[Silicon Defense logo]

SnortSnarf alert page

Source: 71.13.115.117

SnortSnarf v021111.1

Signature section (16810)Top 20 source IPsTop 20 dest IPs

5 such alerts found using input module SnortFileInput, with sources:
Earliest: 11:50:53.882670 on 12/22/2009
Latest: 00:48:31.220351 on 02/03/2010

1 different signatures are present for 71.13.115.117 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

71.13.115.117 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
12/22-11:50:53.882670 71.13.115.117:56707 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:171
***AP*** Seq: 0x3655652C Ack: 0x76446886 Win: 0x5B4 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
12/23-03:36:26.615190 71.13.115.117:16746 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:171
***AP*** Seq: 0x50AC3C22 Ack: 0x6946BD59 Win: 0x5B4 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
12/27-05:31:10.915799 71.13.115.117:46132 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:171
***AP*** Seq: 0xC51B2BBD Ack: 0x117DE7EE Win: 0x5B4 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
01/04-19:08:28.602079 71.13.115.117:33059 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:171
***AP*** Seq: 0xE13F5D35 Ack: 0xFA973B7 Win: 0x5B4 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
02/03-00:48:31.220351 71.13.115.117:31695 -> 192.168.24.11:80
TCP TTL:240 TOS:0x10 ID:0 IpLen:20 DgmLen:171
***AP*** Seq: 0xD5D038F9 Ack: 0x14725523 Win: 0x5B4 TcpLen: 20
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Sep 14 05:05:18 2010