The following are Authorization Failure
signatures:
- 6250—FTP (severity 1,
information/access): This signature is triggered when a user has
failed to authenticate three times in a row, while trying to
establish an FTP session. This may indicate a "brute
force" password-guessing attempt, and may be viewed as an
attempt to gain unauthorized access to system resources.
- 6251—Telnet (severity 1,
information/access): This signature is triggered when a user has
failed to authenticate three times in a row, while trying to
establish a telnet session. This may indicate a "brute
force" password-guessing attempt, and may be viewed as an
attempt to gain unauthorized access to system resources.
- 6252—Rlogin (severity 1 access):
This signature is triggered when a user has failed to authenticate
three times in a row, while trying to establish an rlogin session.
This may indicate a "brute force" password-guessing
attempt, and may be viewed as an attempt to gain unauthorized
access to system resources.
- 6253—POP3 (severity 1,
information/access): This signature is triggered when a user has
failed to authenticate three times in a row, while trying to
establish a POP3 session. This may indicate a "brute
force" password-guessing attempt, and may be viewed as an
attempt to gain unauthorized access to system resources.
- 6255—SMB (severity 1,
information/access): This alarm is triggered when a client fails
Windows NT's (or Samba's) user authentication three or more
consecutive times within a single SMB session. This indicates that
the user does not have a valid account name or password, the user
has forgotten the password, or a password guessing attack like NAT
is being used against the server. This alarm will also trigger on
multiple failures to access a Windows 95 share. Share level access
disregards the provided username and only uses the provided
password.
|
|