<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tomcat Denial of Service Attack in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tomcat-denial-of-service-attack/m-p/481952#M95002</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please send me some more information and we can look into refining this signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An IPLog dmp file or a traffic capture would help me dig into the cause of the false positive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-jonathan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Nov 2005 15:51:40 GMT</pubDate>
    <dc:creator>jlimbo</dc:creator>
    <dc:date>2005-11-29T15:51:40Z</dc:date>
    <item>
      <title>Tomcat Denial of Service Attack</title>
      <link>https://community.cisco.com/t5/network-security/tomcat-denial-of-service-attack/m-p/481951#M95001</link>
      <description>&lt;P&gt;The signature id 5648 (Tomcat Denial of Service Attack) seams to be prone to false positives.... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have seen in a number of incidents, that when the destination of this attack uses the ephemeral port of 8007 with an established connection on TCP port 80, the signature is often triggered. The signature looks for the content \xfe\x0f&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is anyone else seeing this problem?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tomcat-denial-of-service-attack/m-p/481951#M95001</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2019-03-10T09:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Tomcat Denial of Service Attack</title>
      <link>https://community.cisco.com/t5/network-security/tomcat-denial-of-service-attack/m-p/481952#M95002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please send me some more information and we can look into refining this signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An IPLog dmp file or a traffic capture would help me dig into the cause of the false positive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-jonathan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2005 15:51:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tomcat-denial-of-service-attack/m-p/481952#M95002</guid>
      <dc:creator>jlimbo</dc:creator>
      <dc:date>2005-11-29T15:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Tomcat Denial of Service Attack</title>
      <link>https://community.cisco.com/t5/network-security/tomcat-denial-of-service-attack/m-p/481953#M95003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i replied to you with the information you requested offline&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2005 14:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tomcat-denial-of-service-attack/m-p/481953#M95003</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2005-12-01T14:32:54Z</dc:date>
    </item>
  </channel>
</rss>

