12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

506 IDS eventsSuspicious activityAffected:No specific targets.False Positives: It is possible this is just someone mistyping a root password though remote access as root (asopposed to using “su”) is generally a security risk anyways.<strong>Reference</strong>s http://www.whitehats.com (arachNIDS #251)Telnet SpecificationsTelnet WinGate ActiveBase Event:Details:Response:Affected:TELNET_WINGATE_PROMPTTelnet Wingate activity was detected. This is a common Relay and SOCKs program that may beexploited.Location and audit of client and server is recommended.No specific targets.False Positives: None known.<strong>Reference</strong>sCAN-1999-0657http://www.whitehats.com (arachNIDS #2366)Telnet SpecificationsUnauthenticated OSPFBase Event:Details:<strong>Reference</strong>sOSPF_NULL_AUTHENTICATIONAn OSPF message with a null authentication field was detected. Unauthenticated OSPF messagesare vulnerable to spoofing and other attacks. All devices participating in OSPF should beconfigured to use cryptographic authentication.OSPF SpecificationsUnauthenticated SOCKS4 ConnectionBase Event:Details:SOCKS4_UNAUTHENTICATEDThe SOCKS4 server sent an unauthenticated reply to the client.Unauthenticated SOCKS5 ConnectionBase Event:Details:SOCKS5_UNAUTHENTICATEDThe SOCKS5 server sent an unauthenticated reply to the client.WIN DNS Malformed DataBase Event:Details:Response:WIN_DNS_DATA_AFTER_ENDProbably a Microsoft Windows DNS implementation talking to a Microsoft WINS name server thatviolates DNS protocol. Extra data was sent after a valid DNS packet. Probably an overflow attempt.If seen in sufficient volume or variation, location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!