[Silicon Defense logo]

SnortSnarf alert page

Source: 210.128.52.4

SnortSnarf v021111.1

Signature section (16810)Top 20 source IPsTop 20 dest IPs

4 such alerts found using input module SnortFileInput, with sources:
Earliest: 13:37:10.364132 on 09/28/2009
Latest: 02:20:50.660226 on 02/22/2010

1 different signatures are present for 210.128.52.4 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

210.128.52.4 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:2570:7] WEB-MISC Invalid HTTP Version String [**]
[Classification: Detection of a non-standard protocol or event] [Priority: 2]
09/28-13:37:10.364132 210.128.52.4:17598 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:504
***AP*** Seq: 0x75D6F322 Ack: 0xDF54BC56 Win: 0x3624 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=11593][Xref => http://www.securityfocus.com/bid/9809]
[**] [1:2570:7] WEB-MISC Invalid HTTP Version String [**]
[Classification: Detection of a non-standard protocol or event] [Priority: 2]
02/21-11:56:34.870122 210.128.52.4:55088 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:805
***AP*** Seq: 0xA37794BA Ack: 0x8C379C42 Win: 0x7C86 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=11593][Xref => http://www.securityfocus.com/bid/9809]
[**] [1:2570:7] WEB-MISC Invalid HTTP Version String [**]
[Classification: Detection of a non-standard protocol or event] [Priority: 2]
02/21-11:56:35.010152 210.128.52.4:55104 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:593
***AP*** Seq: 0xA33CF819 Ack: 0x8C268BE8 Win: 0x16D0 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=11593][Xref => http://www.securityfocus.com/bid/9809]
[**] [1:2570:7] WEB-MISC Invalid HTTP Version String [**]
[Classification: Detection of a non-standard protocol or event] [Priority: 2]
02/22-02:20:50.660226 210.128.52.4:25158 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:588
***AP*** Seq: 0x6204360F Ack: 0x4CB0ABAE Win: 0x16D0 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=11593][Xref => http://www.securityfocus.com/bid/9809]

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Sep 14 05:05:20 2010