6.4 3000 Series—TCP Signatures
6.4.13 Application Exploit signatures
The following are Application Exploit signatures: -
  • 3400—Sun Kill Telnet DOS (severity 3, DoS): Fires when someone attempts to cause the telnetd server to lock up. This will catch the program known as sunkill.
  • 3450—Finger Bomb (severity 3, DoS): This signature is triggered when it detects a finger bomb attack. This attack attempts to crash a finger server by issuing a finger request that contains multiple @ symbols. If the finger server allows forwarding, then the multiple @ symbols will cause the finger server to recursively call itself and use up system resources.
  • 3500—rlogin -froot (severity 5, access): This signature is triggered when an attempt to rlogin with the arguments -froot has been made. A flaw in some rlogin processes allow unauthorized root access. Serious system compromise is possible.
  • 3525—Imap Authenticate Overflow (severity 5, access): This signature is triggered by receipt of packets bound for port 143 that are indicative of an attempt to overflow a buffer in the IMAP daemon. This may be the precursor to an attempt to gain unauthorized access to system resources.
  • 3526—Imap Login Overflow (severity 5, access): This signature is triggered by receipt of packets bound for port 143 that are indicative of an attempt to overflow the imapd login buffer. This may be the precursor to an attempt to gain unauthorized access to system resources.
  • 3550—Pop Overflow (severity 5, access): This signature is triggered by receipt of packets bound for port 110 that are indicative of an attempt to overflow the POP daemon user buffer. This may be the precursor to an attempt to gain unauthorized access to system resources.
  • 3575—Inn Overflow (severity 5, access): This signature is triggered when an attempt is made to overflow a buffer in the Internet News Server.
  • 3576—Inn Control Message (severity 5, access): This signature is triggered when an attempt is made to execute arbitrary commands via the control message.
  • 3600—IOS Telnet buffer overflow (severity 5, DoS): This signature is triggered by receipt of packets bound for port 23 of a Cisco router that are indicative of attempt to crash the router by overflowing an internal command buffer. This may be the precursor to an attempt to gain unauthorized access to system resources.
  • 3601—IOS Command History Exploit (severity 5, access): This signature is triggered by an attempt to force a Cisco router to reveal prior users' command histories.
  • 3602—Cisco IOS Identity (severity 1, information): This signature is triggered if someone attempts to connect to port 1999 on a Cisco router. This port is not enabled for access.