[Silicon Defense logo]

SnortSnarf alert page

Destination: 255.255.255.255

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

8 such alerts found using input module SnortFileInput, with sources:
Earliest: 16:47:36.754413 on 04/22/2003
Latest: 17:13:54.013625 on 05/08/2003

1 different signatures are present for 255.255.255.255 as a destination

There are 1 distinct source IPs in the alerts of the type on this page.

255.255.255.255 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:1415:2] SNMP Broadcast request [**]
[Classification: Attempted Information Leak] [Priority: 2]
04/22-16:47:36.754413 192.168.1.4:1903 -> 255.255.255.255:161
UDP TTL:128 TOS:0x0 ID:32950 IpLen:20 DgmLen:265
Len: 237
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1415:2] SNMP Broadcast request [**]
[Classification: Attempted Information Leak] [Priority: 2]
04/22-16:47:37.322816 192.168.1.4:1903 -> 255.255.255.255:161
UDP TTL:128 TOS:0x0 ID:32952 IpLen:20 DgmLen:267
Len: 239
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1415:2] SNMP Broadcast request [**]
[Classification: Attempted Information Leak] [Priority: 2]
04/22-16:47:37.885473 192.168.1.4:1903 -> 255.255.255.255:161
UDP TTL:128 TOS:0x0 ID:32954 IpLen:20 DgmLen:265
Len: 237
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1415:2] SNMP Broadcast request [**]
[Classification: Attempted Information Leak] [Priority: 2]
05/08-16:58:19.674391 192.168.1.4:4682 -> 255.255.255.255:161
UDP TTL:128 TOS:0x0 ID:57747 IpLen:20 DgmLen:84
Len: 56
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1415:2] SNMP Broadcast request [**]
[Classification: Attempted Information Leak] [Priority: 2]
05/08-17:02:11.602148 192.168.1.4:4691 -> 255.255.255.255:161
UDP TTL:128 TOS:0x0 ID:57810 IpLen:20 DgmLen:84
Len: 56
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1415:2] SNMP Broadcast request [**]
[Classification: Attempted Information Leak] [Priority: 2]
05/08-17:03:53.083609 192.168.1.4:4694 -> 255.255.255.255:161
UDP TTL:128 TOS:0x0 ID:61074 IpLen:20 DgmLen:84
Len: 56
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1415:2] SNMP Broadcast request [**]
[Classification: Attempted Information Leak] [Priority: 2]
05/08-17:10:08.254004 192.168.1.4:1078 -> 255.255.255.255:161
UDP TTL:128 TOS:0x0 ID:484 IpLen:20 DgmLen:84
Len: 56
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1415:2] SNMP Broadcast request [**]
[Classification: Attempted Information Leak] [Priority: 2]
05/08-17:13:54.013625 192.168.1.4:1104 -> 255.255.255.255:161
UDP TTL:128 TOS:0x0 ID:947 IpLen:20 DgmLen:84
Len: 56
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:09:29 2003