sos5.0.0,
sos5.1.0
critical
This signature detects buffer overflow attempts to exploit
a vulnerability in the Qpopper daemon. Some 3.0 beta
versions are vulnerable.
POP3:OVERFLOW:QPOP-OF3
sos5.0.0,
sos5.1.0
critical
This signature detects a buffer overflow attempt to exploit
a vulnerability in Qpopper using custom shellcode. Version
3.0beta20 and many earlier versions are vulnerable.
POP3:OVERFLOW:QPOP-OF4
sos5.1.0
high
This protocol anomaly is a message data line that exceeds
the defined maximum length (sc_mime_textline_length).
POP3:OVERFLOW:TXTLINE_2LONG
sos5.0.0,
sos5.1.0
high
This protocol anomaly is a POP3 USER command argument
that is too long. This may indicate a buffer overflow attempt.
POP3:OVERFLOW:USER
sos5.0.0,
sos5.1.0
high
This protocol anomaly is a POP3 message number that is
unreasonably high. This may indicate a huge mailbox or an
exploit attempt.
POP3:REQERR:REQ-MESSAGE-NUMBER
sos5.0.0,
sos5.1.0
medium
This protocol anomaly is an unparsed POP command line
or header line. This may indicate a nonstandard e-mail client
or server or a backdoor/exploit attempt.
POP3:REQERR:REQ-SYNTAX-ERROR
sos5.1.0
low
This signature detects the scanner tool amap, made by the
Hacker's Choice. THC-AMAP is used in initial reconnaissance
for an attacker to determine services running on target hosts
before launching other attacks.
SCAN:AMAP:FTP-ON-HTTP
sos5.1.0
low
This signature detects the scanner tool AMAP, made by The
Hacker's Choice (THC). Attackers may use THC-AMAP during
their initial reconnaissance to determine services running on
target hosts before launching other attacks.
SCAN:AMAP:SAP-R3-ON-HTTP
sos5.1.0
low
This signature detects the scanner tool AMAP, made by The
Hacker's Choice (THC). Attackers may use THC-AMAP during
their initial reconnaissance to determine services running on
target hosts before launching other attacks.
SCAN:AMAP:SSL-ON-HTTP
sos5.1.0
low
This signature detects the scanner tool AMAP, made by The
Hacker's Choice (THC). Attackers may use THC-AMAP during
their initial reconnaissance to determine services running on
target hosts before launching other attacks.
SCAN:AMAP:SSL-ON-POP3
sos5.1.0
high
This signature detects traffic generated by the open-source
exploiting tool Metasploit Framework. Other signatures may
also trip. This indicates that someone is using this tool on
your network. Follow-up investigation of source or target
machines may be required.
SCAN:METASPLOIT:SMB-ACTIVE
sos5.0.0
sos5.1.0
medium
"This signature detects denial-of-service (DoS) attacks
against Microsoft IIS 4.0 and 5.0. Attackers may send
maliciously crafted HTR requests (.htr) with long variable
names to overflow the buffer in the ism.dll ISAPI extension
that implements HTR scripting and create a denial of service
or execute arbitrary commands.
SCAN:MISC:HTTP:HTR-OVERFLOW
913
Copyright © 2010, Juniper Networks, Inc.
Appendix E: Log Entries
Summary of Contents for NETWORK AND SECURITY MANAGER 2010.3
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Page 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Page 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Page 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Page 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Page 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Page 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Page 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Page 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Page 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Page 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Page 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Page 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Page 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Page 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Page 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Page 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Page 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Page 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Page 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Page 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Page 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Page 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Page 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Page 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...