ISS RealSecure Network Sensor Policy
[ issPolicy v1.01 | http://packet.sequenced.org/projects/isspolicy ]



POLICY INFORMATION

   Policy File: policies/AttackDetector.policy
   Policy Name: Attack Detector
   Policy Version: 7.0.2003.59
   Sensor Type: RealSecure Network Sensor (v7.0)


SIGNATURES POLICY

Response Summary Legend: DISPLAY | LOGDB | EMAIL | SNMP | RSKILL | OPSEC | LOGEVIDENCE | VIEWSESSION

Signature NameSignature DescriptionSignature StatusSignature PriorityResponse SummaryLog
AIX_Pdnsd_OverflowAIX pdnsd buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
AOLIM_AddExternalApp_OverflowAOL Instant Messenger AddExternalApp OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
AOLIM_File_XferAOL Instant Messenger file transferDisabled LOWDISPLAY LOGDB LogWithoutRaw
AOLIM_GameRequest_OverflowAOL Instant Messenger game request overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
AOLIM_LoginAOL Instant Messenger loginDisabled LOWDISPLAY LOGDB LogWithoutRaw
AOLIM_MessageAOL Instant Messenger messageDisabled LOWDISPLAY LOGDB LogWithoutRaw
AOLIM_Password_ChangeAOL Instant Messenger password changeDisabled LOWDISPLAY LOGDB LogWithoutRaw
AOLIM_Trillian_Encrypt_HandshakeTrillian encrypted messaging handshakeDisabled LOWDISPLAY LOGDB LogWithoutRaw
AOL_Instant_Messenger_OverflowAOL Instant Messenger overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
AUDIT_DNS_Version_RequestBind Version Information RequestedDisabled LOWDISPLAY LOGDB LogWithoutRaw
Allaire_JRun_JSP_ExecuteAllaire JRun JSP executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Allaire_JRun_SSIFilterAllaire JRun SSIFilter servletEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Allaire_JRun_Sample_FilesAllaire JRun sample filesEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Allaire_JRun_WebInf_DotSlashAllaire JRun WEB-INF /./ exploitEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Allaire_JRun_WebInf_SlashSlashAllaire JRun WEB-INF double slash allows remote file accessEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
AntiSniff_ARP_TestAnti-Sniff ARP packet test detectionEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
AntiSniff_DNS_TestAnti-Sniff DNS packet test detectionEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
AolAdmin_ResponseAolAdmin BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Ascend_KillAscend kill denial of service attackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Ascend_Kill_IIAscend AttackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Asylum_ResponseAsylum BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Audit_TFTP_Get_FilenameTFTP Get FilenameDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Avaya_Cajun_Default_SNMPAvaya SNMP agent back door community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BGP_Illegal_SizeIllegal size BGP message or parameterEnabled LOWDISPLAY LOGDB LogWithoutRaw
BGP_New_RouteBGP new route advertisementDisabled LOWDISPLAY LOGDB LogWithoutRaw
BGP_Notify_MsgBGP notification messageDisabled LOWDISPLAY LOGDB LogWithoutRaw
BGP_Route_UnreachableBGP route has become unreachableDisabled LOWDISPLAY LOGDB LogWithoutRaw
BOOTP_Remote_OverflowBOOTP File OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackConstruction_ResponseBackConstruction backdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_TCP_Auth_RequestBack Orifice 2000 pingEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_TCP_Auth_ResponseBack Orifice 2000 authEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_TCP_RequestBack Orifice 2000 commandEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_TCP_ResponseBack Orifice 2000 responseEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_UDP_Auth_RequestBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_UDP_Auth_ResponseBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_UDP_RequestBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_UDP_ResponseBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice_PingBack Orifice pingEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice_RequestBack Orifice scanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice_ResponseBack Orifice responseEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Backdoor2_ResponseBackdoor2 BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BigGluck_ResponseBigGluck BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BioNet_ResponseBionet trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Blazer5_ResponseBlazer5 BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BoinkBoink DoSEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BonkBonk DoSEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Bootparamrpc.bootparam whoami mismatchEnabled LOWDISPLAY LOGDB LogWithoutRaw
Bugs_ResponseBugs BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Cerebus_ScannerCerebus ScanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Chargen_Denial_of_ServiceChargen denial of service attackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Chupacabra_RequestChupacabra BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Cisco_CR_DoSCisco Carriage Return Denial of ServiceEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Cisco_Cable_Docsis_SNMP_CommunityCisco IOS cable-docsis hidden SNMP community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Cisco_ILMI_SNMP_CommunityCisco IOS "ILMI" hidden SNMP community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Cisco_IdentCisco identification port activityEnabled LOWDISPLAY LOGDB LogWithoutRaw
Coma_ResponseComa BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
ConnectionBackdoor_ResponseConnection BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Corrupt_IP_OptionsCorrupt IP optionsEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
CrazzyNet_ResponseCrazzyNet BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_HTTPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_ICMPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_RPCCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_RadiusCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_SMTPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_TFTPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DHCP_AckDHCP AckDisabled LOWDISPLAY LOGDB LogWithoutRaw
DHCP_DiscoverDHCP DiscoverDisabled LOWDISPLAY LOGDB LogWithoutRaw
DHCP_Domain_MetacharDHCP Domain MetacharEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DHCP_Minires_Format_OverflowDHCP Minires library format string overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DHCP_RequestDHCP RequestDisabled LOWDISPLAY LOGDB LogWithoutRaw
DNS_Address_LengthDNS Internet not 4 bytesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Antisniff_OverflowAntiSniff DNS exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Bind_OPT_DoSDNS BIND OPT large UDP payload sizeEnabled LOWDISPLAY LOGDB LogWithoutRaw
DNS_Bind_SIG_OverflowDNS BIND SIG response buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Chaos_RequestDNS Chaos lookupEnabled LOWDISPLAY LOGDB LogWithoutRaw
DNS_Crack_SuccessDNS crack successfulEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Excessive_RequestsExcessive DNS requestsEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
DNS_Format_StringDNS name overflow contains %Enabled MEDIUMDISPLAY LOGDB LogWithoutRaw
DNS_Generic_Intel_OverflowDNS Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_HInfoDNS HINFO queryEnabled LOWDISPLAY LOGDB LogWithoutRaw
DNS_Hostname_OverflowDNS name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Hostname_Overflow_VerylongDNS name overflow very longEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_IQueryDNS IQUERYEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
DNS_IQuery_boDNS I-Query exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_MalformedDNS malformedEnabled LOWDISPLAY LOGDB LogWithoutRaw
DNS_NULL_QueryDNS nullEnabled LOWDISPLAY LOGDB LogWithoutRaw
DNS_NXT_OverflowDNS NXT record overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_NonInternetDNS non-Internet lookupEnabled LOWDISPLAY LOGDB LogWithoutRaw
DNS_PoisonDNS cache poisonEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
DNS_Query_AllDNS dump All requestsDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
DNS_Spoof_FailedDNS spoof attemptEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
DNS_Spoof_SuccessDNS spoof successfulEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
DNS_TSIG_OverflowDNS TSIG name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Version_RequestDNS BIND version requestEnabled LOWDISPLAY LOGDB LogWithoutRaw
DNS_VirusScanTrojanDNS VirusScanTrojanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Zero_Size_UDPArgent Office denial of service attackEnabled LOWDISPLAY LOGDB LogWithoutRaw
DNS_Zone_TransferDNS Zone transfersEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
DNS_Zonexfer_HighDNS Zone Xfer from high port numberEnabled LOWDISPLAY LOGDB LogWithoutRaw
DeepThroat_ResponseDeepThroat BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DeltaSource_ResponseDeltaSource BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Devil_RequestDevil BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Doly_ResponseDoly BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DonaldDick_ResponseDonald Dick BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Dtspcd_OverflowDtspcd OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
EMail_Generic_Intel_OverflowEMAIL Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Echo_Denial_of_ServiceEcho_Denial_of_Service_With_Src_and_Dst_of_7Enabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Echo_Reply_Without_RequestEcho reply without requestEnabled LOWDISPLAY LOGDB LogWithoutRaw
Email_Almail_OverflowE-Mail ALMail pop3 overflow in smtp processing codeEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Amavis_ExecAMaViS EMail Command ExecuteEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Auth_FailedSMTP login failedEnabled LOWDISPLAY LOGDB LogWithoutRaw
Email_Auth_OverflowSMTP Auth OverflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_BioNetBioNet backdoor email alertEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Command_OverflowSMTP command overflowEnabled LOWDISPLAY LOGDB LogWithoutRaw
Email_DataReport SMTP e-mail message bodyDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_DebugE-mail debug attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_DecodeSMTP mail to decode aliasEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_EhloE-mail SMTP Ehlo info leakDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_Encap_Exch_RelaySTMP encapsulated Exchange relayEnabled LOWDISPLAY LOGDB LogWithoutRaw
Email_Encap_RelaySMTP encapsulated relayEnabled LOWDISPLAY LOGDB LogWithoutRaw
Email_Envid_OverflowSMTP ENVID overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_ErrorE-Mail too many errorsEnabled LOWDISPLAY LOGDB LogWithoutRaw
Email_ExchangeStore_DoSMicrosoft Exchange Server DoSEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_ExpnDecode SMTP Expn: lineEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Expn_OverflowSMTP Expn OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_False_AttachmentE-Mail false attachmentEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_FromDecode SMTP From: lineDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_From_OverflowE-Mail FROM: field overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Helo_OverflowSMTP login name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Invalid_CommandSMTP corrupted MAIL commandEnabled LOWDISPLAY LOGDB LogWithoutRaw
Email_Listserv_OverflowSMTP Listserv OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Lotus_DominoLotus_Domino_SMTP_OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Mime_FilenameSMTP MIME filenameDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_Mime_Filename_BlanksSMTP MIME filename repeated blanksEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Mime_Filename_CharsSMTP MIME filename repeated charsEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Mime_Filename_OverflowE-Mail MIME file name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Mime_Name_OverflowE-Mail MIME name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Mime_NullE-Mail MIME null character setEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Name_OverflowSMTP email name overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Outlook_Date_OverflowE-Mail Outlook Date overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_PipeSMTP pipe in mail addressEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Qmail_LengthSMTP Qmail length denial of service attackEnabled LOWDISPLAY LOGDB LogWithoutRaw
Email_Qmail_RcptSMTP Qmail RCPT denial of service attackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Rcpt_TooManyQuotesNetscape Directory Server buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Recipient_DotSMTP Recipient with trailing dotEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Recipient_OverflowSMTP Too many recipientsEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Relay_AttemptSMTP relay attemptEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Relay_SpamDecode SMTP Relay % SPAMEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_ReplyTo_ExecutableE-Mail "Reply-To:" is an executableEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Rpmmail_AliasSMTP mail to rpmmail aliasEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_ServerIDSMTP Server IDDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_SubSevenSubSeven backdoor email alertEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_SubjectDecode E-Mail Subject: lineDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_ToDecode SMTP To: lineDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_To_Dot_DotaVirt create directory vulnerabilityEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_TurnE-mail SMTP Turn attackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_UUDecode_AliasSMTP mail to uudecode aliasEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_VCF_OverflowVCF attachment overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Virus_Double_ExtensionEmail attachment has double extensionEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Virus_IloveyouILOVEYOU wormEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Virus_MelissaMelissa virusEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Virus_PICTURE_EXEEmail PICTURE.EXE virusEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Virus_PapaPapa virusEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Virus_exploreZipExploreZip wormEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Virus_investigatorKeystrokes monitoredEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_VrfySMTP VRFY commandEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Email_Vrfy_OverflowDecode SMTP Vrfy Overflow attacksEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_WIZE-mail WIZ attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Xchg_AuthSMTP Xchg AuthDisabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Y3KY3K backdoor email alertEnabled HIGHDISPLAY LOGDB LogWithoutRaw
EventHorizon_RequestEventHorizon BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
EvilFTP_ResponseEvilFTP trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FSP_Delete_FileFSP protocol delete fileDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FSP_DetectedFSP protocol activityDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FSP_Read_FileFSP protocol read fileDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FSP_Write_FileFSP protocol write fileDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_AIX_OverflowFTP AIX OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Args_OverflowFTP command line overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Auth_FailedFTP login failedEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Command_OverflowFTP command too longEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Cwd_OverflowFTP CWD directory overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Cwd_RootFTP CWD ~root commandEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Cwd_TildeSolaris FTP server shadow file recoveryEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Cwd_conconFTP server denial of service attackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Cwd_dotdotFTP server traversal using CWD and dotdotEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Cybercop_ScanCybercop FTP scanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Data_OverflowFTP data too longEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Delete_Very_LongFTP DELE command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Delete_dotdotFTP server traversal using DELE and dotdotEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_FileName_BdlFTP server traversal using .bdl fileEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_File_ExecFTP file exec exploitEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_FilenameFTP File NameDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Filename_OverflowFTP file name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Floppy_DoSFTP server floppy drive denial of service attackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Fname_Eftp2Encrypted FTP password disclosureEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Fname_LnkFTP server traversal using .lnk fileEnabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Format_StringFTP Site Exec Format AttackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Generic_Intel_OverflowFTP Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_GetDecode FTP get file commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Glob_ExpansionFTP Glob Expansion CharactersEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Glob_ImplementationFTP Glob Expansion CharactersEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Glob_TildeBrace_VulnsFTP server vulnerable to args with ~ and {Enabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Help_OverflowFTP HELP OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Invalid_Port_CmdFTP invalid PORT commandEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_List_dotdotFTP server traversal using LIST and dotdotEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Login_OverflowFTP USER name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Mdtm_Very_LongFTP MDTM command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Mget_DotDotFTP Mget DotDotEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Mkd_OverflowFTP MKD directory overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_MkdirDecode FTP mkdir commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Mlst_Very_LongFTP MLST command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NLST_OverflowFTP NLST directory overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Dele_OverflowFTP NetTerm Dele OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Dir_OverflowFTP NetTerm Dir OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Ls_OverflowFTP NetTerm Ls OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Mkd_OverflowFTP NetTerm Mkd OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Pass_OverflowFTP NetTerm Pass OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Rmdir_OverflowFTP NetTerm Rmdir OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_PassDecode FTP password commandDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Passive_Very_LongFTP PASV command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Password_OverflowFTP password overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_PasvFTP PASV commandDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Pasv_DOSFTP Pasv DoSEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_PipeFTP pipe in filenameEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_PortFTP Port CommandDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Port_BounceFTP PORT bounce to other systemEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Port_Very_LongFTP PORT command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_PrivilegedBounceFTP PrivilegedBounceEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_PrivilegedPortFTP PORT restrictedEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_ProFTPDProFTPD snprintf exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_PutDecode FTP put file commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Restart_Very_LongFTP REST command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Retr_Very_LongFTP RETR command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Retr_dotdotFTP server traversal using RETR and dotdotEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Rmd_Very_LongFTP RMD command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Rnfr_Very_LongFTP RNFR command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Rnto_Very_LongFTP RNTO command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Server_IdentityFTP Server IdentityDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Site_Chown_OverflowFTP Site Chown OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Site_CmdFTP SITE EXEC commandEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Site_CpwdFTP Site Cpwd overflow attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Site_ExecFTP SITE EXEC exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Site_Exec_DotDotFTP site exec .. attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Site_Exec_TarFTP Site Exec TarEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Site_PswdFTP SITE PSWD exploitEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Size_Very_LongFTP SIZE command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Size_dotdotFTP server traversal using SIZE and dotdotEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Stat_Very_LongFTP STAT command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Stor_Very_LongFTP STOR command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_SystFTP SYST command decodeDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Tar_ExecFTP compress exec exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Unix_Password_FileFTP passwd fileEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Unix_RemoteHost_FileFTP Remote Host FileEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_UserDecode FTP username commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Virus_Wm_Marker_AW97M.Marker.a virusEnabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Windows_Drive_PathFTP server traversal using windows drivesEnabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Windows_INI_FileFTP win.ini fileEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_Windows_PWL_FileFTP pwl file typeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Windows_SAM_FileFTP sam fileEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_ZIPCHK_MetaFTP SITE ZIPCHK metacharactersEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_ZIPCHK_OverflowFTP SITE ZIPCHK buffer overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FTP_dotdotdotFTP server traversal using dotdotdotEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
FW1_Auth_As_LocalFireWall-1 misconfiguration allows manipulation of filter modulesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FW1_Auth_ReplayFireWall-1 FWA1 authentication weaknessEnabled LOWDISPLAY LOGDB LogWithoutRaw
FW1_GetTopologyFireWall-1 allows remote "get topology" requests without authenticationEnabled LOWDISPLAY LOGDB LogWithoutRaw
FastTrack_DownloadFastTrack DownloadDisabled LOWDISPLAY LOGDB LogWithoutRaw
Finger_BackdoorFinger BackdoorEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Finger_CommandFinger commandEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Finger_EnumerationFinger EnumerationEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Finger_ForwardingFinger forwardingEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Finger_Forwarding_DOSFinger forwarding overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Finger_Generic_Intel_OverflowFinger Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Finger_ListFinger listEnabled LOWDISPLAY LOGDB LogWithoutRaw
Finger_OverflowFinger overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Finger_Overflow_RTMFinger RTM overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Finger_ScanFinger ScanEnabled LOWDISPLAY LOGDB LogWithoutRaw
Finger_SearchFinger searchEnabled LOWDISPLAY LOGDB LogWithoutRaw
Finger_UserFinger AttemptEnabled LOWDISPLAY LOGDB LogWithoutRaw
ForcedEntry_ResponseForcedEntry BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Fore_ResponseFore BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FragRoute_TCP_Chaff_PAWSFragRoute tcp_chaff paws detectedEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Fraggle_AttackPossible Fraggle attack initiatedEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Fragment_Differential_OverlapIP fragment data changedEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Fragment_Differential_SizeIP last fragment length changedEnabled LOWDISPLAY LOGDB LogWithoutRaw
Fragment_Resources_ExhaustedToo much IP fragmentationEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Freak88_ResponseFreak88 BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Frenzy_ResponseFrenzy BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
GateCrasher_ResponseGateCrasher trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Gauntlet_CyberDaemon_OverflowGauntlet CyberDaemon proxy buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Gauntlet_ICMP_DoSICMP Protocol Problem packet with encapsulated IP header with optionsEnabled HIGHDISPLAY LOGDB LogWithoutRaw
GayOL_RequestGayOL BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
GirlFriend_ResponseGirlFriend trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Glacier_RequestGlacier BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Glacier_ResponseGlacier BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Gnutella_BearShareGnutella BearShareDisabled LOWDISPLAY LOGDB LogWithoutRaw
Gnutella_ConnectGnutella connectionDisabled LOWDISPLAY LOGDB LogWithoutRaw
Gnutella_DownloadGnutella file transferDisabled LOWDISPLAY LOGDB LogWithoutRaw
Gnutella_LimeWireGnutella LimeWireDisabled LOWDISPLAY LOGDB LogWithoutRaw
Gnutella_WormGnutella WormEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HPUX_RLPD_OverflowHPUX RLPD buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HP_OpenView_NNM_OverflowHP OpenView Network Node Manager buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HP_OpenView_SNMP_BackdoorHP OpenView SNMP agent back door community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_$DATA_Source_DisclosedIIS source code disclosureEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_EasySetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_FilteringSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_FirmwareSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_ModemSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_RFSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_SNMPSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_SecuritySetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_SpecialFunctions3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw