<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS &amp; Dictionary Attacks / Multiple Failed Logon Attempts in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990758#M79400</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you, i was looking for an answer to this for a while!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Jul 2008 16:05:21 GMT</pubDate>
    <dc:creator>zvadim</dc:creator>
    <dc:date>2008-07-25T16:05:21Z</dc:date>
    <item>
      <title>IPS &amp; Dictionary Attacks / Multiple Failed Logon Attempts</title>
      <link>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990753#M79395</link>
      <description>&lt;P&gt;Could anyone enlighten me on answering this question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could an ASA 5520(IPS) stop a dictionary attack from happening and could it pickup alerts for multiple failed logon attempts inside the network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be great.  Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990753#M79395</guid>
      <dc:creator>GoldleafIT</dc:creator>
      <dc:date>2019-03-10T11:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPS &amp; Dictionary Attacks / Multiple Failed Logon Attempts</title>
      <link>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990754#M79396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Probably, but it depends entirely on which protocol you're talking about. I have attached a snapshot of signatures containing "authorization failure" in the name.  there may be others. You should be able to use these (or a variant) to do what you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jul 2008 16:00:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990754#M79396</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2008-07-17T16:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPS &amp; Dictionary Attacks / Multiple Failed Logon Attempts</title>
      <link>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990755#M79397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mhellman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the contents of your attachment?  I am not going to open a file on a blog.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 11:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990755#M79397</guid>
      <dc:creator>GoldleafIT</dc:creator>
      <dc:date>2008-07-18T11:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPS &amp; Dictionary Attacks / Multiple Failed Logon Attempts</title>
      <link>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990756#M79398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a jpeg image file.  Sorry, no...I'm not going to transcribe the text in the image. FWIW, your browser automatically fetches and open hundreds, probably thousands, of remote images every day as you use the web.  The risk is exactly the same.  The ONLY different is that you don't have to think about it;-)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 12:11:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990756#M79398</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2008-07-18T12:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPS &amp; Dictionary Attacks / Multiple Failed Logon Attempts</title>
      <link>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990757#M79399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your feedback.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 16:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990757#M79399</guid>
      <dc:creator>GoldleafIT</dc:creator>
      <dc:date>2008-07-18T16:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPS &amp; Dictionary Attacks / Multiple Failed Logon Attempts</title>
      <link>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990758#M79400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you, i was looking for an answer to this for a while!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2008 16:05:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-dictionary-attacks-multiple-failed-logon-attempts/m-p/990758#M79400</guid>
      <dc:creator>zvadim</dc:creator>
      <dc:date>2008-07-25T16:05:21Z</dc:date>
    </item>
  </channel>
</rss>

