12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

450 IDS eventsSuspicious activityRlogin Malformed DataBase Event:Details:Response:Affected:RLOGIN_INVALID_TERM_FIELDAn invalid terminal type specified was specified in a rlogin session.If seen in sufficient volume or variation, audit of client and server is recommended. Examination ofthe packet contents may provide some additional information about the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>sRlogin SpecificationsRlogin Malformed DataBase Event:Details:Response:Affected:RLOGIN_INVALID_USERNAMEOne of a set of “bad” user names was used in a rlogin attempt (for example, daemon, bin, sys, adm,lp, uucp, nuucp, listen, nobody, noaccess, or nobody4).If seen in sufficient volume or variation, audit of client and server is recommended. Examination ofthe packet contents may provide some additional information about the particular command.No specific targets.False Positives: None known.<strong>Reference</strong>sRlogin SpecificationsRPC Malformed DataBase Event:Details:Response:Affected:RPC_BUFFER_OVERFLOWA possible buffer overflow was seen in the RPC traffic.If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sRPC SpecificationsRPC Malformed DataBase Event:Details:Response:Affected:RPC_INVALID_ACCEPTED_TYPEThere are six types of messages that are in an RPC packet (marked by a string of three consecutivenull characters, followed by a fourth character of value 0x0 to 0x5). This event is triggered if a typeother than the six known types was specified.If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sRPC Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!