[Silicon Defense logo]

SnortSnarf alert page

Source: 129.137.91.78

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

5 such alerts found using input module SnortFileInput, with sources:
Earliest: 15:43:25.426637 on 05/14/2003
Latest: 15:43:57.363031 on 05/14/2003

1 different signatures are present for 129.137.91.78 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

129.137.91.78 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:1042:6] WEB-IIS view source via translate header [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
05/14-15:43:25.426637 129.137.91.78:1247 -> 192.168.1.6:80
TCP TTL:108 TOS:0x0 ID:30329 IpLen:20 DgmLen:181 DF
***AP*** Seq: 0x246DFA1A Ack: 0x9180B842 Win: 0x44E8 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/1578][Xref => http://www.whitehats.com/info/IDS305]
[**] [1:1042:6] WEB-IIS view source via translate header [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
05/14-15:43:25.963013 129.137.91.78:1247 -> 192.168.1.6:80
TCP TTL:108 TOS:0x0 ID:30338 IpLen:20 DgmLen:196 DF
***AP*** Seq: 0x246DFAA7 Ack: 0x9180B9B0 Win: 0x437A TcpLen: 20
[Xref => http://www.securityfocus.com/bid/1578][Xref => http://www.whitehats.com/info/IDS305]
[**] [1:1042:6] WEB-IIS view source via translate header [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
05/14-15:43:53.419908 129.137.91.78:1249 -> 192.168.1.6:80
TCP TTL:108 TOS:0x0 ID:30899 IpLen:20 DgmLen:206 DF
***AP*** Seq: 0x668D9CC8 Ack: 0x93C65DFC Win: 0x44E8 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/1578][Xref => http://www.whitehats.com/info/IDS305]
[**] [1:1042:6] WEB-IIS view source via translate header [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
05/14-15:43:53.800294 129.137.91.78:1250 -> 192.168.1.6:80
TCP TTL:108 TOS:0x0 ID:30911 IpLen:20 DgmLen:206 DF
***AP*** Seq: 0x80E61BE7 Ack: 0x93232BC3 Win: 0x44E8 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/1578][Xref => http://www.whitehats.com/info/IDS305]
[**] [1:1042:6] WEB-IIS view source via translate header [**]
[Classification: access to a potentially vulnerable web application] [Priority: 2]
05/14-15:43:57.363031 129.137.91.78:1251 -> 192.168.1.6:80
TCP TTL:108 TOS:0x0 ID:30970 IpLen:20 DgmLen:206 DF
***AP*** Seq: 0x7B696A41 Ack: 0x93A55FF6 Win: 0x44E8 TcpLen: 20
[Xref => http://www.securityfocus.com/bid/1578][Xref => http://www.whitehats.com/info/IDS305]

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:03:52 2003