[Silicon Defense logo]

SnortSnarf signature page

WEB-IIS multiple decode attempt

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

952 alerts with this signature using input module SnortFileInput, with sources:

Earliest such alert at 19:49:24.965869 on 04/17/2003
Latest such alert at 04:47:14.753241 on 06/17/2003

WEB-IIS multiple decode attempt 176 sources 1 destinations
Priority: 1Classification: Web Application Attack
[sid:970] [CVE:CAN-2001-0333]

Sources triggering this attack signature

Source# Alerts (sig)# Alerts (total)# Dsts (sig)# Dsts (total)
24.209.39.2465432611
24.209.105.1565230611
24.209.174.04925011
24.209.219.1624321311
24.209.11.98229911
24.209.219.95168111
24.209.191.911613611
24.63.13.134157611
24.245.2.233146611
24.209.18.197126511
24.130.219.16115011
24.44.2.165115111
24.209.40.219104911
24.209.42.242107711
24.35.68.68104911
24.98.140.13494611
24.99.37.18683411
24.209.118.13483411
24.219.28.22183411
24.74.84.12483411
24.126.82.2284911
24.166.45.3773211
24.57.13.7873311
24.98.99.14173111
24.186.148.2473311
24.99.137.15373311
24.157.173.3973311
24.209.113.1175211
24.46.127.15773211
24.112.153.4473311
24.29.173.8163311
24.242.248.24863111
24.125.85.18763211
24.189.230.11864011
24.98.50.14263211
24.93.48.9164111
24.150.22.13951811
24.91.103.15251811
24.203.221.551811
24.85.206.15251811
24.98.69.17253311
24.150.202.3753211
24.114.34.2451811
24.30.115.9351811
24.243.144.1352011
24.204.108.6141711
24.157.153.20442111
24.164.56.16541711
24.28.27.20141711
24.127.15.1642111
24.201.150.21841711
24.61.174.15841811
24.226.59.10441711
24.245.36.14242111
24.191.37.11341711
24.218.160.23842211
24.203.10.19441711
24.226.120.16741711
24.148.68.17741711
24.160.16.4641711
24.138.38.20641711
24.218.253.6741711
24.112.193.14543011
24.59.74.4741711
24.123.41.13041711
24.209.36.20741711
24.209.36.194412911
24.95.244.12941711
24.167.224.15041711
24.140.13.15541711
24.171.142.3241711
24.98.61.17741811
24.114.7.12142511
24.201.31.4141711
24.30.227.13641711
24.126.254.1341711
24.84.94.19541711
24.198.102.6041711
24.201.23.6331611
24.91.57.21131611
24.153.56.2631611
24.90.92.16731711
24.150.86.22431211
24.160.157.7931611
24.126.120.8831611
24.206.140.7831611
24.84.101.19431611
24.205.10.24731611
24.242.253.12232311
24.54.164.10531611
24.106.83.10231611
24.148.37.19631611
24.76.98.11331611
24.25.55.9331611
24.157.60.4832011
24.71.58.20831711
24.60.182.12431511
24.162.219.20331611
24.91.112.14931811
24.202.81.5931611
24.162.12.21031611
24.175.171.18031511
24.98.129.25131211
24.94.212.16631611
24.214.128.12631611
24.120.188.23631611
24.220.31.331611
24.150.19.12331611
24.201.83.15231611
24.174.223.21231611
24.158.5.11331611
24.62.112.14831611
24.202.15.24031611
24.205.137.1231611
24.99.136.1631411
24.147.143.3231811
24.208.232.17331611
24.198.148.10431711
24.198.96.14931611
24.161.112.4031611
24.197.103.21031611
24.60.106.18531611
24.99.90.2831611
24.166.119.8831911
24.150.35.19431611
24.43.35.5031511
24.243.238.24831611
24.74.33.15531511
24.114.19.20331611
24.129.102.20532711
24.202.34.7231611
24.161.94.6131611
24.150.116.1031611
24.98.22.11732511
24.208.193.21832011
24.50.102.8831611
24.114.84.14331711
24.52.59.2531811
24.158.6.1531611
24.70.71.23631611
24.160.23.5331511
24.91.73.15231611
24.66.107.8731611
24.30.204.14531611
24.74.152.24931611
24.99.49.21031611
24.34.222.5231911
24.236.70.231711
24.114.70.18231611
24.98.223.23331511
24.112.68.20831611
24.92.8.831611
24.198.96.12031611
24.99.96.13131511
24.98.81.1631611
24.87.77.10631611
24.98.186.23131611
24.214.104.3831611
24.62.250.7231611
24.47.19.14431611
24.201.229.6731511
24.92.146.11131611
24.243.175.14431511
24.165.15.14531611
24.199.188.22631811
24.57.76.3731411
24.200.41.11331611
24.130.204.3021511
24.98.23.21021311
24.214.98.642611
24.78.148.8521511
24.148.85.8521811
24.34.91.2921411
24.71.47.17311411
24.98.20.1411711
24.140.76.1411311

Destinations receiving this attack signature

Destinations# Alerts (sig)# Alerts (total)# Srcs (sig)# Srcs (total)
192.168.1.69527770176624

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:03:51 2003