[Silicon Defense logo]

SnortSnarf alert page

Destination: 192.168.1.1: #81301-81311

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

Looking using input module SnortFileInput, with sources:
Earliest: 08:54:36.941421 on 06/17/2003
Latest: 08:59:41.672112 on 06/17/2003

7 different signatures are present for 192.168.1.1 as a destination

There are 5 distinct source IPs in the alerts of the type on this page.

192.168.1.1 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade
See also 192.168.1.1 as an alert source [56 alerts]


Go to: previous range, all alerts, overview page
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:54:36.941421 192.168.1.6:36453 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:54:36.945349 192.168.1.6:36453 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:54:41.692675 192.168.1.7:33160 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:54:41.710908 192.168.1.7:33160 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:54:41.770031 192.168.1.7:33160 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:59:37.314411 192.168.1.6:36453 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:59:37.334691 192.168.1.6:36453 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:59:37.338610 192.168.1.6:36453 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:59:41.572711 192.168.1.7:33162 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:59:41.643161 192.168.1.7:33162 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:59:41.672112 192.168.1.7:33162 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
Go to: previous range, all alerts, overview page
SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:09:43 2003