[Silicon Defense logo]

SnortSnarf alert page

Source: 131.112.174.57

SnortSnarf v021111.1

Signature section (16810)Top 20 source IPsTop 20 dest IPs

6 such alerts found using input module SnortFileInput, with sources:
Earliest: 16:18:42.919989 on 11/01/2009
Latest: 13:27:40.336826 on 07/18/2010

5 different signatures are present for 131.112.174.57 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

131.112.174.57 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
11/01-16:18:42.919989 131.112.174.57:2398 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:3226
***AP*** Seq: 0x8A954BCA Ack: 0x17061980 Win: 0xFFFF TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [119:16:1] (http_inspect) OVERSIZE CHUNK ENCODING [**]
12/22-14:33:24.285267 131.112.174.57:3610 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:841
***AP*** Seq: 0x62B3FC20 Ack: 0xDC771322 Win: 0xFFFF TcpLen: 20
[**] [119:4:1] (http_inspect) BARE BYTE UNICODE ENCODING [**]
02/19-00:15:48.725616 131.112.174.57:3224 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:795
***AP*** Seq: 0x8CD9015F Ack: 0xBA167DD2 Win: 0xFFFF TcpLen: 20
[**] [1:1112:6] WEB-MISC http directory traversal [**]
[Classification: Attempted Information Leak] [Priority: 2]
05/24-15:36:33.260399 131.112.174.57:1595 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:4317
***AP*** Seq: 0x68D3A00F Ack: 0xCE2CE15F Win: 0x3C12 TcpLen: 20
[Xref => http://www.whitehats.com/info/IDS298]
[**] [1:3070:1] IMAP fetch overflow attempt [**]
[Classification: Misc Attack] [Priority: 2]
07/18-12:11:22.289799 131.112.174.57:1080 -> 192.168.24.11:143
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:2612
***AP*** Seq: 0x695F570D Ack: 0x6D6489EA Win: 0xFFFF TcpLen: 20
[Xref => http://www.securityfocus.com/bid/11775]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
07/18-13:27:40.336826 131.112.174.57:1346 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:2439
***AP*** Seq: 0x6406EE94 Ack: 0x50B5DC3D Win: 0xFFFF TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Sep 14 05:05:26 2010