The following are Ident Attack signatures:
- 6200—Ident buffer overflow
(severity 5, access): This signature is triggered when a server
returns an IDENT reply that is too large. This may indicate an
attempt to gain unauthorized access to system resources.
- 6201—Ident newline (severity 5,
access): This signature is triggered when a server returns an
IDENT reply that includes a newline followed by more data. This
may indicate an attempt to gain unauthorized access to system
resources.
- 6202—Ident improper request
(severity 5, access): This signature is triggered when a client's
IDENT request is too long or specifies non-existent ports. This
may indicate an attempt to gain unauthorized access to system
resources.
|
|