[Silicon Defense logo]

SnortSnarf alert page

Destination: 12.2.177.190

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

1 such alerts found using input module SnortFileInput, with sources:
Earliest: 19:54:24.493679 on 05/27/2003
Latest: 19:54:24.493679 on 05/27/2003

1 different signatures are present for 12.2.177.190 as a destination

There are 1 distinct source IPs in the alerts of the type on this page.

12.2.177.190 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade
See also 12.2.177.190 as an alert source [1 alerts]


[**] [1:1201:6] ATTACK RESPONSES 403 Forbidden [**]
[Classification: Attempted Information Leak] [Priority: 2]
05/27-19:54:24.493679 192.168.1.6:80 -> 12.2.177.190:37375
TCP TTL:64 TOS:0x0 ID:16986 IpLen:20 DgmLen:636 DF
***AP*** Seq: 0x12AB66F2 Ack: 0x1AA7714 Win: 0x2180 TcpLen: 20

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:09:29 2003