12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsSuspicious activity385Affected:No specific targets.False Positives: None known.<strong>Reference</strong>sHTTP SpecificationsHTTP Malformed DataBase Event:Details:Response:Affected:HTTP_UNKNOWN_STATUSThis event indicates that the status response that appears in the first line of an HTTP serverresponse did not comply with the format specified by the RFC.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>sHTTP SpecificationsHTTP Malformed RequestBase Event:Details:Response:Affected:HTTP_MISSING_HOSTAn HTTP 1.1 request was detected which did not contain the Host request-header. This is aviolation of the HTTP 1.1 standard and may indicate an attempt to compromise the server.If seen in sufficient volume or variation, audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>sHTTP SpecificationsHTTP Malformed Transport EncodingBase Event:Details:Response:Affected:HTTP_BAD_CHUNKED_HEXThe HTTP traffic contained badly formatted encoding. This may be an attempt to exploit certainserver vulnerabilities.If seen in sufficient volume or variation, audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>sHTTP SpecificationsHTTP Malformed Transport EncodingBase Event:Details:Response:Affected:HTTP_NO_CRLF_AFTER_CHUNKThe HTTP traffic was missing not properly terminated. This may be an attempt to exploit certainserver vulnerabilities.If seen in sufficient volume or variation, audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>sHTTP Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!