[Silicon Defense logo]

SnortSnarf alert page

Source: 24.209.215.159

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

33 such alerts found using input module SnortFileInput, with sources:
Earliest: 06:13:25.476293 on 06/01/2003
Latest: 10:06:52.704269 on 06/02/2003

2 different signatures are present for 24.209.215.159 as a source

There are 1 distinct destination IPs in the alerts of the type on this page.

24.209.215.159 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-06:13:25.476293 24.209.215.159:3279 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:24935 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xF88355D2 Ack: 0x366B7D8E Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-06:13:25.482884 24.209.215.159:3279 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:24936 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xF8835B86 Ack: 0x366B7D8E Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-06:48:31.439255 24.209.215.159:4187 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:39702 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xA11454CD Ack: 0xBAAA76CE Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-06:48:31.445585 24.209.215.159:4187 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:39703 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xA1145A81 Ack: 0xBAAA76CE Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-06:49:22.210579 24.209.215.159:1373 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:43177 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xA517F62F Ack: 0xBDE69998 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-06:49:22.211903 24.209.215.159:1373 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:43178 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xA517FBE3 Ack: 0xBDE69998 Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-07:20:25.344497 24.209.215.159:3994 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:38884 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x3818BA9A Ack: 0x33A736EE Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-07:20:25.350787 24.209.215.159:3994 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:38885 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x3818C04E Ack: 0x33A736EE Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-07:59:38.039024 24.209.215.159:4557 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:64309 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xEE0FF988 Ack: 0xC73443AA Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-07:59:38.040057 24.209.215.159:4557 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:64310 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xEE0FFF3C Ack: 0xC73443AA Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-08:22:39.148557 24.209.215.159:3046 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:23890 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x57D0B2A4 Ack: 0x1DF85278 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-08:22:39.153243 24.209.215.159:3046 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:23891 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x57D0B858 Ack: 0x1DF85278 Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-09:20:39.441795 24.209.215.159:2336 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:51803 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x5DD973D5 Ack: 0xF93529B4 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-09:20:39.443060 24.209.215.159:2336 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:51804 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x5DD97989 Ack: 0xF93529B4 Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-09:34:55.120218 24.209.215.159:4527 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:40609 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x9D557697 Ack: 0x2F992847 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-09:34:55.121245 24.209.215.159:4527 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:40610 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x9D557C4B Ack: 0x2F992847 Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-11:49:17.626514 24.209.215.159:3750 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:15976 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xE70B6315 Ack: 0x2A6C54A0 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-11:49:17.632464 24.209.215.159:3750 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:15977 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xE70B68C9 Ack: 0x2A6C54A0 Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-13:29:17.114614 24.209.215.159:1771 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:59762 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x89200173 Ack: 0xA46DBD72 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-13:29:17.115883 24.209.215.159:1771 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:59763 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x89200727 Ack: 0xA46DBD72 Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-13:43:07.570427 24.209.215.159:1219 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:40221 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xC0381E8C Ack: 0xD89D3B26 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-13:43:07.571691 24.209.215.159:1219 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:40222 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xC0382440 Ack: 0xD89D3B26 Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-14:01:32.367168 24.209.215.159:1742 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:35785 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x9C08042 Ack: 0x1E92AE59 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-14:01:32.368437 24.209.215.159:1742 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:35786 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x9C085F6 Ack: 0x1E92AE59 Win: 0x4470 TcpLen: 20
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-14:57:54.123699 24.209.215.159:1771 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:18005 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xE252A5A6 Ack: 0xF37408BD Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-17:04:43.432479 24.209.215.159:4019 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:8488 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xBB5AA4A6 Ack: 0xD242C414 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-17:04:43.448763 24.209.215.159:4019 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:8489 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xBB5AAA5A Ack: 0xD242C414 Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-19:20:44.579633 24.209.215.159:4261 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:4406 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xA1793D76 Ack: 0xD41389F2 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/01-19:20:44.580684 24.209.215.159:4261 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:4407 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xA179432A Ack: 0xD41389F2 Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/02-02:32:56.241053 24.209.215.159:2958 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:1541 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xB6C78726 Ack: 0x34A6B6E4 Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/02-02:32:56.242326 24.209.215.159:2958 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:1542 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xB6C78CDA Ack: 0x34A6B6E4 Win: 0x4470 TcpLen: 20
[**] [1:1243:8] WEB-IIS ISAPI .ida attempt [**]
[Classification: Web Application Attack] [Priority: 1]
06/02-10:06:52.697888 24.209.215.159:4576 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:20655 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x8122C837 Ack: 0xE8076AEE Win: 0x4470 TcpLen: 20
[Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2000-0071][Xref => http://www.securityfocus.com/bid/1065][Xref => http://www.whitehats.com/info/IDS552]
[**] [1:1002:5] WEB-IIS cmd.exe access [**]
[Classification: Web Application Attack] [Priority: 1]
06/02-10:06:52.704269 24.209.215.159:4576 -> 192.168.1.6:80
TCP TTL:124 TOS:0x0 ID:20656 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x8122CDEB Ack: 0xE8076AEE Win: 0x4470 TcpLen: 20

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:09:28 2003