Snort Report

Begins:Sun Aug 19 23:37:10 2001
Ends:Mon Aug 20 08:36:54 2001
File:/usr/tardis/vault/snort/snort-20010820.0

Alerts

grouped by id

%#priodescription
60.914medIDS552/web-iis_IIS ISAPI Overflow ida
21.75medIDS118/scan_Traceroute ICMP
8.72IDS243/web-cgi-pipe
4.31IDS278/dns_named-probe-version
4.31lowIDS296/web-misc http-whisker-splicing attack-space

grouped by remote host, id

#remote hostpriodescription
2lhr.skitter.caida.orgmedIDS118/scan_Traceroute ICMP
2uoregon.skitter.caida.orgmedIDS118/scan_Traceroute ICMP
261.154.12.10medIDS552/web-iis_IIS ISAPI Overflow ida
1waikato.skitter.caida.orgmedIDS118/scan_Traceroute ICMP
163.169.45.12IDS243/web-cgi-pipe
1PPP-200-7-175.bng.vsnl.net.inIDS243/web-cgi-pipe
1210.108.181.1IDS278/dns_named-probe-version
1204.133.181.6lowIDS296/web-misc http-whisker-splicing attack-space
1138.87.217.80medIDS552/web-iis_IIS ISAPI Overflow ida
1203.68.161.230medIDS552/web-iis_IIS ISAPI Overflow ida
1204.133.181.6medIDS552/web-iis_IIS ISAPI Overflow ida
1206.251.228.69medIDS552/web-iis_IIS ISAPI Overflow ida
124-148-14-172....1stcentury.netmedIDS552/web-iis_IIS ISAPI Overflow ida
124-196-235-122...er-georgia.commedIDS552/web-iis_IIS ISAPI Overflow ida
1atr-0015.unm.edumedIDS552/web-iis_IIS ISAPI Overflow ida
1dialup-209.245...es1.Level3.netmedIDS552/web-iis_IIS ISAPI Overflow ida
1pD901836B.dip.t-dialin.netmedIDS552/web-iis_IIS ISAPI Overflow ida
1s211-49-60-227.thrunet.ne.krmedIDS552/web-iis_IIS ISAPI Overflow ida
1slip-129-37-44....us.prserv.netmedIDS552/web-iis_IIS ISAPI Overflow ida
1st188.dhcp.ttu.edumedIDS552/web-iis_IIS ISAPI Overflow ida

grouped by local host, id

#local hostpriodescription
6tardis-b3medIDS552/web-iis_IIS ISAPI Overflow ida
5tardis-a4medIDS552/web-iis_IIS ISAPI Overflow ida
3buwayamedIDS118/scan_Traceroute ICMP
3tardis-b2medIDS552/web-iis_IIS ISAPI Overflow ida
2tardis-a4medIDS118/scan_Traceroute ICMP
2cyclopsIDS243/web-cgi-pipe
1algolIDS278/dns_named-probe-version
1tardis-b2lowIDS296/web-misc http-whisker-splicing attack-space

grouped by local port, id

#portpriodescription
1domainIDS278/dns_named-probe-version
14httpmedIDS552/web-iis_IIS ISAPI Overflow ida
2httpIDS243/web-cgi-pipe
1httplowIDS296/web-misc http-whisker-splicing attack-space

Note: 'port' is destination port, only traffic with local destination considered.


snort-rep 1.5