problem withthe routers or that an attack is being launched.HSRP SpecificationsHSRP Inconsistent StateBase Event:Details:<strong>Reference</strong>sHSRP_WRONG_STATE_FOR_SPEAKINGAccording to the HSRP RFC, only a router in the Listen, Speak, Standby, or Active states may sendout an HSRP message. However, an HSRP message was detected from a router that is in Initial orLearn states. This violation of the standard could indicate an attempt to compromise the protocol.HSRP SpecificationsHSRP Inconsistent Time FieldsBase Event:Details:<strong>Reference</strong>sHSRP_HOLDTIME_GT_HELLOTIMEThe HSRP HOLDTIME field was less than the HELLOTIME field, which is explicitly disallowed bythe RFC. This violation of the standard could indicate an attempt to compromise the protocol.HSRP Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!