12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsSuspicious activity401IMAP Protocol ViolationBase Event:Details:IMAP_SER_INVALID_MSG_ATTAn IMAP violation occurred while parsing server side message attributes.IMAP Protocol ViolationBase Event:Details:IMAP_SER_INVALID_NONAUTHThe server sent an invalid command in a non-authenticated state. This violation of the standardcould indicate an attempt to compromise the protocol.IMAP Protocol ViolationBase Event:Details:IMAP_SER_INVALID_TAGGED_ANYInvalid IMAP server side lead string in the TAGGED ANY state.IMAP Protocol ViolationBase Event:Details:IMAP_SER_INVALID_UNTAGGED_ANYInvalid IMAP server side lead string in the UNTAGGED ANY state.IMAP URL Invalid LoginBase Event:Details:IMAP_URL_INVALID_LOGINAn invalid IMAP logon with URL encoding was detected.IRC Malformed DataBase Event:Details:Response:Affected:IRCCLISER_BAD_AFTER_NICKThis event indicates that data was received after the IRC NICK (PASS) was transmitted by theclient. According to the RFC, no data is expected after the proper termination of the NICK (PASS)command.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>sIRC SpecificationsIRC Malformed DataBase Event:Details:Response:IRCCLISER_BAD_AFTER_USERThis event indicates that data was received after the IRC USER (PASS) was transmitted. Accordingto the RFC, no data is expected after the proper termination of the USER (PASS) command.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!