[Silicon Defense logo]

SnortSnarf start page

All Snort signatures

SnortSnarf v021111.1

Signature section (71781)Top 20 source IPsTop 20 dest IPs

71781 alerts found using input module SnortFileInput, with sources: Earliest alert at 17:04:10.676936 on 06/04/2003
Latest alert at 14:03:50.208489 on 08/07/2003

PrioritySignature (click for sig info)# Alerts# Sources# DestsDetail link
N/A(snort_decoder) WARNING: TCP Header length exceeds packet length!111Summary
N/A(snort_decoder): T/TCP Detected2443531Summary
3ICMP Destination Unreachable (Communication Administratively Prohibited) [sid]117222Summary
3ICMP PING speedera [sid]294479Summary
2WEB-MISC /doc/ access [sid] [BUGTRAQ]111Summary
2ATTACK RESPONSES id check returned root [sid]111Summary
2WEB-IIS ISAPI .printer access [sid] [arachNIDS]111Summary
2WEB-MISC login.htm access [sid] [CVE]221Summary
2DOS ath [sid] [arachNIDS]313Summary
2SCAN nmap TCP [sid] [arachNIDS]331Summary
2WEB-IIS encoding access [sid] [arachNIDS]311Summary
2WEB-MISC webdav search access [sid] [arachNIDS]411Summary
2FTP passwd retreval attempt [sid] [arachNIDS]511Summary
2DNS zone transfer TCP [sid] [arachNIDS]911Summary
2ICMP L3retriever Ping [sid] [arachNIDS]1442Summary
2RPC portmap request mountd [sid] [arachNIDS]1511Summary
2RPC portmap listing TCP 111 [sid] [arachNIDS]1811Summary
2RPC mountd TCP mount request [sid]1811Summary
2RPC portmap request NFS UDP [sid]1811Summary
2ATTACK RESPONSES 403 Forbidden [sid]2218Summary
2WEB-CGI calendar access [sid]2381Summary
2WEB-MISC bad HTTP/1.1 request, Potentially worm attack [securityresponse.symantec.com] [sid]27102Summary
2WEB-IIS view source via translate header [sid] [arachNIDS]4472Summary
2WEB-MISC robots.txt access [cgi.nessus.org] [sid]54141Summary
2WEB-IIS _mem_bin access [sid]72251Summary
2WEB-FRONTPAGE /_vti_bin/ access [sid]75271Summary
2WEB-MISC apache DOS attempt [sid]8011Summary
2ICMP Source Quench [sid]8181Summary
2BAD TRAFFIC loopback traffic [rr.sans.org] [sid]8719Summary
2SNMP missing community string attempt [sid] [CVE]12011Summary
2ICMP superscan echo [sid]265766Summary
2ICMP Large ICMP Packet [sid] [arachNIDS]634775Summary
2ICMP PING NMAP [sid] [arachNIDS]76716210Summary
2SNMP public access udp [sid] [CVE]181811Summary
2WEB-MISC http directory traversal [sid] [arachNIDS]662731Summary
2SNMP request udp [sid] [CVE]5069611Summary
1FTP CWD overflow attempt [sid] [CVE]111Summary
1FTP format string attempt [sid]111Summary
1WEB-MISC Transfer-Encoding: chunked [sid] [BUGTRAQ]221Summary
1WEB-PHP content-disposition [sid] [BUGTRAQ]411Summary
1SMTP HELO overflow attempt [sid] [CVE]28251Summary
1WEB-MISC Apache Chunked-Encoding worm attempt [sid] [BUGTRAQ]4221Summary
1WEB-IIS WEBDAV nessus safe scan attempt [sid] [BUGTRAQ]64232Summary
1WEB-IIS CodeRed v2 root.exe access [www.cert.org] [sid]165301Summary
1WEB-IIS multiple decode attempt [sid] [CVE]192231Summary
1WEB-MISC cross site scripting attempt [sid]27111Summary
1WEB-IIS ISAPI .ida attempt [sid] [arachNIDS]3582691Summary
1WEB-IIS unicode directory traversal attempt [sid] [CVE]26491812Summary
1WEB-IIS cmd.exe access [sid]35428572Summary

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Thu Aug 7 14:05:03 2003