12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

442 IDS eventsSuspicious activityNNTP Malformed DataBase Event:Details:Response:Affected:NNTPSER_INVALID_ASCIIThe NNTP server responded with characters outside the ASCII range allowed in a response. ValidASCII characters are x00 - 0x7f inclusive. It is possible this indicates an attempt to compromise theserver.The packet contents should be examined and the server should be audited.No specific targets.False Positives: It is possible this is a news client or server using an unofficial protocol extension or non-compliantNNTP implementation.<strong>Reference</strong>sNNTP SpecificationsNNTP Malformed DataBase Event:Details:Response:Affected:NNTPSER_INVALID_TEXTThe NNTP server responded with text outside the expected character range. The expectedcharacter range includes ASCII characters x00 - 0x7f inclusive. It is possible this indicates anattempt to compromise the server.The packet contents should be examined and the server should be audited.No specific targets.False Positives: It is possible this is a news client or server using an unofficial protocol extension or non-compliantNNTP implementation.<strong>Reference</strong>sNNTP SpecificationsOSPF “Hello” Invalid OptionsBase Event:Details:<strong>Reference</strong>sOSPF_HELLO_INVALID_OPTSThe options specified in the OSPF Hello message were invalid. This violation of the standard couldindicate an attempt to compromise the protocol.OSPF SpecificationsOSPF “Hello” Malformed Neighbor FieldsBase Event:Details:<strong>Reference</strong>sOSPF_HELLO_BAD_NEIGHBORThe neighbor fields specified in the OSPF Hello message were malformed. This violation of thestandard could indicate an attempt to compromise the protocol.OSPF SpecificationsOSPF “Hello” Short PacketBase Event:Details:<strong>Reference</strong>sOSPF_HELLO_SHORT_PACKETThe OSPF Hello message was shorter than minimum required length. This violation of thestandard could indicate an attempt to compromise the protocol.OSPF Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!