[Silicon Defense logo]

SnortSnarf signature page

SHELLCODE x86 setgid 0

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

8 alerts with this signature using input module SnortFileInput, with sources:

Earliest such alert at 23:32:06.425602 on 04/22/2003
Latest such alert at 00:15:28.447014 on 06/11/2003

SHELLCODE x86 setgid 0 6 sources 7 destinations
Priority: 2Classification: A system call was detected
[sid:649] [arachNIDS:284]

Sources triggering this attack signature

Source# Alerts (sig)# Alerts (total)# Dsts (sig)# Dsts (total)
206.151.167.2272323
216.168.224.692211
152.163.134.1641111
63.210.68.2131111
63.216.0.2511211
66.187.232.1001111

Destinations receiving this attack signature

Destinations# Alerts (sig)# Alerts (total)# Srcs (sig)# Srcs (total)
192.168.1.10023818
192.168.1.1011951125
192.168.1.4169111
192.168.1.10411618
192.168.1.7128612
192.168.1.1061513
192.168.1.1071111

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:03:48 2003