12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

440 IDS eventsSuspicious activityMalformed LDAP TrafficBase Event:Details:LDAP_VERSION_UNKNOWNAn unknown version of the LDAP protocol was specified.<strong>Reference</strong>s LDAP RFC 2251LDAP RFC 2252LDAP RFC 2253LDAP RFC 2254LDAP RFC 2255NBT Malformed DataBase Event:Details:Response:Affected:NBT_INVALID_COMMANDInvalid NetBIOS command data sent to a server was detected.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>sSMB InformationNNTP Auth FailureBase Event:Details:Response:Affected:NNTPCLI_FAILED_AUTHENTICATIONThis event corresponds to the server sending a 482 or 452 response code.If seen in sufficient volume or variation, audit of client and server is recommended.No specific targets.False Positives: It is possible this is only a user mistyping their password.<strong>Reference</strong>sNNTP SpecificationsNNTP Malformed DataBase Event:Details:Response:Affected:NNTPCLI_EXPECTED_CRLFA carriage return linefeed (CRLF) sequence was expected as the next string from the client,however something else was sent. It is possible this indicates an attempt to compromise the server.The packet contents should be examined and the server should be audited.No specific targets.False Positives: It is possible this is a news client or server using an unofficial protocol extension or non-compliantNNTP implementation.<strong>Reference</strong>sNNTP Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!