Table 124: Deep Inspection Alarm Log Entries
Versions
Severity
Attack Description
Attack Name
sos5.1.0
high
This signature detects buffer overflow attempts against the
cURL file retrieval client. cURL 6.1 to 7.4 versions are
vulnerable. Attackers may use a malicious server to connect
to the cURL client and execute arbitrary code with the
permissions of the cURL user.
APP:CURL-OF-BANNER
sos5.1.0
info
This signature detects messages sent from AIM clients to
other AIM clients.
CHAT:AIM:MESSAGE-SEND
sos5.1.0
info
This protocol anomaly is a AIM message with an invalid TLV;
the TLV data specified in the FLAP header is less than the
actual data in the TLV header.
CHAT:AUDIT:AIM:INVALID-TLV
sos5.1.0
info
This protocol anomaly is a AIM message with an invalid TLV;
the TLV length is less than expected, or the TLV length is
greater than the data specified in the FLAP header.
CHAT:AUDIT:AIM:INV-TLV-LEN
sos5.1.0
info
This protocol anomaly is an MSN message with a group
name length that exceeds the user-defined maximum. The
default group name maximum is 64.
CHAT:AUDIT:MSN:GROUP-NAME
sos5.1.0
info
This signature detects a Yahoo Messenger client sending a
file to another user.
CHAT:AUDIT:YMSG:FILE-SEND
sos5.1.0
info
This protocol anomaly is a Yahoo! Messenger e-mail address
that exceeds the user-defined maximum. A Yahoo!
Messenger server sends an e-mail address as part of a new
e-mail alert message. The default number of bytes in an
Yahoo! Messenger e-mail address is 84.
CHAT:AUDIT:YMSG:MAIL-ADDR
sos5.1.0
info
This protocol anomaly is a Yahoo! Messenger message that
exceeds the user-defined maximum. The default number of
bytes in an Yahoo! Messenger message is 8192.
CHAT:AUDIT:YMSG:MSG-TOO-BIG
sos5.1.0
info
This protocol anomaly is a Yahoo! Messenger group name
that exceeds the user-defined maximum. Yahoo! Messenger
clients use groups to separate their friends into categories.
The default number of bytes in an Yahoo! Messenger group
name is 84.
CHAT:AUDIT:YMSG:OFLOW-GRP-NAME
sos5.1.0
info
This protocol anomaly is a Yahoo! Messenger encrypted
password that exceeds the user-defined maximum. The
Yahoo! Messenger client sends an encrypted password to
the server as part of the authentication process. The default
number of bytes in an Yahoo! Messenger encrypted
password is 1024.
CHAT:AUDIT:YMSG:OFLOW-PASSWD
sos5.1.0
info
This signature detects MSN Messenger chat using the
specified content type "text/plain" on port 1863 (default
port of MSN Messenger).
CHAT:MSN:ACCESS
865
Copyright © 2010, Juniper Networks, Inc.
Appendix E: Log Entries
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...