[Silicon Defense logo]

SnortSnarf alert page

Source: 130.54.208.193: #101-200

SnortSnarf v021111.1

Signature section (16810)Top 20 source IPsTop 20 dest IPs

Looking using input module SnortFileInput, with sources:
Earliest: 10:25:08.150558 on 04/20/2010
Latest: 09:16:31.573988 on 05/01/2010

9 different signatures are present for 130.54.208.193 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

130.54.208.193 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


Go to: previous range, next range, all alerts, overview page
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/20-10:25:08.150558 130.54.208.193:35584 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:244
***AP*** Seq: 0x9C545FB0 Ack: 0x410DB16E Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/20-10:31:27.146000 130.54.208.193:58362 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:543
***AP*** Seq: 0xCF9A8DF3 Ack: 0x7295BE38 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/20-10:52:53.892206 130.54.208.193:36228 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1649
***AP*** Seq: 0xD3CBC714 Ack: 0x2047C636 Win: 0x16D0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/20-12:55:17.877567 130.54.208.193:48478 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1854
***AP*** Seq: 0xEC8EEF99 Ack: 0xC14A25EB Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/20-15:29:04.280290 130.54.208.193:1718 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1649
***AP*** Seq: 0x7C7CEA1 Ack: 0x3217695C Win: 0x6C0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/20-15:44:40.583419 130.54.208.193:55996 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:193
***AP*** Seq: 0x67B6E68E Ack: 0x18D7FC39 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/20-21:24:54.634229 130.54.208.193:36326 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:536
***AP*** Seq: 0x6A55396B Ack: 0xB6619FBF Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-09:59:16.136850 130.54.208.193:32778 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:331
***AP*** Seq: 0x8AEE057F Ack: 0x652B03D5 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-09:59:16.983259 130.54.208.193:32778 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:324
***AP*** Seq: 0x8AEE0725 Ack: 0x652B04F1 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-09:59:17.592598 130.54.208.193:32778 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:321
***AP*** Seq: 0x8AEE08C2 Ack: 0x652B060A Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-09:59:18.681107 130.54.208.193:32778 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:523
***AP*** Seq: 0x8AEE0B94 Ack: 0x652B07ED Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-10:46:50.796221 130.54.208.193:57041 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:346
***AP*** Seq: 0x3565A05E Ack: 0xE5A3B009 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:20:56.754763 130.54.208.193:32811 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:172
***AP*** Seq: 0xBEBDB92B Ack: 0x9021FA9D Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:20:57.343078 130.54.208.193:32811 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:335
***AP*** Seq: 0xBEBDBAD1 Ack: 0x9021FBC4 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:21:01.525041 130.54.208.193:32811 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1331
***AP*** Seq: 0x9021FFFB Ack: 0xBEBDC2B2 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:43:16.030286 130.54.208.193:47008 -> 192.168.24.11:143
TCP TTL:47 TOS:0x0 ID:15008 IpLen:20 DgmLen:262 DF
***AP*** Seq: 0xC2D4BA48 Ack: 0x11E71079 Win: 0x3E96 TcpLen: 32
TCP Options (3) => NOP NOP TS: 69983267 112508173
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:44:10.322561 130.54.208.193:47008 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:243
***AP*** Seq: 0x11E92E49 Ack: 0xC2D4BFB7 Win: 0x29E0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:44:13.976034 130.54.208.193:47008 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:256
***AP*** Seq: 0x11E9D3E5 Ack: 0xC2D4C17D Win: 0x29E0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:44:17.830515 130.54.208.193:47008 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1218
***AP*** Seq: 0x11E9DC06 Ack: 0xC2D4C617 Win: 0x29E0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:44:38.360283 130.54.208.193:32811 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:263
***AP*** Seq: 0xBEBDE1EA Ack: 0x90220540 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:44:44.069978 130.54.208.193:32811 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:269
***AP*** Seq: 0xBEBF56C4 Ack: 0x90220625 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:44:45.979039 130.54.208.193:32811 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:263
***AP*** Seq: 0xBEBF58F1 Ack: 0x90220704 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:44:48.778969 130.54.208.193:32811 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:283
***AP*** Seq: 0xBEBF5B4E Ack: 0x902207F7 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-11:44:50.998782 130.54.208.193:32811 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:256
***AP*** Seq: 0x902208BA Ack: 0xBEBF5C92 Win: 0x875A TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-17:21:33.859422 130.54.208.193:32937 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:312
***AP*** Seq: 0xB062B17F Ack: 0xE7C8780 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/21-17:37:55.334803 130.54.208.193:32937 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1451
***AP*** Seq: 0xB062B9B6 Ack: 0xE7D300D Win: 0x875A TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/22-11:54:49.173657 130.54.208.193:32983 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:439
***AP*** Seq: 0x744B9252 Ack: 0x488FE2DF Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/22-11:55:03.999263 130.54.208.193:32983 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:541
***AP*** Seq: 0x744CC3ED Ack: 0x488FE5CE Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/22-11:55:28.799401 130.54.208.193:32983 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:502
***AP*** Seq: 0x744E294D Ack: 0x488FE79C Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/22-11:55:29.780231 130.54.208.193:32983 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:233
***AP*** Seq: 0x488FE849 Ack: 0x744EC90D Win: 0x7C86 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/22-12:11:04.824759 130.54.208.193:32983 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1451
***AP*** Seq: 0x488FE89D Ack: 0x744EC9D1 Win: 0x7C86 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/22-19:57:13.408799 130.54.208.193:33004 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:353
***AP*** Seq: 0x8F473E62 Ack: 0xA9B32DA Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/22-19:57:18.468028 130.54.208.193:33004 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:343
***AP*** Seq: 0x8F47B53C Ack: 0xA9B3409 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-08:51:28.616439 130.54.208.193:32793 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:331
***AP*** Seq: 0x96D939E5 Ack: 0x90D7B95 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-08:51:29.570096 130.54.208.193:32793 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:324
***AP*** Seq: 0x96D93B8B Ack: 0x90D7CB1 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-08:51:30.208546 130.54.208.193:32793 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:321
***AP*** Seq: 0x96D93D28 Ack: 0x90D7DCA Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-08:51:31.418139 130.54.208.193:32793 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:523
***AP*** Seq: 0x96D93FFA Ack: 0x90D7FAD Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-09:06:55.519491 130.54.208.193:32793 -> 192.168.24.11:143
TCP TTL:47 TOS:0x0 ID:45888 IpLen:20 DgmLen:261 DF
***AP*** Seq: 0x90D8432 Ack: 0x96DBA683 Win: 0x7C86 TcpLen: 32
TCP Options (3) => NOP NOP TS: 145118 154771303
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-09:07:06.484798 130.54.208.193:32793 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:353
***AP*** Seq: 0x96DC5C3D Ack: 0x90D86F1 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-09:07:10.046476 130.54.208.193:32793 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:217
***AP*** Seq: 0x96DC8E53 Ack: 0x90D8859 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-09:31:48.339804 130.54.208.193:46442 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:241
***AP*** Seq: 0x2F89CA19 Ack: 0x9B4C028A Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-09:31:49.524363 130.54.208.193:46442 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:612
***AP*** Seq: 0x2F89CD64 Ack: 0x9B4C04C6 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-09:31:50.758626 130.54.208.193:46442 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:535
***AP*** Seq: 0x2F89D034 Ack: 0x9B4C06B5 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-09:31:51.019494 130.54.208.193:46442 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:178
***AP*** Seq: 0x2F89D108 Ack: 0x9B4C073F Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-14:38:36.827945 130.54.208.193:37865 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:246
***AP*** Seq: 0xB49F5EE2 Ack: 0x1C5217D5 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-14:38:38.217524 130.54.208.193:37865 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:544
***AP*** Seq: 0xB49F61C3 Ack: 0x1C5219CD Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-14:38:38.800109 130.54.208.193:37865 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:253
***AP*** Seq: 0xB49F62F5 Ack: 0x1C521AA2 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-14:38:39.578974 130.54.208.193:37865 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:251
***AP*** Seq: 0xB49F6428 Ack: 0x1C521B75 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-14:38:40.210351 130.54.208.193:37865 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:249
***AP*** Seq: 0xB49F6567 Ack: 0x1C521C46 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-14:38:45.031766 130.54.208.193:37865 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:392
***AP*** Seq: 0xB49F67E7 Ack: 0x1C521DA6 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-14:38:47.251725 130.54.208.193:37865 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:223
***AP*** Seq: 0xB49F6AB2 Ack: 0x1C521E5D Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-21:42:01.569662 130.54.208.193:57246 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:750
***AP*** Seq: 0xF0B766CD Ack: 0x5B5BF5D3 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-21:42:02.783355 130.54.208.193:57246 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:535
***AP*** Seq: 0xF0B7699D Ack: 0x5B5BF7C2 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-21:42:03.140431 130.54.208.193:57246 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:241
***AP*** Seq: 0xF0B76AD1 Ack: 0x5B5BF88B Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/26-21:45:30.918049 130.54.208.193:57246 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:287
***AP*** Seq: 0xF0B86CD8 Ack: 0x5B5BFFA0 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-09:37:02.375502 130.54.208.193:57058 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:311
***AP*** Seq: 0x756990A4 Ack: 0xE4083223 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-09:37:04.238082 130.54.208.193:57058 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:258
***AP*** Seq: 0x756A7D88 Ack: 0xE40832FD Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-09:37:04.700554 130.54.208.193:57058 -> 192.168.24.11:143
TCP TTL:47 TOS:0x0 ID:60591 IpLen:20 DgmLen:266 DF
***AP*** Seq: 0xE408332E Ack: 0x756AABF4 Win: 0x3E96 TcpLen: 32
TCP Options (3) => NOP NOP TS: 85700411 163592444
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-10:39:10.362197 130.54.208.193:45197 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:249
***AP*** Seq: 0x62701BA3 Ack: 0xD2FFBE09 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-12:09:32.918270 130.54.208.193:42633 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1451
***AP*** Seq: 0xFD237533 Ack: 0x8E4AC64A Win: 0x3E96 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-12:32:13.570518 130.54.208.193:42633 -> 192.168.24.11:143
TCP TTL:47 TOS:0x0 ID:37421 IpLen:20 DgmLen:262 DF
***AP*** Seq: 0xFD237B0E Ack: 0x8E4ADD68 Win: 0x3E96 TcpLen: 32
TCP Options (3) => NOP NOP TS: 96211584 164643240
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-12:32:15.756428 130.54.208.193:42633 -> 192.168.24.11:143
TCP TTL:47 TOS:0x0 ID:37475 IpLen:20 DgmLen:264 DF
***AP*** Seq: 0xFD237CB8 Ack: 0x8E4D6463 Win: 0x3E96 TcpLen: 32
TCP Options (3) => NOP NOP TS: 96213771 164643511
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-12:32:16.727344 130.54.208.193:42633 -> 192.168.24.11:143
TCP TTL:47 TOS:0x0 ID:37498 IpLen:20 DgmLen:280 DF
***AP*** Seq: 0xFD237D8E Ack: 0x8E4EAC9D Win: 0x3E96 TcpLen: 32
TCP Options (3) => NOP NOP TS: 96214742 164643611
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-12:32:23.848717 130.54.208.193:42633 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:440
***AP*** Seq: 0x8E507487 Ack: 0xFD238004 Win: 0x2E10 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-14:18:49.583820 130.54.208.193:46659 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:265
***AP*** Seq: 0x9FCC873C Ack: 0x10CB4D27 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-14:19:15.507387 130.54.208.193:46659 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1066
***AP*** Seq: 0x9FCC8EAD Ack: 0x10CB5129 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-14:19:16.025844 130.54.208.193:46659 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:357
***AP*** Seq: 0x9FCC9105 Ack: 0x10CB5266 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-14:19:17.485913 130.54.208.193:46659 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:201
***AP*** Seq: 0x9FCCE6A2 Ack: 0x10CB5307 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-14:44:33.801597 130.54.208.193:46659 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1451
***AP*** Seq: 0x10CB5371 Ack: 0x9FCCE7D5 Win: 0x3BF1 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-15:19:17.575655 130.54.208.193:55909 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:244
***AP*** Seq: 0x827F8401 Ack: 0xF3F99D6D Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-15:19:18.635383 130.54.208.193:55909 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:196
***AP*** Seq: 0xF3F99DF5 Ack: 0x827F9AAD Win: 0x3E96 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/27-21:05:14.041159 130.54.208.193:47775 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:219
***AP*** Seq: 0x995C71E8 Ack: 0xC53E954 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-08:40:36.117318 130.54.208.193:41515 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:273
***AP*** Seq: 0xA8F85994 Ack: 0x1F512A40 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-08:40:37.036102 130.54.208.193:41515 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:304
***AP*** Seq: 0xA8F96209 Ack: 0x1F512B48 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-08:40:39.233672 130.54.208.193:41515 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:377
***AP*** Seq: 0xA8F99165 Ack: 0x1F512C99 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-08:40:47.115382 130.54.208.193:41515 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:278
***AP*** Seq: 0xA8FA2861 Ack: 0x1F512D87 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-08:40:47.505940 130.54.208.193:41515 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:303
***AP*** Seq: 0xA8FA2BDE Ack: 0x1F512E8E Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-08:40:52.655204 130.54.208.193:41515 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:360
***AP*** Seq: 0xA8FAD451 Ack: 0x1F5130C6 Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-08:40:56.075988 130.54.208.193:41515 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:285
***AP*** Seq: 0xA8FAE6B3 Ack: 0x1F5131BB Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-08:51:55.377444 130.54.208.193:32848 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1320
***AP*** Seq: 0x41802CF Ack: 0x7B784509 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-11:10:16.079510 130.54.208.193:55568 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1700
***AP*** Seq: 0xC5C049C Ack: 0x83B5AFB4 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-12:15:02.017915 130.54.208.193:58757 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1649
***AP*** Seq: 0x7B24D3C6 Ack: 0x30133F5 Win: 0x6C0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-15:19:49.716997 130.54.208.193:39381 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1451
***AP*** Seq: 0xDD79348F Ack: 0x649E5CF8 Win: 0x1185 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-17:41:35.014334 130.54.208.193:54165 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1583
***AP*** Seq: 0xB71EC220 Ack: 0x30A017B7 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-17:42:05.804425 130.54.208.193:54165 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1707
***AP*** Seq: 0xB71ECE19 Ack: 0x30A01E3A Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-17:42:12.885324 130.54.208.193:54165 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:318
***AP*** Seq: 0xB71FAA15 Ack: 0x30A0218C Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/28-17:52:09.645701 130.54.208.193:54165 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:180
***AP*** Seq: 0xB71FAAA1 Ack: 0x30A02218 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/29-16:48:55.280698 130.54.208.193:42400 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:345
***AP*** Seq: 0x3D9CFAE1 Ack: 0xC022B8B7 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/29-16:48:59.969704 130.54.208.193:42400 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:377
***AP*** Seq: 0x3D9D2AB8 Ack: 0xC022BA08 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
04/29-16:49:08.221753 130.54.208.193:42400 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:333
***AP*** Seq: 0x3D9DBEB0 Ack: 0xC022BBF4 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:15:11.008740 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1026
***AP*** Seq: 0xFD169153 Ack: 0xF37EF92B Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:16:00.884645 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:204
***AP*** Seq: 0xFD1831DE Ack: 0xF37EFE5F Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:16:01.325825 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:204
***AP*** Seq: 0xFD184D87 Ack: 0xF37EFF03 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:16:02.121668 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:204
***AP*** Seq: 0xFD18D4C6 Ack: 0xF37EFFA7 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:16:02.744368 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:222
***AP*** Seq: 0xFD1935BD Ack: 0xF37F005D Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:16:04.800425 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:47 TOS:0x0 ID:3845 IpLen:20 DgmLen:266 DF
***AP*** Seq: 0xF37F00DB Ack: 0xFD1965D2 Win: 0x3E96 TcpLen: 32
TCP Options (3) => NOP NOP TS: 254878 198027325
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:16:10.639087 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:255
***AP*** Seq: 0xFD1A1C82 Ack: 0xF37F028A Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:16:25.633209 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:174
***AP*** Seq: 0xFD1B40DD Ack: 0xF37F0676 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:16:30.944749 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:517
***AP*** Seq: 0xFD1B65E2 Ack: 0xF37F0853 Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:16:31.573988 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:203
***AP*** Seq: 0xFD1C3236 Ack: 0xF37F08F6 Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
Go to: previous range, next range, all alerts, overview page
SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Sep 14 05:05:21 2010