[Silicon Defense logo]

SnortSnarf alert page

Source: 209.237.238.175

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

9 such alerts found using input module SnortFileInput, with sources:
Earliest: 17:05:00.897284 on 04/27/2003
Latest: 08:43:37.546793 on 06/08/2003

1 different signatures are present for 209.237.238.175 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

209.237.238.175 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/27-17:05:00.897284 209.237.238.175:45680 -> 192.168.1.6:80
TCP TTL:41 TOS:0x0 ID:48859 IpLen:20 DgmLen:177 DF
***AP*** Seq: 0x452302EA Ack: 0x8B6A1BA6 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 77446207 875363325
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/27-19:24:05.600180 209.237.238.175:45254 -> 192.168.1.6:80
TCP TTL:41 TOS:0x0 ID:4085 IpLen:20 DgmLen:177 DF
***AP*** Seq: 0x527A7831 Ack: 0x97DD510D Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 78280654 879637250
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/27-23:31:48.032855 209.237.238.175:37194 -> 192.168.1.6:80
TCP TTL:41 TOS:0x0 ID:9207 IpLen:20 DgmLen:177 DF
***AP*** Seq: 0xF98506C9 Ack: 0x40EFBE2F Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 79766857 887249343
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
05/22-16:39:26.825682 209.237.238.175:53250 -> 192.168.1.6:80
TCP TTL:41 TOS:0x0 ID:58541 IpLen:20 DgmLen:177 DF
***AP*** Seq: 0xE831D8E7 Ack: 0xF4BC05CA Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 293289051 1980876646
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
05/24-12:39:20.499059 209.237.238.175:42109 -> 192.168.1.6:80
TCP TTL:42 TOS:0x0 ID:17870 IpLen:20 DgmLen:173 DF
***AP*** Seq: 0xD830A9AA Ack: 0xE9A203FB Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 309128306 2062002825
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
05/26-14:59:33.436163 209.237.238.175:49254 -> 192.168.1.6:80
TCP TTL:42 TOS:0x0 ID:17070 IpLen:20 DgmLen:177 DF
***AP*** Seq: 0x65552CE4 Ack: 0x7A634967 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 327249503 2154816730
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
05/30-07:25:17.867673 209.237.238.175:40509 -> 192.168.1.6:80
TCP TTL:43 TOS:0x0 ID:38502 IpLen:20 DgmLen:177 DF
***AP*** Seq: 0xA8EDB8D9 Ack: 0xC68B37A6 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 359083722 2317866575
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
06/02-16:00:20.194713 209.237.238.175:54671 -> 192.168.1.6:80
TCP TTL:36 TOS:0x0 ID:13471 IpLen:20 DgmLen:177 DF
***AP*** Seq: 0xFA8D0B6F Ack: 0x1E876E3A Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 24068094 2466451319
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
06/08-08:43:37.546793 209.237.238.175:44831 -> 192.168.1.6:80
TCP TTL:37 TOS:0x0 ID:45245 IpLen:20 DgmLen:177 DF
***AP*** Seq: 0xFB39F788 Ack: 0x2C84A3AB Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 73287495 2718545314
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:03:52 2003