[Silicon Defense logo]

SnortSnarf alert page

Source: 202.93.76.90

SnortSnarf v021111.1

Signature section (16810)Top 20 source IPsTop 20 dest IPs

5 such alerts found using input module SnortFileInput, with sources:
Earliest: 11:46:24.906059 on 12/15/2009
Latest: 19:52:28.138868 on 07/31/2010

1 different signatures are present for 202.93.76.90 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

202.93.76.90 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
12/15-11:46:24.906059 202.93.76.90:27629 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:185
***AP*** Seq: 0xC4955174 Ack: 0xB4D2D04D Win: 0x81F0 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
01/12-18:06:44.137623 202.93.76.90:39746 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:185
***AP*** Seq: 0x4B998D35 Ack: 0x14AF04B9 Win: 0x81F0 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
05/28-00:15:29.345125 202.93.76.90:25396 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:238
***AP*** Seq: 0x2BAFA047 Ack: 0xAEA5E79D Win: 0x81F0 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
06/25-00:46:36.165973 202.93.76.90:46755 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:238
***AP*** Seq: 0xB15BFE5B Ack: 0xFFBC1EED Win: 0x81F0 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
07/31-19:52:28.138868 202.93.76.90:36084 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:238
***AP*** Seq: 0xBAD94478 Ack: 0x215869FC Win: 0x81F0 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Sep 14 05:05:20 2010