6.8 8000 Series—String Match Signatures
6.8.2 TCP application signatures

The following are TCP application signatures:

  • Capture password file:
    • 2101—FTP "RETR passwd" (severity 5, access): This signature is triggered by a string "passwd" issued during an FTP session. It may indicate someone attempting to retrieve the password file from a machine in order to crack it and gain unauthorized access to system resources.
  • Attempt loadmodule Attack
    • 2301—Telnet "IFS=/" (severity 5, access): This signature is triggered by an attempt to change the IFS to / is done during a telnet session. This may indicate an attempt to gain unauthorized access to system resources.
    • 51301—Rlogin "IFS=/" (severity 5, access): This signature is triggered when an attempt to change the IFS to / is done during a rlogin session. This may indicate an attempt to gain unauthorized access to system resources.
  • Enable unrestricted r-service access
    • 2303—Telnet "+ +" (severity 1, access): This signature is triggered by string "+ +" issued during a telnet session.
    • 51303—Rlogin "+ +" (severity 1, access): This signature is triggered by string "+ +" issued during a rlogin session.
  • Access UNIX shadow password file
    • 2302—Telnet "/etc/shadow" (severity 5, access): This signature is triggered by a string "/etc/shadow" issued during a Telnet session. This may indicate an attempt to gain unauthorized access to system resources.
    • 51302—Rlogin "/etc/shadow" (severity 5, access): This signature is triggered on a string "/etc/shadow" issued during a rlogin session. This may indicate an attempt to gain unauthorized access to system resources.