[Silicon Defense logo]

SnortSnarf start page

All Snort signatures

SnortSnarf v021111.1

Signature section (16810)Top 20 source IPsTop 20 dest IPs

16810 alerts found using input module SnortFileInput, with sources: Earliest alert at 05:22:46.109645 on 09/14/2009
Latest alert at 03:01:30.602679 on 09/14/2010

PrioritySignature (click for sig info)# Alerts# Sources# DestsDetail link
N/A(http_inspect) DOUBLE DECODING ATTACK411Summary
N/A(snort_decoder) WARNING: TCP Data Offset is less than 5!1351Summary
N/A(http_inspect) OVERSIZE REQUEST-URI DIRECTORY50161Summary
N/A(http_inspect) OVERSIZE CHUNK ENCODING57361Summary
N/A(http_inspect) IIS UNICODE CODEPOINT ENCODING34761Summary
N/A(http_inspect) BARE BYTE UNICODE ENCODING432511Summary
3ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited [sid]331Summary
3ICMP Destination Unreachable Communication Administratively Prohibited [sid]42121Summary
2WEB-MISC long basic authorization string [sid] [BUGTRAQ]111Summary
2SNMP private access udp [sid] [BUGTRAQ]211Summary
2SNMP public access udp [sid] [BUGTRAQ]211Summary
2WEB-MISC WebDAV search access [sid] [arachNIDS]221Summary
2WEB-MISC /etc/passwd [sid]331Summary
2ATTACK-RESPONSES 403 Forbidden [sid]311Summary
2SNMP request udp [sid] [BUGTRAQ]421Summary
2IMAP authenticate overflow attempt [sid] [CVE]531Summary
2WEB-FRONTPAGE /_vti_bin/ access [cgi.nessus.org] [sid]651Summary
2ATTACK-RESPONSES id check returned root [sid]822Summary
2WEB-MISC apache directory disclosure attempt [sid] [BUGTRAQ]971Summary
2WEB-PHP test.php access [cgi.nessus.org] [sid]1311Summary
2WEB-MISC http directory traversal [sid] [arachNIDS]38181Summary
2WEB-IIS view source via translate header [sid] [arachNIDS]85741Summary
2WEB-MISC Invalid HTTP Version String [sid] [BUGTRAQ]144541Summary
2IMAP status overflow attempt [sid] [BUGTRAQ]25671Summary
2IMAP fetch overflow attempt [sid] [BUGTRAQ]470111Summary
2WEB-MISC robots.txt access [cgi.nessus.org] [sid]147716511Summary
1WEB-MISC Cisco IOS HTTP configuration attempt [sid] [BUGTRAQ]111Summary
1MS-SQL probe response overflow attempt [sid] [BUGTRAQ]431Summary
1WEB-MISC cross site scripting attempt [sid]411Summary
1WEB-PHP remote include path [sid]531Summary
1WEB-MISC Chunked-Encoding transfer attempt [sid] [BUGTRAQ]931Summary
1NETBIOS SMB trans2open buffer overflow attempt [sid] [BUGTRAQ]1741Summary

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Sep 14 05:05:16 2010