[Silicon Defense logo]

SnortSnarf alert page

Source: 66.249.65.211

SnortSnarf v021111.1

Signature section (16810)Top 20 source IPsTop 20 dest IPs

5 such alerts found using input module SnortFileInput, with sources:
Earliest: 20:54:52.349935 on 04/20/2010
Latest: 03:52:28.007730 on 04/25/2010

1 different signatures are present for 66.249.65.211 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

66.249.65.211 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/20-20:54:52.349935 66.249.65.211:54176 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:288
***AP*** Seq: 0x3DB5BC6D Ack: 0xFE3E0BF7 Win: 0x1658 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/22-05:40:23.269523 66.249.65.211:49718 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1197
***AP*** Seq: 0xF12A7316 Ack: 0x3D3472BF Win: 0x25B0 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/22-15:15:57.937361 66.249.65.211:34887 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:792
***AP*** Seq: 0x6A55E83A Ack: 0xBA24B6AE Win: 0x2180 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/23-15:37:42.541425 66.249.65.211:39453 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1334
***AP*** Seq: 0xF1C75B9F Ack: 0x49D1F1F0 Win: 0x29E0 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/25-03:52:28.007730 66.249.65.211:33140 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:1201
***AP*** Seq: 0x5F8C62B2 Ack: 0xFAE38115 Win: 0x1658 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Sep 14 05:05:32 2010