12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsSuspicious activity451RPC Malformed DataBase Event:Details:Response:Affected:RPC_INVALID_MTYPEA RPC MTYPE was specified that is out of range. MTYPE can only be 0 or 1, even though it isrepresented as a 32-bit quantity.If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sRPC SpecificationsRPC Malformed DataBase Event:Details:Response:Affected:RPC_INVALID_REJECTED_REPLYThe RPC reply specifying why a packet was rejected was out of range. According to thespecification, rejection replies must contain two characteristic id strings: “null null null null” or“null null null 0x01 null null null” followed by a character in the normal ASCII range.If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sRPC SpecificationsRPC Malformed DataBase Event:Details:Response:Affected:RPC_INVALID_VERSIONVersion number in the RPC packet is invalid.If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sRPC SpecificationsRPC Malformed DataBase Event:Details:Response:Affected:RPC_NULL_RMFRAGAn RPC packet indicated that a fragment was coming, but the first packet contained no data.If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sRPC Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!