[Silicon Defense logo]

SnortSnarf alert page

Source: 130.54.208.193: #201-300

SnortSnarf v021111.1

Signature section (16810)Top 20 source IPsTop 20 dest IPs

Looking using input module SnortFileInput, with sources:
Earliest: 09:16:31.915905 on 05/01/2010
Latest: 11:40:59.607964 on 05/07/2010

9 different signatures are present for 130.54.208.193 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

130.54.208.193 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


Go to: previous range, next range, all alerts, overview page
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:16:31.915905 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:180
***AP*** Seq: 0xFD1C50E2 Ack: 0xF37F0982 Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:26:15.773328 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1471
***AP*** Seq: 0xF37F09EF Ack: 0xFD1C5240 Win: 0x3E96 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:38:41.304803 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1471
***AP*** Seq: 0xF37F0FC7 Ack: 0xFD1C5B13 Win: 0x3E96 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-09:44:10.916443 130.54.208.193:35153 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1471
***AP*** Seq: 0xF37F159F Ack: 0xFD1C63E6 Win: 0x3E96 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-13:22:26.155664 130.54.208.193:33546 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:182
***AP*** Seq: 0xC49816A3 Ack: 0x9E2858B3 Win: 0x7C86 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-21:44:02.257247 130.54.208.193:52918 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:253
***AP*** Seq: 0x3AC1492 Ack: 0x265AC3 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-21:44:03.274600 130.54.208.193:52918 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:470
***AP*** Seq: 0x3AC170E Ack: 0x265C71 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-21:44:04.381750 130.54.208.193:52918 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:464
***AP*** Seq: 0x3AC1973 Ack: 0x265E19 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-21:44:04.823361 130.54.208.193:52918 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:249
***AP*** Seq: 0x3AC1AB2 Ack: 0x265EEA Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-21:44:32.430549 130.54.208.193:52918 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:394
***AP*** Seq: 0x3AC1D38 Ack: 0x26604C Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/01-21:44:58.927073 130.54.208.193:52918 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:272
***AP*** Seq: 0x3AC2640 Ack: 0x266134 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:1113:5] WEB-MISC http directory traversal [**]
[Classification: Attempted Information Leak] [Priority: 2]
05/01-21:56:17.007699 130.54.208.193:1793 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:8303
***AP*** Seq: 0xAA0677C1 Ack: 0x32A69827 Win: 0x3E6E TcpLen: 20
[Xref => http://www.whitehats.com/info/IDS297]
[**] [1:1113:5] WEB-MISC http directory traversal [**]
[Classification: Attempted Information Leak] [Priority: 2]
05/01-21:56:20.248323 130.54.208.193:1792 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:6826
***AP*** Seq: 0x32A9AF59 Ack: 0x7181F7AA Win: 0x643E TcpLen: 20
[Xref => http://www.whitehats.com/info/IDS297]
[**] [1:2570:7] WEB-MISC Invalid HTTP Version String [**]
[Classification: Detection of a non-standard protocol or event] [Priority: 2]
05/01-21:59:52.185900 130.54.208.193:1794 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:4743
***AP*** Seq: 0x85159344 Ack: 0x3F35A8C2 Win: 0x3E14 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=11593][Xref => http://www.securityfocus.com/bid/9809]
[**] [1:1113:5] WEB-MISC http directory traversal [**]
[Classification: Attempted Information Leak] [Priority: 2]
05/01-22:04:15.869397 130.54.208.193:1804 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:6840
***AP*** Seq: 0x596387C9 Ack: 0x503706B3 Win: 0x4188 TcpLen: 20
[Xref => http://www.whitehats.com/info/IDS297]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-09:13:20.026781 130.54.208.193:59494 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:245
***AP*** Seq: 0x1FD49907 Ack: 0x2090AB44 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-09:13:22.277070 130.54.208.193:59494 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:237
***AP*** Seq: 0x1FD54A0C Ack: 0x2090AC09 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-09:13:22.532807 130.54.208.193:59494 -> 192.168.24.11:143
TCP TTL:47 TOS:0x0 ID:50823 IpLen:20 DgmLen:261 DF
***AP*** Seq: 0x2090AC26 Ack: 0x1FD5771A Win: 0x5372 TcpLen: 32
TCP Options (3) => NOP NOP TS: 86511533 206651318
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-09:13:42.385354 130.54.208.193:59494 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:240
***AP*** Seq: 0x1FD62E38 Ack: 0x2090ADE2 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-09:13:43.055932 130.54.208.193:59494 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:336
***AP*** Seq: 0x1FD63D00 Ack: 0x2090AF0A Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-09:13:46.975075 130.54.208.193:59494 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:275
***AP*** Seq: 0x1FD656AA Ack: 0x2090AFF5 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-09:13:54.544813 130.54.208.193:59494 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:443
***AP*** Seq: 0x1FD6677D Ack: 0x2090B188 Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-09:16:22.440612 130.54.208.193:59494 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:377
***AP*** Seq: 0x1FD6B4DE Ack: 0x2090B445 Win: 0x29E0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-09:16:23.892147 130.54.208.193:59494 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:432
***AP*** Seq: 0x1FD6B869 Ack: 0x2090B5CD Win: 0x2E10 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-12:33:00.261680 130.54.208.193:33612 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:438
***AP*** Seq: 0x1934A495 Ack: 0x4AEC1655 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-14:53:17.377822 130.54.208.193:33615 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1139
***AP*** Seq: 0x295A60A1 Ack: 0x40CB6DAA Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-17:28:12.462900 130.54.208.193:48397 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:337
***AP*** Seq: 0x752F4C21 Ack: 0x78610261 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-17:28:13.540961 130.54.208.193:48397 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:460
***AP*** Seq: 0x752F4E8B Ack: 0x78610405 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-17:28:47.370124 130.54.208.193:48397 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:897
***AP*** Seq: 0x752F67D4 Ack: 0x7861075E Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-17:29:02.460683 130.54.208.193:48397 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:280
***AP*** Seq: 0x752F89E9 Ack: 0x7861084E Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-17:29:02.460683 130.54.208.193:48397 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:280
***AP*** Seq: 0x752F89E9 Ack: 0x7861084E Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-17:29:05.182517 130.54.208.193:48397 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:543
***AP*** Seq: 0x752F9F0B Ack: 0x78610A45 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-17:29:05.182517 130.54.208.193:48397 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:543
***AP*** Seq: 0x752F9F0B Ack: 0x78610A45 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-20:24:29.722939 130.54.208.193:33748 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:329
***AP*** Seq: 0xB928ABE Ack: 0xF24E89A7 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/02-20:24:31.853030 130.54.208.193:33748 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:318
***AP*** Seq: 0xB929973 Ack: 0xF24E8ABD Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:21:03.694006 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:253
***AP*** Seq: 0x6B70AA0 Ack: 0x102B21A2 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:21:04.139327 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:263
***AP*** Seq: 0x6B70BE4 Ack: 0x102B2281 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:21:05.207531 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:460
***AP*** Seq: 0x6B70E4F Ack: 0x102B2425 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:21:32.477065 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:906
***AP*** Seq: 0x6B722E9 Ack: 0x102B2787 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:25:31.851735 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:286
***AP*** Seq: 0x6B7BB39 Ack: 0x102B28E8 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:25:35.845139 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:267
***AP*** Seq: 0x6B7E2C0 Ack: 0x102B29CB Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:25:36.680876 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:336
***AP*** Seq: 0x6B80261 Ack: 0x102B2AF3 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:25:54.900403 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:275
***AP*** Seq: 0x6B821C4 Ack: 0x102B2BDE Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:26:05.010734 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:260
***AP*** Seq: 0x6B83A7F Ack: 0x102B2CBA Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:26:27.849787 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:270
***AP*** Seq: 0x6B86B1A Ack: 0x102B2DA0 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:26:38.480492 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:443
***AP*** Seq: 0x6B87A56 Ack: 0x102B2F33 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-13:26:43.389773 130.54.208.193:57895 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:383
***AP*** Seq: 0x6B8AE96 Ack: 0x102B308A Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-15:56:14.810391 130.54.208.193:33060 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:331
***AP*** Seq: 0x5019426A Ack: 0x5ACDAA9D Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-15:56:16.081058 130.54.208.193:33060 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:533
***AP*** Seq: 0x50194546 Ack: 0x5ACDAC8A Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-15:56:44.011867 130.54.208.193:33060 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:646
***AP*** Seq: 0x50194A4D Ack: 0x5ACDAEE8 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-15:56:46.961794 130.54.208.193:33060 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:560
***AP*** Seq: 0x50195F31 Ack: 0x5ACDB0F0 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-15:56:46.961794 130.54.208.193:33060 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:560
***AP*** Seq: 0x50195F31 Ack: 0x5ACDB0F0 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-15:56:51.621640 130.54.208.193:33060 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:293
***AP*** Seq: 0x50198996 Ack: 0x5ACDB316 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-15:57:10.552397 130.54.208.193:33060 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:320
***AP*** Seq: 0x5019AA91 Ack: 0x5ACDB42E Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/03-15:57:12.352042 130.54.208.193:33060 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:477
***AP*** Seq: 0x5019AF18 Ack: 0x5ACDB5E3 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:18:22.302458 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:290
***AP*** Seq: 0x15F497E5 Ack: 0x2FC93052 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:18:31.254333 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:185
***AP*** Seq: 0x15F511CD Ack: 0x2FC930E3 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:18:31.933823 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:204
***AP*** Seq: 0x15F5E2F0 Ack: 0x2FC93187 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:18:32.672821 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:245
***AP*** Seq: 0x15F6CD1D Ack: 0x2FC93254 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:18:33.312538 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:204
***AP*** Seq: 0x15F74E0A Ack: 0x2FC932F8 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:18:34.413062 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:269
***AP*** Seq: 0x15F774ED Ack: 0x2FC933DD Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:18:35.681173 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:47 TOS:0x0 ID:46718 IpLen:20 DgmLen:266 DF
***AP*** Seq: 0x2FC93431 Ack: 0x15F7A3A2 Win: 0x3E96 TcpLen: 32
TCP Options (3) => NOP NOP TS: 364085681 234403329
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:18:43.231836 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:470
***AP*** Seq: 0x15F903A6 Ack: 0x2FC9376A Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:18:56.651566 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:411
***AP*** Seq: 0x15F9398A Ack: 0x2FC938DD Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:19:00.826176 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:189
***AP*** Seq: 0x15F9479F Ack: 0x2FC93972 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:19:04.901243 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:340
***AP*** Seq: 0x15F989E2 Ack: 0x2FC93C85 Win: 0x29E0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:19:09.231987 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:204
***AP*** Seq: 0x15F9F977 Ack: 0x2FC93E67 Win: 0x29E0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-14:19:09.744141 130.54.208.193:45447 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:203
***AP*** Seq: 0x15FA2DD3 Ack: 0x2FC93F0A Win: 0x29E0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:09.795980 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:192
***AP*** Seq: 0x6084F3F5 Ack: 0x7B565156 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:10.930531 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:462
***AP*** Seq: 0x6084F669 Ack: 0x7B5652FC Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:11.282052 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:183
***AP*** Seq: 0x6084F739 Ack: 0x7B56538B Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:11.896520 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:251
***AP*** Seq: 0x6084F86C Ack: 0x7B56545E Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:12.329663 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:249
***AP*** Seq: 0x6084F9AB Ack: 0x7B56552F Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:15.556971 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:183
***AP*** Seq: 0x6084FBF7 Ack: 0x7B5655BE Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:15.926899 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:328
***AP*** Seq: 0x6084FE1B Ack: 0x7B5656DE Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:18.787351 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:243
***AP*** Seq: 0x60851067 Ack: 0x7B5657A9 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:18.787351 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:243
***AP*** Seq: 0x60851067 Ack: 0x7B5657A9 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:19.957157 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:333
***AP*** Seq: 0x608515A8 Ack: 0x7B5658CE Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-16:40:19.957157 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:333
***AP*** Seq: 0x608515A8 Ack: 0x7B5658CE Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-17:04:28.589276 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:403
***AP*** Seq: 0x60852FD4 Ack: 0x7B565B3F Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-17:04:29.641855 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:462
***AP*** Seq: 0x6085328D Ack: 0x7B565CE5 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-17:04:30.193246 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:322
***AP*** Seq: 0x60853427 Ack: 0x7B565DFF Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-17:04:30.843611 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:258
***AP*** Seq: 0x60853563 Ack: 0x7B565ED9 Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/05-17:04:30.908007 130.54.208.193:42378 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:166
***AP*** Seq: 0x7B565ED9 Ack: 0x608535CF Win: 0x2ABB TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:04:47.983775 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:471
***AP*** Seq: 0xDAF273CC Ack: 0x4A43A29 Win: 0x16A0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:10:23.016169 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:245
***AP*** Seq: 0xDAF501F7 Ack: 0x4A441C4 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:10:23.847485 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:245
***AP*** Seq: 0xDAF5D9B1 Ack: 0x4A44291 Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:10:24.936031 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:245
***AP*** Seq: 0xDAF735B4 Ack: 0x4A4435E Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:10:25.695263 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:263
***AP*** Seq: 0xDAF7E703 Ack: 0x4A4443D Win: 0x1920 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:10:27.612419 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:47 TOS:0x0 ID:29483 IpLen:20 DgmLen:266 DF
***AP*** Seq: 0x4A444BB Ack: 0xDAF81784 Win: 0x3E96 TcpLen: 32
TCP Options (3) => NOP NOP TS: 525633079 250554938
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:10:30.931076 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:255
***AP*** Seq: 0xDAF89CF9 Ack: 0x4A4466A Win: 0x1D50 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:10:34.296651 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:357
***AP*** Seq: 0xDAF92EA3 Ack: 0x4A447A7 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:10:40.925660 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:253
***AP*** Seq: 0xDAF95171 Ack: 0x4A4487C Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:10:47.065685 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:260
***AP*** Seq: 0xDAF975DD Ack: 0x4A44958 Win: 0x2180 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:10:56.370908 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:438
***AP*** Seq: 0xDAF99614 Ack: 0x4A44AE6 Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:11:00.275005 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:347
***AP*** Seq: 0xDAF9D042 Ack: 0x4A44C19 Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:11:00.905877 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:245
***AP*** Seq: 0xDAFA45AC Ack: 0x4A44CE6 Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:11:01.664485 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:183
***AP*** Seq: 0x4A44D60 Ack: 0xDAFA5F94 Win: 0x3E96 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3072:1] IMAP status overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:40:59.607964 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1502
***AP*** Seq: 0xDAFA9A37 Ack: 0x4A45566 Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
05/07-11:40:59.607964 130.54.208.193:53323 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1502
***AP*** Seq: 0xDAFA9A37 Ack: 0x4A45566 Win: 0x25B0 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
Go to: previous range, next range, all alerts, overview page
SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Sep 14 05:05:21 2010