[Silicon Defense logo]

SnortSnarf alert page

Source: 216.39.48.24

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

9 such alerts found using input module SnortFileInput, with sources:
Earliest: 11:35:11.966007 on 04/18/2003
Latest: 12:21:36.499772 on 04/24/2003

1 different signatures are present for 216.39.48.24 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

216.39.48.24 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/18-11:35:11.966007 216.39.48.24:32914 -> 192.168.1.6:80
TCP TTL:37 TOS:0x0 ID:28421 IpLen:20 DgmLen:211 DF
***AP*** Seq: 0x36D71485 Ack: 0x6B746853 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 316963733 466918808
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/19-04:53:30.671532 216.39.48.24:42604 -> 192.168.1.6:80
TCP TTL:37 TOS:0x0 ID:12285 IpLen:20 DgmLen:211 DF
***AP*** Seq: 0x8887AB01 Ack: 0xBD355E56 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 323192072 498826382
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/22-21:40:27.926476 216.39.48.24:50184 -> 192.168.1.6:80
TCP TTL:37 TOS:0x0 ID:25951 IpLen:20 DgmLen:211 DF
***AP*** Seq: 0x1FB45E3D Ack: 0x5E8C7F51 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 355154799 662570316
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/23-02:05:32.912613 216.39.48.24:35995 -> 192.168.1.6:80
TCP TTL:37 TOS:0x0 ID:60013 IpLen:20 DgmLen:211 DF
***AP*** Seq: 0x9A494D7 Ack: 0x4696AA4E Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 356744906 670716384
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/23-15:18:30.978684 216.39.48.24:56637 -> 192.168.1.6:80
TCP TTL:37 TOS:0x0 ID:58478 IpLen:20 DgmLen:211 DF
***AP*** Seq: 0xBC32F725 Ack: 0xFA43D834 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 361501540 695084394
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/23-18:01:09.199442 216.39.48.24:45996 -> 192.168.1.6:80
TCP TTL:37 TOS:0x0 ID:42124 IpLen:20 DgmLen:211 DF
***AP*** Seq: 0x223F5184 Ack: 0x6052D835 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 362477123 700082345
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/23-18:08:00.638959 216.39.48.24:41604 -> 192.168.1.6:80
TCP TTL:37 TOS:0x0 ID:395 IpLen:20 DgmLen:211 DF
***AP*** Seq: 0x3B86976E Ack: 0x7B203717 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 362518257 700293073
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/23-19:42:45.098608 216.39.48.24:47151 -> 192.168.1.6:80
TCP TTL:37 TOS:0x0 ID:47738 IpLen:20 DgmLen:211 DF
***AP*** Seq: 0xA16AF8AD Ack: 0xDFD25F90 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 363086563 703204476
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]
[**] [1:1852:3] WEB-MISC robots.txt access [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
04/24-12:21:36.499772 216.39.48.24:55213 -> 192.168.1.6:80
TCP TTL:37 TOS:0x0 ID:40991 IpLen:20 DgmLen:211 DF
***AP*** Seq: 0x5D5F0FD9 Ack: 0x9CEDFC56 Win: 0x16D0 TcpLen: 32
TCP Options (3) => NOP NOP TS: 369078228 733899591
[Xref => http://cgi.nessus.org/plugins/dump.php3?id=10302]

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:03:52 2003