ISS RealSecure Network Sensor Policy
[ issPolicy v1.01 | http://packet.sequenced.org/projects/isspolicy ]



POLICY INFORMATION

   Policy File: policies/AttackDetector.policy
   Policy Name: Attack Detector
   Policy Version: 7.0.2003.59
   Sensor Type: RealSecure Network Sensor (v7.0)


SIGNATURES POLICY

Response Summary Legend: DISPLAY | LOGDB | EMAIL | SNMP | RSKILL | OPSEC | LOGEVIDENCE | VIEWSESSION

Signature NameSignature DescriptionSignature StatusSignature PriorityResponse SummaryLog
AIX_Pdnsd_OverflowAIX pdnsd buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
AOLIM_AddExternalApp_OverflowAOL Instant Messenger AddExternalApp OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
AOLIM_GameRequest_OverflowAOL Instant Messenger game request overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Allaire_JRun_JSP_ExecuteAllaire JRun JSP executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Allaire_JRun_SSIFilterAllaire JRun SSIFilter servletEnabled HIGHDISPLAY LOGDB LogWithoutRaw
AolAdmin_ResponseAolAdmin BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Asylum_ResponseAsylum BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Avaya_Cajun_Default_SNMPAvaya SNMP agent back door community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BOOTP_Remote_OverflowBOOTP File OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackConstruction_ResponseBackConstruction backdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_TCP_Auth_RequestBack Orifice 2000 pingEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_TCP_Auth_ResponseBack Orifice 2000 authEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_TCP_RequestBack Orifice 2000 commandEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_TCP_ResponseBack Orifice 2000 responseEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_UDP_Auth_RequestBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_UDP_Auth_ResponseBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_UDP_RequestBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice2K_UDP_ResponseBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice_PingBack Orifice pingEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice_RequestBack Orifice scanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BackOrifice_ResponseBack Orifice responseEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Backdoor2_ResponseBackdoor2 BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BigGluck_ResponseBigGluck BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BioNet_ResponseBionet trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Blazer5_ResponseBlazer5 BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BoinkBoink DoSEnabled HIGHDISPLAY LOGDB LogWithoutRaw
BonkBonk DoSEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Bugs_ResponseBugs BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Cerebus_ScannerCerebus ScanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Chupacabra_RequestChupacabra BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Cisco_Cable_Docsis_SNMP_CommunityCisco IOS cable-docsis hidden SNMP community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Cisco_ILMI_SNMP_CommunityCisco IOS "ILMI" hidden SNMP community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Coma_ResponseComa BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
ConnectionBackdoor_ResponseConnection BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CrazzyNet_ResponseCrazzyNet BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_HTTPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_ICMPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_RPCCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_RadiusCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_SMTPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
CyberCop_Scanner_TFTPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DHCP_Domain_MetacharDHCP Domain MetacharEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DHCP_Minires_Format_OverflowDHCP Minires library format string overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Address_LengthDNS Internet not 4 bytesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Antisniff_OverflowAntiSniff DNS exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Bind_SIG_OverflowDNS BIND SIG response buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Crack_SuccessDNS crack successfulEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Generic_Intel_OverflowDNS Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Hostname_OverflowDNS name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_Hostname_Overflow_VerylongDNS name overflow very longEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_IQuery_boDNS I-Query exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_NXT_OverflowDNS NXT record overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_TSIG_OverflowDNS TSIG name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DNS_VirusScanTrojanDNS VirusScanTrojanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DeepThroat_ResponseDeepThroat BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DeltaSource_ResponseDeltaSource BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Devil_RequestDevil BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Doly_ResponseDoly BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
DonaldDick_ResponseDonald Dick BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Dtspcd_OverflowDtspcd OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
EMail_Generic_Intel_OverflowEMAIL Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Amavis_ExecAMaViS EMail Command ExecuteEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_BioNetBioNet backdoor email alertEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_DebugE-mail debug attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_DecodeSMTP mail to decode aliasEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Expn_OverflowSMTP Expn OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_From_OverflowE-Mail FROM: field overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Helo_OverflowSMTP login name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Listserv_OverflowSMTP Listserv OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Lotus_DominoLotus_Domino_SMTP_OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Mime_Filename_OverflowE-Mail MIME file name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Mime_Name_OverflowE-Mail MIME name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Outlook_Date_OverflowE-Mail Outlook Date overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_PipeSMTP pipe in mail addressEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Rcpt_TooManyQuotesNetscape Directory Server buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Rpmmail_AliasSMTP mail to rpmmail aliasEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_SubSevenSubSeven backdoor email alertEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_UUDecode_AliasSMTP mail to uudecode aliasEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Virus_IloveyouILOVEYOU wormEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Virus_MelissaMelissa virusEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Virus_PapaPapa virusEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Virus_exploreZipExploreZip wormEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Virus_investigatorKeystrokes monitoredEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Vrfy_OverflowDecode SMTP Vrfy Overflow attacksEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_WIZE-mail WIZ attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Email_Y3KY3K backdoor email alertEnabled HIGHDISPLAY LOGDB LogWithoutRaw
EventHorizon_RequestEventHorizon BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
EvilFTP_ResponseEvilFTP trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_AIX_OverflowFTP AIX OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Args_OverflowFTP command line overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Command_OverflowFTP command too longEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Cwd_OverflowFTP CWD directory overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Cwd_RootFTP CWD ~root commandEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Cybercop_ScanCybercop FTP scanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Delete_Very_LongFTP DELE command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Filename_OverflowFTP file name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Format_StringFTP Site Exec Format AttackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Generic_Intel_OverflowFTP Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Glob_ExpansionFTP Glob Expansion CharactersEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Glob_ImplementationFTP Glob Expansion CharactersEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Glob_TildeBrace_VulnsFTP server vulnerable to args with ~ and {Enabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Help_OverflowFTP HELP OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Invalid_Port_CmdFTP invalid PORT commandEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_List_dotdotFTP server traversal using LIST and dotdotEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Login_OverflowFTP USER name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Mdtm_Very_LongFTP MDTM command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Mkd_OverflowFTP MKD directory overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Mlst_Very_LongFTP MLST command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Dele_OverflowFTP NetTerm Dele OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Dir_OverflowFTP NetTerm Dir OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Ls_OverflowFTP NetTerm Ls OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Mkd_OverflowFTP NetTerm Mkd OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Pass_OverflowFTP NetTerm Pass OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_NetTerm_Rmdir_OverflowFTP NetTerm Rmdir OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Passive_Very_LongFTP PASV command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Password_OverflowFTP password overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_PipeFTP pipe in filenameEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Port_Very_LongFTP PORT command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_ProFTPDProFTPD snprintf exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Restart_Very_LongFTP REST command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Retr_Very_LongFTP RETR command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Rmd_Very_LongFTP RMD command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Rnfr_Very_LongFTP RNFR command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Rnto_Very_LongFTP RNTO command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Site_Chown_OverflowFTP Site Chown OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Site_CpwdFTP Site Cpwd overflow attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Site_ExecFTP SITE EXEC exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Site_Exec_DotDotFTP site exec .. attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Site_Exec_TarFTP Site Exec TarEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Size_Very_LongFTP SIZE command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Stat_Very_LongFTP STAT command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Stor_Very_LongFTP STOR command buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Tar_ExecFTP compress exec exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Unix_Password_FileFTP passwd fileEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FTP_Windows_PWL_FileFTP pwl file typeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
FW1_Auth_As_LocalFireWall-1 misconfiguration allows manipulation of filter modulesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Finger_CommandFinger commandEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Finger_Generic_Intel_OverflowFinger Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Finger_OverflowFinger overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
ForcedEntry_ResponseForcedEntry BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Fore_ResponseFore BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Freak88_ResponseFreak88 BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Frenzy_ResponseFrenzy BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
GateCrasher_ResponseGateCrasher trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Gauntlet_CyberDaemon_OverflowGauntlet CyberDaemon proxy buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Gauntlet_ICMP_DoSICMP Protocol Problem packet with encapsulated IP header with optionsEnabled HIGHDISPLAY LOGDB LogWithoutRaw
GayOL_RequestGayOL BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
GirlFriend_ResponseGirlFriend trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Glacier_RequestGlacier BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Glacier_ResponseGlacier BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Gnutella_WormGnutella WormEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HPUX_RLPD_OverflowHPUX RLPD buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HP_OpenView_NNM_OverflowHP OpenView Network Node Manager buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HP_OpenView_SNMP_BackdoorHP OpenView SNMP agent back door community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_$DATA_Source_DisclosedIIS source code disclosureEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_EasySetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_FilteringSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_FirmwareSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_ModemSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_RFSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_SNMPSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_SecuritySetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_SpecialFunctions3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_3com_AirConnect_SystemSetup3com AirConnect configurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_ACCEPT_OverflowHTTP ACCEPT: field overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_ASP_Stateserver_OverflowHTTP ASP Stateserver OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Advancestack_BypassAuthHP Advancestack bypass authenticationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_AnswerBook2_AdminSolaris AnswerBook2 administrator accessEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_AnswerBook2_DocServerSolaris AnswerBook2 arbitrary command executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_AnswerBook2_ExecuteSolaris AnswerBook2 arbitrary command executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Answerbook_AddAdminSun AnswerBook2 AddAdmin ScriptsEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Answerbook_Format_StringSun AnswerBook2 format stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_AnyFormCGI AnyForm2Enabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_AnyForm_PostCGI AnyForm PostEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Apache_Chunked_BOHTTP Apache Chunked BOEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Apache_PHPApache PHP.EXE file executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_AuctionweaverAuction Weaver CGI exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_AuthFilter_ISAPI_OverflowHTTP AuthFilter ISAPI OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Auth_TooLongHTTP Authentication overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_BAT_Executebat URL typeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_BBN_surveyBNBSurvey survey.cgiEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_BioNet_ICQ_PagerDetect BioNet backdoor ICQ page alertEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Bugbear_BackdoorBugbear worm HTTP backdoor trafficEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_CGI_FastgrafHTTP Fastgraf CGIEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_CGI_Guestbook_MetaCGI guestbook.plEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_CMD_Executecmd URL typeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Calender_AdminCalendar CGI exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_CampasCGI campasEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_CarelloHTTP Carello File DuplicationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Cart32_ChangeAdminPasswordCart32 ChangeAdminPassword URLEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Cart32_ClientListHTTP Cart32 Client ListEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_CdomainHTTP Cdomain cgi-bin attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_CheckLoginPhpphpSecurePages arbitrary code executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Cisco_Aironet_WebconfigCisco Aironet configigurationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Cisco_Catalyst_ExecCisco Catalyst 2900/3500 XL remote executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Cisco_IOS_Admin_AccessCisco IOS athentication bypassedEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_CobaltRAQ_OverflowCGICobalt RaQ with SHP allows arbitrary command execution.Enabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Code_RedCode Red IEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Code_Red_IICode Red IIEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Code_Red_II_PlusCode Red II+Enabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_ColdFusion_Expr_EvaluatorCold Fusion Sample URLEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_ColdFusion_WebPublish_ExampleAppHTTP ColdFusion WebPublishing Example AppEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Compaq_Insight_Cpqlogin_OverflowMalformed login requests can cause execeptions in Compaq Insight.Enabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_CountHTTP count Cgi-Bin Exploit CheckEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Csvform_ExecuteCSVForm CGI script arbitrary command executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_DCForum_Admin_AccessDCForum allows administrative accessEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_DCForum_File_UploadDCForum file uploadEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_DCShop_infoDCShop Txt InformationEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Dansie_BackdoorDansie Shopping Cart allows remote command executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Dir_Manager_exeDirectory Manager edit_image.php ExecutionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_DotDotHTTP URL directory traversal/climbingEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_EZShopper_LoadpageEZShopper loadpage.cgi could be used to execute arbitrary commandsEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_EZShopper_SearchEZShopper search.cgi could be used to execute arbitrary commandsEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Eva_Forms_BoEva Forms OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Favorites_Icon_Overflowfavicon.ico bad formatEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_FaxSurveyCGI faxsurveyEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_FileTypeLnk.lnk URL typeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_FileTypeUrl.url URL typeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_FormMailCGI formmailEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Frontpage_Extensions_RAD_OverflowFrontpage fp30reg.dll OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GET_ComputeSumHTTP GET contains Compute SumEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GET_CreateTableHTTP GET contains Create TableEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GET_DotDot_DataHTTP CGI data contains ../../../..Enabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GET_Filename_pwlHTTP GET pwl file type.Enabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GET_GroupByHTTP GET contains Group ByEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GET_Very_LongHTTP GET data overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GET_XP_CmdshellHTTP GET contains xp_cmdshellEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GETargscriptHTTP GET data contains scriptEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Generic_Intel_OverflowHTTP Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GetAccess_loginGetAccess Login ExecutionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GlimpseCGI glimpseEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_GuestbookHTTP Guestbook vulnerable CGI scriptEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_HTMLScriptHTTP access to HTMLScript CGI to read filesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_HackATack_ICQ_PagerDetect Hack-a-tack backdoor ICQ page alertEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Hassan_ExecuteHassan Shopping Cart arbitrary command execEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Htimage_ExeFrontPage htimage.exe URLEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IE_HTML_Embed_OverflowHTML Embed directive buffer overflow in IEEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IISHTR_OverflowIIS HTR OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_ASP_Chunked_OverflowHTTP IIS Chunked EncodingEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_CmdAspIIS CmdAsp allows privlaged executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_CsimpleIIS ASP data transfer heap overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_HTR_Chunked_OverflowHTTP IIS HTR Chunked OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_ISAPI_Printer_OverflowIIS .printer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_IndexSearchIIS Index Search buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_Index_Server_OverflowISAPI index extension overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_MSSQL_XML_ScriptMicrosoft SQL Server SQLXML ISAPI script injectionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_MSSQL_xmlMicrosoft SQL Server SQLXML ISAPI buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_Trailing_SlashHTTP IIS .asp with trailing slashEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_Unicode_EncodingUnicode Encoding detected in URLEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_dumpvariablesIIS ASP HTTP header parsing buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_htr_isapiIIS ASP HTR ISAPI OverflowsEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IIS_ssiIIS SSI safety check buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Imagemap_ExeCGI imagemap.exeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_IndexServer_Source_DisclosureIndex Server null.htw exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Info2WWWCGI info2wwwEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_InterScan_VirusWall_OverflowVirusWall DLL buffer overflow attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_InterscanViruswall_RegGoViruswall RegGo.dll buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_InterscanViruswall_SmtpscanViruswall smtpscan.dll buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_JJ_OverflowCGI jj exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_JRun_Double_SlashJRun Double fowardslash Authentication BypassEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_JRun_IIS_OverflowMacromedia JRun and ColdFusion long URL overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_JRun_ISAPI_HostJRun ISAPI.DLL Host overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Java_Webadmin_BBSJava Admin Servlet backdoor URLEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_LastlinesCgi_CmdExecuteLastlines.cgi arbitrary command executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Listrec_ExecuteListrec.pl ExecutionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Listserv_WaexeListserv CGI exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_MDAC_AccessIIS data service queryEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_MDAC_RDS_OverflowMDAC RDS OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_MSCS_ProfileSvc_OverflowHTTP MS Commerce Server Profile Service API buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_MSRadio_OverflowInternet Explorer msradio buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Mailsite_WconsoleRockliffe CGI exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Mambo_PhpsessidMambo Site Server administrator privilegesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Netscape_URI_OverflowNetscape Enterprise Server denial of serviceEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Nimda_WormHTTP NimdaEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Novell_ConvertHTTP Novell convert cgi-bin attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_OWC_Installer_OverflowHTTP MS Commerce Server OWC pkg installer buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_OracleAdmin_help_overflowOracle Admin help overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_OracleApp_soapOracle Application Server soap ConfigEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Oracle_Appserver_OverflowOracleAppserver buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Oracle_Appserver_rwcgi60Oracle Application Server Demo sendmail jspEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Oracle_BatchfileOracle batch file URLEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PDGSoft_ChangepwPDGSoft Shopping Cart buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHF_CommandExecCGI phfEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHPMyAdmin_EvalExecutephpMyAdmin arbitrary command executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHPMyAdmin_SqlPhpphpPgAdmin arbitrary code executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHPMyAdmin_Sql_IncludeMyAdmin sql.php Include FilesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHPNuke_Admin_AccessPHP-Nuke URL configuration allows administrator access to the programEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHPNuke_Index_FilePHP Nuke index.php HTTP FilesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHPNuke_Prefix_AdminPHPNuke administrative database accessEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHP_IncludedirPhp #includedir code executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHP_LoadPrefsSquirrelMail arbitrary code executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHP_Memchr_BOHTTP PHP buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PHP_OverflowHTTP PHP buffer overflow attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_POST_ComputeSumHTTP POST contains Compute SumEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_POST_CreateTableHTTP POST contains Create TableEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_POST_Filename_passwdHTTP POST passwd fileEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_POST_GroupByHTTP POST contains Group ByEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_POST_PeopleSoft_TraversalHTTP POST PeopleSoft Directory TraversalEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Passwd_Txtpasswd.txt URLEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Pfdispaly_ExecuteHTTP Pfdisplay ExecuteEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PlanetIntra_OverflowPlanet Intra buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Polycom_Reveal_PasswordHTTP Polycom password disclosedEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_PostQueryCgiPost-query buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_Post_Filename_pwlHTTP POST pwl file typeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_RpcNLogHTTP access of vulnerable Nlog CGI scriptEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_SCO_View_SourceCGI view-sourceEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_SGI_HandlerCGI handlerEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_SGI_InfosrchInfoSearch CGI exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
HTTP_SGI_WebdistHTTP SGI Webdist cgi-bin attackEnabled HIGH</