12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

402 IDS eventsSuspicious activityAffected:No specific targets.False Positives: None known.<strong>Reference</strong>sIRC SpecificationsIRC Malformed DataBase Event:Details:Response:Affected:IRCSER_UNKNOWN_AFTERPASSThe first data sent by the client after a PASS command was unrecognized. Valid commands hereinclude “SERVER,” “ERROR,” and “CAPAB.”If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>sIRC SpecificationsIRC Malformed DataBase Event:Details:Response:Affected:IRCSER_UNKNOWN_INITA Client initialization sequence was sent to server that did not comply with the IRC specification.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>sIRC SpecificationsIRC Malformed DataBase Event:Details:Response:Affected:IRCSERSER_UNKNOWN_AFTERPASSAn unknown command was sent after a PASS command in an IRC session.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>sIRC SpecificationsIRC Malformed DataBase Event:Details:Response:IRCSERSER_INVALID_CAPABThe IRC server responded to a CAPAB query with an invalid answer.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!