INTRUSION DETECTION AND PREVENTION
General
Signature
Update
Backup & Restore
Signature Groups
Switch to query view
Attack Type
---Select a Type---
DDOS
BufferOverflow
AccessControl
Scan
TrojanHorse
Other
P2P
IM
VirusWorm
Porn
WebAttacks
SPAM
Name
ID
Severity
Platform
Active
Log
Alert
Action
EXPLOIT MS IE HHCtrl ActiveX Control Vulnerability (MS06-046)
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT MS SMB PIPE Remote Denial of Service Vulnerability
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT IIS Malformed HTTP Request Remote DoS
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT MS Windows Metafile (WMF) Image Handling (MS05-053) -1
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT MS Distributed Transaction Coordinator (MS05-051) -1
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT MS Windows Metafile (WMF) Image Handling (MS05-053)
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT Windows 2000 Server UPNP DoS
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT Microsoft ASN.1 DoS -4
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT Microsoft ASN.1 DoS -3
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT Microsoft ASN.1 DoS -2
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT Microsoft ASN.1 DoS -1
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT Microsoft Windows SSL Library Denial of Service
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
DoS Microsoft Windows RDP rdpwd.sys Remote Kernel DoS
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Worm.Mytob.DC -3
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Worm.Mytob.DC -2
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Worm.Mytob.DC -1
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Worm.Mytob.DB -3
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Worm.Mytob.DB -2
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Worm.Mytob.DB -1
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Possible DoS HGOD SynKiller Flooding
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
DoS WebDAV XML Message Handler Denial of Service (MS04-030)
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Apache HTTP GET Remote DoS Exploit
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB Plug and Play Web Server DoS attempt
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
DoS DNS UDP flooding
Severe
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
MISC xfs overflow attempt
Severe
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
DoS MS-SQL Slammer Worm
Severe
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
DoS-ath0-modem-disconnect
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
DDoS tfn2k-icmp_possible_communication
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB-MISC /ecscripts/ecware.exe access
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB-MISC jigsaw dos attempt
Low
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
SNMP community string buffer overflow attempt
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB-MISC CISCO VoIP DOS ATTEMPT
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
DDoS Stacheldraht agent->handler (skillz)
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
DDoS Stacheldraht handler->agent (niggahbitch)
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
DDoS Stacheldraht handler->agent (ficken)
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
BACKDOOR win-trin00 connection attempt
Severe
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
BACKDOOR trinity connection attempt
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
MS Terminal server request (RDP)
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
SNMP PROTOS test-suite-trap-app attempt
Very Low
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
SNMP PROTOS test-suite-req-app attempt
Very Low
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB sml3com access - type 1
Low
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB HP Openview Manager DoS
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB Annex Terminal DoS attempt
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB Cisco Web DoS attempt
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB ICQ Webfront HTTP DoS
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB netscape servers suite DoS
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
WEB Netscape Enterprise DoS
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
IIS isc$data attempt
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
IIS *.idc attempt
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
FRONTPAGE shtml.exe access
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
FRONTPAGE shtml.dll access
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
FRONTPAGE _vti_rpc access
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
CGI classifieds.cgi access
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
SMTP exchange mime DoS
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
NETBIOS DoS RFPoison
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
NETBIOS nimda .nws
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
NETBIOS nimda .eml
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
MISC UPNP malformed advertisement
Low
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
ICMP Large ICMP Packet
Very Low
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
ICMP redirect net
Very Low
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
EXPLOIT VQServer admin
Low
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
DoS UDP echo+chargen bomb
Severe
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
TFN client command LE
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
mstream agent pong to handler
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
mstream handler ping to agent
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
mstream handler to agent
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
mstream agent to handler
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
shaft synflood
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
shaft handler to agent
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
TFN server response
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Trin00 Master to Daemon (default pass detected!)
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Stacheldraht client-check-gag
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Trin00 Attacker to Master default mdie password
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Trin00 Attacker to Master default password
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Trin00 Attacker to Master default startup password
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Trin00 Daemon to Master (*HELLO* detected)
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Trin00 Daemon to Master (message detected)
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Stacheldraht client-check-skillz
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
TFN client command BE
Medium
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Stacheldraht client-spoofworks
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Stacheldraht server-response
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Stacheldraht server-response-gag
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Stacheldraht server-spoof
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
Trin00 Daemon to Master (PONG detected)
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both
TFN Probe
High
No Action
Drop Packet
Drop Session
Reset Sender
Reset Receiver
Reset Both