sos5.1.0
info
This protocol anomaly is a Gnutella message with a search
criteria field that does not end with a NULL character.
P2P:AUDIT:GNUTELLA-SEARCH
sos5.1.0
info
This protocol anomaly is a Gnutella server response that
does not use the expected syntax. Correct syntax for Gnutella
0.4 is: GNUTELLA OK<CR><LF>; correct syntax for Gnutella
0.6 is: GNUTELLA/0.6 200 OK<CR><LF>.
P2P:AUDIT:GNUTELLA-SVR-RESP
sos5.1.0
info
This protocol anomaly is a Gnutella message with a TTL
that exceeds the user-defined maximum. The default TTL
is 8. The Gnutella RFC recommends an 8 to 10 TTL maximum
for Gnutella messages.
P2P:AUDIT:GNUTELLA-TTL
sos5.1.0
info
This protocol anomaly is a Gnutella message with a connect
string that does not conform to Gnutella RFC or the
requesting Gnutella version is not 0.4 or 0.6.
P2P:AUDIT:GNUTELLA-UNSUP-VER
sos5.1.0
info
This signature detects requests to a BitTorrent tracker
website. Users may be querying the tracker to look for files
to download.
P2P:BITTORRENT:TRACKER-QUERY
sos5.1.0
info
This signature detects 'scrape' requests to a BitTorrent
tracker website. Users may be querying the tracker to look
for files to download.
P2P:BITTORRENT:TRACKER-SCRAPE
sos5.1.0
info
This signature detects use of the Direct Connect Plus Plus
(DC++) file sharing client.
P2P:DC:DC-PP-ACTIVE
sos5.1.0
info
This signature detects version checks by eDonkey 2000, a
peer-to-peer file sharing client. The eDonkey client
occasionally checks its own version number to ensure that
the client is current.
P2P:EDONKEY:CLIENT-VER-CHECK
sos5.1.0
info
This signature detects Gnutella client connection requests.
Because Gnutella does not use a fixed port number, this
signature searches TCP connections to port 1024 and higher
by default.
P2P:GNUTELLA:CONNECT
sos5.1.0
info
This signature detects GNUTella server responses to a
connection request. Because GNUTella does not use a fixed
port number, this signature searches TCP connections to
port 1024 and higher by default.
P2P:GNUTELLA:CONNECTION-OK
sos5.1.0
info
This signature detects Gnutella server responses to a
connection request. Because Gnutella does not use a fixed
port number, this signature searches TCP connections to
port 1024 and higher by default.
P2P:GNUTELLA:CONNECTION-OK-V06
sos5.1.0
info
This signature detects activity by the peer-to-peer (P2P) file
sharing client MLDonkey, a multi-protocol P2P file sharing
application.
P2P:MLDONKEY:CLIENT-ACTIVE
sos5.1.0
info
This signature detects a Skype client request (to a central
server) that checks for the latest version of the client
software.
P2P:SKYPE:VERSION-CHECK
915
Copyright © 2010, Juniper Networks, Inc.
Appendix E: Log Entries
Summary of Contents for NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Page 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Page 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Page 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Page 236: ...Copyright 2010 Juniper Networks Inc 186 Network and Security Manager Administration Guide...
Page 292: ...Copyright 2010 Juniper Networks Inc 242 Network and Security Manager Administration Guide...
Page 314: ...Copyright 2010 Juniper Networks Inc 264 Network and Security Manager Administration Guide...
Page 368: ...Copyright 2010 Juniper Networks Inc 318 Network and Security Manager Administration Guide...
Page 370: ...Copyright 2010 Juniper Networks Inc 320 Network and Security Manager Administration Guide...
Page 484: ...Copyright 2010 Juniper Networks Inc 434 Network and Security Manager Administration Guide...
Page 584: ...Copyright 2010 Juniper Networks Inc 534 Network and Security Manager Administration Guide...
Page 588: ...Copyright 2010 Juniper Networks Inc 538 Network and Security Manager Administration Guide...
Page 600: ...Copyright 2010 Juniper Networks Inc 550 Network and Security Manager Administration Guide...
Page 678: ...Copyright 2010 Juniper Networks Inc 628 Network and Security Manager Administration Guide...
Page 694: ...Copyright 2010 Juniper Networks Inc 644 Network and Security Manager Administration Guide...
Page 700: ...Copyright 2010 Juniper Networks Inc 650 Network and Security Manager Administration Guide...
Page 706: ...Copyright 2010 Juniper Networks Inc 656 Network and Security Manager Administration Guide...
Page 708: ...Copyright 2010 Juniper Networks Inc 658 Network and Security Manager Administration Guide...
Page 758: ...Copyright 2010 Juniper Networks Inc 708 Network and Security Manager Administration Guide...
Page 788: ...Copyright 2010 Juniper Networks Inc 738 Network and Security Manager Administration Guide...
Page 882: ...Copyright 2010 Juniper Networks Inc 832 Network and Security Manager Administration Guide...
Page 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Page 918: ...Copyright 2010 Juniper Networks Inc 868 Network and Security Manager Administration Guide...
Page 920: ...Copyright 2010 Juniper Networks Inc 870 Network and Security Manager Administration Guide...
Page 1005: ...PART 6 Index Index on page 957 955 Copyright 2010 Juniper Networks Inc...
Page 1006: ...Copyright 2010 Juniper Networks Inc 956 Network and Security Manager Administration Guide...