6.7 6000 Series—Cross-Protocol Signatures
6.7.7 Authorization Failure signatures
The following are Authorization Failure signatures:
  • 6250—FTP (severity 1, information/access): This signature is triggered when a user has failed to authenticate three times in a row, while trying to establish an FTP session. This may indicate a "brute force" password-guessing attempt, and may be viewed as an attempt to gain unauthorized access to system resources.
  • 6251—Telnet (severity 1, information/access): This signature is triggered when a user has failed to authenticate three times in a row, while trying to establish a telnet session. This may indicate a "brute force" password-guessing attempt, and may be viewed as an attempt to gain unauthorized access to system resources.
  • 6252—Rlogin (severity 1 access): This signature is triggered when a user has failed to authenticate three times in a row, while trying to establish an rlogin session. This may indicate a "brute force" password-guessing attempt, and may be viewed as an attempt to gain unauthorized access to system resources.
  • 6253—POP3 (severity 1, information/access): This signature is triggered when a user has failed to authenticate three times in a row, while trying to establish a POP3 session. This may indicate a "brute force" password-guessing attempt, and may be viewed as an attempt to gain unauthorized access to system resources.
  • 6255—SMB (severity 1, information/access): This alarm is triggered when a client fails Windows NT's (or Samba's) user authentication three or more consecutive times within a single SMB session. This indicates that the user does not have a valid account name or password, the user has forgotten the password, or a password guessing attack like NAT is being used against the server. This alarm will also trigger on multiple failures to access a Windows 95 share. Share level access disregards the provided username and only uses the provided password.