<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tcp Hijack Attack on ips in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-hijack-attack-on-ips/m-p/1780091#M56299</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Hi Guys,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;our cisco ips is under tcp hijack attack the signature id is 3250 ..numbers of servers are targeted by this attack can any body tell me the proper metigation of this attack...&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sher&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:28:20 GMT</pubDate>
    <dc:creator>szamin125</dc:creator>
    <dc:date>2019-03-10T12:28:20Z</dc:date>
    <item>
      <title>Tcp Hijack Attack on ips</title>
      <link>https://community.cisco.com/t5/network-security/tcp-hijack-attack-on-ips/m-p/1780091#M56299</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi Guys,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;our cisco ips is under tcp hijack attack the signature id is 3250 ..numbers of servers are targeted by this attack can any body tell me the proper metigation of this attack...&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sher&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:28:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-hijack-attack-on-ips/m-p/1780091#M56299</guid>
      <dc:creator>szamin125</dc:creator>
      <dc:date>2019-03-10T12:28:20Z</dc:date>
    </item>
    <item>
      <title>Tcp Hijack Attack on ips</title>
      <link>https://community.cisco.com/t5/network-security/tcp-hijack-attack-on-ips/m-p/1780092#M56301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here are details of what this signature does:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=3250&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S394"&gt;http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=3250&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S394&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post a sample alert for this signature here? feel free to modify any sensitive information (like IP addresses).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Sep 2011 16:20:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-hijack-attack-on-ips/m-p/1780092#M56301</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2011-09-12T16:20:34Z</dc:date>
    </item>
    <item>
      <title>Tcp Hijack Attack on ips</title>
      <link>https://community.cisco.com/t5/network-security/tcp-hijack-attack-on-ips/m-p/1780093#M56303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Dear Mr. Prapanch,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;thanks for your Quick reply please check the logs of cisco IPS below...&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;DIV style="border-bottom: windowtext 2.25pt double; border-left: medium none; padding-bottom: 1pt; padding-left: 0cm; padding-right: 0cm; border-top: medium none; border-right: medium none; padding-top: 0cm;"&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;signature:&amp;nbsp;&amp;nbsp; description=TCP Hijack id=3250 version=S394 type=anomaly created=20010202 &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; subsigId: 0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; sigDetails: TCP Hijack &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; marsCategory: Penetrate/HijackSession &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;interfaceGroup: vs0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;vlan:&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;participants:&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; attacker:&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; addr: 111.111.111.222 (suppose this is public outside address)locality=OUT &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port: 1063 &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; target:&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; addr: 10.1.1.1(suppose this is web server) locality=OUT &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port: 80 &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; os:&amp;nbsp;&amp;nbsp; idSource=learned type=linux relevance=relevant &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;actions:&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; denyPacketRequestedNotPerformed: true &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;riskRatingValue: 100 targetValueRating=medium attackRelevanceRating=relevant &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0cm;"&gt;&lt;STRONG&gt;threatRatingValue: 100 &lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Waiting for your reply&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sher&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 07:41:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-hijack-attack-on-ips/m-p/1780093#M56303</guid>
      <dc:creator>szamin125</dc:creator>
      <dc:date>2011-09-13T07:41:47Z</dc:date>
    </item>
    <item>
      <title>Tcp Hijack Attack on ips</title>
      <link>https://community.cisco.com/t5/network-security/tcp-hijack-attack-on-ips/m-p/1780094#M56306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sher,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to get captures to figure out what's going on here. Is it only between the above 2 IP's that you see this alert?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You&amp;nbsp; can enable "produce verbose alert" also in addition to the captures and&amp;nbsp; that way you should be able to figure out which is the offending packet&amp;nbsp; in the stream.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 15:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-hijack-attack-on-ips/m-p/1780094#M56306</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2011-09-13T15:21:48Z</dc:date>
    </item>
  </channel>
</rss>

