The following are UDP application
signatures:
- 4053—Back Orifice (severity 5,
access): This signature is triggered when CIDS detects traffic
coming from a Back Orifice server that is running on the network.
Back Orifice is a "backdoor" program that can be
installed on a Microsoft Windows 95 or Windows 98 system, allowing
remote control of the system.
- 4100—Tftp passwd file attempt
(severity 5, access): This signature is triggered by an attempt to
access the passwd file via TFTP. It is indicative of an attempt to gain unauthorized access to system resources.
- 4150—Ascend Kill (severity 3, DoS):
This signature is triggered when an attempt has been made to send
a maliciously malformed command to an ascend router in an attempt
to crash the router.
- 4600—IOS UDP bomb (severity 5, DoS):
This signature is triggered by receipt of improperly formed SYSLOG
transmissions bound for UDP port 514.
|
|