12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsSuspicious activity453Affected:No specific targets.False Positives: None known.<strong>Reference</strong>s http://www.whitehats.com (arachNIDS #392)http://www.whitehats.com (arachNIDS #393)RSH Auth FailureBase Event:Details:Response:Affected:RSH_ROOT_LOGIN_FAILEDA failed root rsh attempt was detected.If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>s http://www.whitehats.com (arachNIDS #389)RSH Bad UsernameBase Event:Details:Response:Affected:RSH_INVALID_USERNAMEOne of a set of “bad” user names was used in a rsh attempt (for example, daemon, bin, sys, adm, lp,uucp, nuucp, listen, nobody, noaccess, or nobody4).If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.RSH Malformed DataBase Event:Details:Response:Affected:RSH_INVALID_CLI_LOGIN_FIELDThe username logon field sent by the rsh client did not conform to the RSH standard.If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.RSH Malformed DataBase Event:Details:RSH_INVALID_COMMAND_LINESomething was passed to rsh that doesn’t look like a valid command line.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!