12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IDS eventsSuspicious activity403Affected:No specific targets.False Positives: None known.<strong>Reference</strong>sIRC SpecificationsIRC Malformed DataBase Event:Details:Response:Affected:IRCSERSER_UNKNOWN_AFTERPASSCAPABSAfter a successful IRC passwd and capabilities exchange, invalid data was sent.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>sIRC SpecificationsMalformed LDAP TrafficBase Event:Details:LDAP_ASN1_DATALENGTH_IMPOSSIBLE_STATEPlease contact technical support if you see this error as it should be impossible to generate.<strong>Reference</strong>s LDAP RFC 2251LDAP RFC 2252LDAP RFC 2253LDAP RFC 2254LDAP RFC 2255Malformed LDAP TrafficBase Event:Details:LDAP_ASN1_DATALENGTH_RIDICULOUS_WIDTHAn element of BER encoded ASN.1 data specified an integer larger than 32 bits for the data length.LDAP data should never require numbers this large to describe their length, and indicates either anon-conforming LDAP implementation or an intrusion attempt.<strong>Reference</strong>s LDAP RFC 2251LDAP RFC 2252LDAP RFC 2253LDAP RFC 2254LDAP RFC 2255

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!