6.7 6000 Series—Cross-Protocol Signatures
6.7.6 Ident attack signatures
The following are Ident Attack signatures:
  • 6200—Ident buffer overflow (severity 5, access): This signature is triggered when a server returns an IDENT reply that is too large. This may indicate an attempt to gain unauthorized access to system resources.
  • 6201—Ident newline (severity 5, access): This signature is triggered when a server returns an IDENT reply that includes a newline followed by more data. This may indicate an attempt to gain unauthorized access to system resources.
  • 6202—Ident improper request (severity 5, access): This signature is triggered when a client's IDENT request is too long or specifies non-existent ports. This may indicate an attempt to gain unauthorized access to system resources.