Other Security Subjects

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Get

 

Forum Posts

I have been receiving quite a few alarm triggers for the signature FTP Improper Address Specified ID: 3153. All of the alarms have triggered when the attackers port is greater that 1024 and less than 65355. The victims port is always port 21. Has any...

I have an interesting observation. The signature Soulseek Client Login has triggered quite often when the victim’s address is a Nachi infected machine. The signature is triggered when the attackers port is 135 and the victim’s port is TCP port 2234 o...

I am starting to use VMS 3 for IDS monitoring. I just realize VMS is using java plug-in 1.3.1, which is older version some of my other programms cannot live with on the same machine. Currently I have to build a seperat machine only for VMS, which is ...

fengluo by Level 1
  • 312 Views
  • 1 replies
  • 0 Helpful votes

Has anyone come up with a way to detect if a sensor is functioning(ie. heartbeat)? In the absence of generating any alarms over some period of time, looking to determine if a sensor is down or just not firing alarms.

csmeriglio by Level 1
  • 1112 Views
  • 12 replies
  • 0 Helpful votes

Before we enabled this signature, we would catch MSBlaster/Nachi infected machines using the 3327 (RPC DCOM Overflow) and 3328 (SMB/RPC NoOp Sled) signatures.Now that 2156 is enabled, infected machines trigger all three.My question is this however. S...

pbobby by Level 1
  • 322 Views
  • 3 replies
  • 0 Helpful votes

I am using PIX 520 and it is working fine but only chat server is not working.Please have a look my configurationPIX Version 6.3(3)interface ethernet0 100fullinterface ethernet1 10basetinterface ethernet2 100fullinterface ethernet3 100fullinterface e...

ishwar by Level 1
  • 233 Views
  • 1 replies
  • 0 Helpful votes