[Silicon Defense logo]

SnortSnarf signature page

SHELLCODE x86 setuid 0

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

9 alerts with this signature using input module SnortFileInput, with sources:

Earliest such alert at 18:46:56.379106 on 04/24/2003
Latest such alert at 14:50:23.831723 on 06/10/2003

SHELLCODE x86 setuid 0 7 sources 6 destinations
Priority: 2Classification: A system call was detected
[sid:650] [arachNIDS:436]

Sources triggering this attack signature

Source# Alerts (sig)# Alerts (total)# Dsts (sig)# Dsts (total)
216.65.98.1322311
128.242.172.25027011
192.234.167.2421111
63.240.15.1361111
63.215.124.461111
172.149.194.1081111
166.90.208.1521311

Destinations receiving this attack signature

Destinations# Alerts (sig)# Alerts (total)# Srcs (sig)# Srcs (total)
192.168.1.1014951225
192.168.1.10315818
192.168.1.6177701624
192.168.1.10512919
192.168.1.1061513
192.168.1.91115512

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:03:50 2003