[Silicon Defense logo]

SnortSnarf signature page

WEB-CLIENT javascript URL host spoofing attempt

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

11 alerts with this signature using input module SnortFileInput, with sources:

Earliest such alert at 20:11:51.301187 on 04/27/2003
Latest such alert at 12:56:30.995172 on 06/07/2003

WEB-CLIENT javascript URL host spoofing attempt 5 sources 5 destinations
Priority: 1Classification: Attempted User Privilege Gain
[sid:1841] [BUGTRAQ:5293]

Sources triggering this attack signature

Source# Alerts (sig)# Alerts (total)# Dsts (sig)# Dsts (total)
80.87.131.1634411
64.12.145.1673311
209.15.189.1732211
63.216.0.2511211
209.202.195.1981111

Destinations receiving this attack signature

Destinations# Alerts (sig)# Alerts (total)# Srcs (sig)# Srcs (total)
192.168.1.4469111
192.168.1.9231017
192.168.1.10421618
192.168.1.10013818
192.168.1.1011951125

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:03:51 2003