[Silicon Defense logo]

SnortSnarf alert page

Source: 192.168.1.7: #27801-27816

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

Looking using input module SnortFileInput, with sources:
Earliest: 08:34:41.585639 on 06/17/2003
Latest: 08:59:41.672112 on 06/17/2003

2 different signatures are present for 192.168.1.7 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

192.168.1.7 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade
See also 192.168.1.7 as an alert destination [286 alerts]


Go to: previous range, all alerts, overview page
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:34:41.585639 192.168.1.7:33151 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:39:41.115142 192.168.1.7:33154 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:39:41.187602 192.168.1.7:33154 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:39:41.256717 192.168.1.7:33154 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:44:41.781379 192.168.1.7:33156 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:44:41.848714 192.168.1.7:33156 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:44:41.865372 192.168.1.7:33156 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:49:41.355028 192.168.1.7:33158 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:49:41.430207 192.168.1.7:33158 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:49:41.499445 192.168.1.7:33158 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:54:41.692675 192.168.1.7:33160 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:54:41.710908 192.168.1.7:33160 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:54:41.770031 192.168.1.7:33160 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:59:41.572711 192.168.1.7:33162 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:59:41.643161 192.168.1.7:33162 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
[**] [1:1417:2] SNMP request udp [**]
[Classification: Attempted Information Leak] [Priority: 2]
06/17-08:59:41.672112 192.168.1.7:33162 -> 192.168.1.1:161
UDP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:121 DF
Len: 93
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012]
Go to: previous range, all alerts, overview page
SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:09:24 2003