Table 122: Deep Inspection Alarm Log Entries - Juniper NETWORK AND SECURITY MANAGER 2010.2 - ADMINISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Table 122: Deep Inspection Alarm Log Entries

Attack Name
APP:CURL-OF-BANNER
CHAT:AIM:MESSAGE-SEND
CHAT:AUDIT:AIM:INVALID-TLV
CHAT:AUDIT:AIM:INV-TLV-LEN
CHAT:AUDIT:MSN:GROUP-NAME
CHAT:AUDIT:YMSG:FILE-SEND
CHAT:AUDIT:YMSG:MAIL-ADDR
CHAT:AUDIT:YMSG:MSG-TOO-BIG
CHAT:AUDIT:YMSG:OFLOW-GRP-NAME
CHAT:AUDIT:YMSG:OFLOW-PASSWD
CHAT:MSN:ACCESS
Copyright © 2010, Juniper Networks, Inc.
Attack Description
This signature detects buffer overflow attempts against the
cURL file retrieval client. cURL 6.1 to 7.4 versions are
vulnerable. Attackers may use a malicious server to connect
to the cURL client and execute arbitrary code with the
permissions of the cURL user.
This signature detects messages sent from AIM clients to
other AIM clients.
This protocol anomaly is a AIM message with an invalid TLV;
the TLV data specified in the FLAP header is less than the
actual data in the TLV header.
This protocol anomaly is a AIM message with an invalid TLV;
the TLV length is less than expected, or the TLV length is
greater than the data specified in the FLAP header.
This protocol anomaly is an MSN message with a group
name length that exceeds the user-defined maximum. The
default group name maximum is 64.
This signature detects a Yahoo Messenger client sending a
file to another user.
This protocol anomaly is a Yahoo! Messenger e-mail address
that exceeds the user-defined maximum. A Yahoo!
Messenger server sends an e-mail address as part of a new
e-mail alert message. The default number of bytes in an
Yahoo! Messenger e-mail address is 84.
This protocol anomaly is a Yahoo! Messenger message that
exceeds the user-defined maximum. The default number of
bytes in an Yahoo! Messenger message is 8192.
This protocol anomaly is a Yahoo! Messenger group name
that exceeds the user-defined maximum. Yahoo! Messenger
clients use groups to separate their friends into categories.
The default number of bytes in an Yahoo! Messenger group
name is 84.
This protocol anomaly is a Yahoo! Messenger encrypted
password that exceeds the user-defined maximum. The
Yahoo! Messenger client sends an encrypted password to
the server as part of the authentication process. The default
number of bytes in an Yahoo! Messenger encrypted
password is 1024.
This signature detects MSN Messenger chat using the
specified content type "text/plain" on port 1863 (default
port of MSN Messenger).
Appendix E: Log Entries
Severity
Versions
high
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
info
sos5.1.0
849

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.2

Table of Contents