6.5 4000 Series—UDP Signatures
6.5.5 UDP application signatures
The following are UDP application signatures:
  • 4053—Back Orifice (severity 5, access): This signature is triggered when CIDS detects traffic coming from a Back Orifice server that is running on the network. Back Orifice is a "backdoor" program that can be installed on a Microsoft Windows 95 or Windows 98 system, allowing remote control of the system.
  • 4100—Tftp passwd file attempt (severity 5, access): This signature is triggered by an attempt to access the passwd file via TFTP. It is indicative of an attempt to gain unauthorized access to system resources.
  • 4150—Ascend Kill (severity 3, DoS): This signature is triggered when an attempt has been made to send a maliciously malformed command to an ascend router in an attempt to crash the router.
  • 4600—IOS UDP bomb (severity 5, DoS): This signature is triggered by receipt of improperly formed SYSLOG transmissions bound for UDP port 514.