CCIE Security - IPS Signatures - from 5700 up to 6921

 

Signature ID

Signature Name

Signature Engine

5700-0

PHP cURL Arbitrary File Access

string-tcp

5701-0

Oracle Soap Request

service-http

5701-1

Oracle Soap Request

service-http

5705-0

iPlanet Web Server Remote Root Command Execution

service-http

5706-0

Persistent Content in a Dynamic Webpage

string-tcp

5708-0

SWAT Pre-Authentication Buffer Overflow

service-http

5710-0

Eicar Standard Anti-Virus Test File

string-tcp

5711-0

Malformed URL

string-tcp

5713-0

Zip File Name Overflow

string-tcp

5714-0

GKrellM Buffer Overflow

string-tcp

5715-0

SAP Internet Transaction Server Information Disclosure

service-http

5716-0

IOS Stack Group Bidding Protocol DoS

atomic-ip

5717-0

Ipswitch SMTP Format String

string-tcp

5718-0

VERITAS NetBackup Volume Manager Daemon Buffer Overflow

string-tcp

5720-0

Lyris ListManager SQL Command Injection

service-http

5722-0

Google Appliance ProxyStyleSheet Command Execution

service-http

5724-0

Nikto Scan

service-http

5725-0

Novell NMAP Agent Buffer Overflow

string-tcp

5726-0

Active Directory Failed Login

multi-string

5726-1

Active Directory Failed Login

multi-string

5727-0

Cisco VPN 3000 Concentrator HTTP Attack Vulnerability

string-tcp

5729-0

Windows Media Player Browser Plug-in Overflow

string-tcp

5729-1

Windows Media Player Browser Plug-in Overflow

service-http

5730-0

Winamp Playlist File Handling Buffer Overflow

string-tcp

5731-1

Windows Media Player BMP Processing Vulnerability

string-tcp

5731-2

Windows Media Player BMP Processing Vulnerability

string-tcp

5732-1

Web Client Remote Code Execution Vulnerability

string-tcp

5732-2

Web Client Remote Code Execution Vulnerability

string-tcp

5733-0

Long HTTP Header Hostname

string-tcp

5734-0

IE isComponentInstalled() Overflow

string-tcp

5735-0

Macromedia Flash Player ActionDefineFunction Code Execution

string-tcp

5736-0

WinVNC Client Buffer Overflow

string-tcp

5737-0

Internet Explorer Action Handlers Overflow

string-tcp

5738-0

Windows ACS Registry Access

string-tcp

5738-1

Windows ACS Registry Access

string-tcp

5738-2

Windows ACS Registry Access

string-tcp

5739-0

Active Directory Failed Login

atomic-ip

5740-0

Kerio Personal Firewall Remote Authentication Buffer Overflow

string-tcp

5740-1

Kerio Personal Firewall Remote Authentication Buffer Overflow

string-tcp

5743-0

PeerCast Buffer Overflow

string-tcp

5744-0

IMAP Login DoS

string-tcp

5745-0

FTP REST command

string-tcp

5746-0

FTP ALLO command

string-tcp

5747-1

MDAC Function Remote Code Execution

string-tcp

5747-2

MDAC Function Remote Code Execution

string-tcp

5748-1

Non-SMTP Session Start

string-tcp

5748-2

Non-SMTP Session Start

string-tcp

5748-3

Non-SMTP Session Start

string-tcp

5748-4

Non-SMTP Session Start

string-tcp

5748-5

Non-SMTP Session Start

string-tcp

5749-0

Internet Explorer Double Byte Character Parsing

string-tcp

5750-0

WLSE Cross Site Scripting

service-http

5752-0

Sybase EAServer Overflow

service-http

5753-0

Office Mailto Handler Vulnerability

string-tcp

5754-0

PAJAX Remote Code Execution Vulnerability

service-http

5756-0

Embedded TCP Connection Relay

service-http

5757-0

Microsoft Exchange Server Cross-Site Scripting

state

5759-0

VNC Authentication Bypass

string-tcp

5759-1

VNC Authentication Bypass

string-tcp

5760-0

Novell GroupWise Messenger Accept-Language Value Overflow

service-http

5761-0

Ultr@VNC Server Overflow

service-http

5763-0

Wireless Control System Cross Server Site Scripting

service-http

5764-0

ShixxNOTE Font Buffer Overflow

string-tcp

5765-0

Horde Help Viewer Remote Code Execution

service-http

5766-0

DNS Resolution Response Code Execution

atomic-ip

5768-0

Warez Activity

service-http

5769-0

Malformed HTTP Request

string-tcp

5769-1

Malformed HTTP Request

string-tcp

5770-0

Cisco Secure ACS XSS

service-http

5771-0

Winny Activity

service-http

5772-0

ASP.NET Information Disclosure Vulnerability

service-http

5773-0

Simple PHP Blog Unauthorized File Access

service-http

5773-1

Simple PHP Blog Unauthorized File Access

service-http

5774-0

Windows Media Player PNG Processing Remote Code Execution

string-tcp

5775-0

MHTML Redirection

string-tcp

5775-1

MHTML Redirection

string-tcp

5776-1

Routing and Remote Access Service Code Execution

string-tcp

5776-3

Routing and Remote Access Service Code Execution

string-tcp

5777-0

Mozilla Favicon Code Execution

string-tcp

5778-0

Windows Uplddrvinfo.htm File Deletion Vulnerability

string-tcp

5779-0

ICCP COTP Connection Request

string-tcp

5780-0

ICCP COTP Connection Established

string-tcp

5781-0

ICCP Client Association

string-tcp

5782-0

ICCP MMS Write Request Attempt

string-tcp

5783-0

ICCP MMS Write Request Succeeded

string-tcp

5784-0

ICCP COTP Address Unknown Disconnect

string-tcp

5785-0

ICCP COTP Protocol Error Disconnect

string-tcp

5786-0

ICCP Invalid OSI SSEL

string-tcp

5787-0

ICCP Invalid OSI PSEL

string-tcp

5788-0

ICCP Invalid TPKT Protocol

string-tcp

5789-0

HTTP Tunnel Client Activity

service-http

5790-0

CS-MARS JBoss Vulnerability

service-http

5792-0

Excel Hyperlink Object Library Buffer Overflow

string-tcp

5793-0

SMB Server Driver Remote Execution

string-tcp

5794-1

Routing and Remote Access Service RASMAN Registry Stack Overflow

string-tcp

5794-2

Routing and Remote Access Service RASMAN Registry Stack Overflow

string-tcp

5795-0

DHCP Option Overflow Code Execution

multi-string

5796-0

Cisco IOS HTTP Unauthorized Command Execution

string-tcp

5797-1

Exchange Calendar DoS

string-tcp

5797-2

Exchange Calendar DoS

string-tcp

5797-3

Exchange Calendar DoS

string-tcp

5798-0

Mambo PHP sbp File Inclusion Vulnerability

service-http

5799-1

Server Service Code Execution

string-tcp

5799-2

Server Service Code Execution

string-tcp

5799-3

Server Service Code Execution

string-tcp

5799-5

Server Service Code Execution

string-tcp

5799-6

Server Service Code Execution

string-tcp

5800-0

HTTP Large Content-Type

string-tcp

5801-0

Quicktime JPEG Code Execution Overflow

string-tcp

5801-1

Quicktime JPEG Code Execution Overflow

multi-string

5802-0

MHTML URI Buffer Overflow

string-tcp

5803-0

Sygate Login Servlet SQL Injection

service-http

5804-1

VPN3000 Concentrator Unauthenticated FTP Access

string-tcp

5804-2

VPN3000 Concentrator Unauthenticated FTP Access

string-tcp

5805-1

VPN3000 Concentrator FTP RMD Execution

string-tcp

5807-0

Indexing Service Cross Site Scripting Vulnerability

service-http

5810-0

SecureCRT SSH1 Buffer Overflow

string-tcp

5813-1

Microsoft Internet Explorer Vector Markup Language Vulnerability

string-tcp

5813-2

Microsoft Internet Explorer Vector Markup Language Vulnerability

string-tcp

5813-3

Microsoft Internet Explorer Vector Markup Language Vulnerability

string-tcp

5813-4

Microsoft Internet Explorer Vector Markup Language Vulnerability

string-tcp

5814-1

Step-by-Step Interactive Training Remote Code Execution

string-tcp

5814-2

Step-by-Step Interactive Training Remote Code Execution

string-tcp

5815-1

WebViewFolderIcon setSlice() Overflow

string-tcp

5815-2

WebViewFolderIcon setSlice() Overflow

string-tcp

5816-0

TOR Client Activity

service-http

5817-0

ASP .NET Cross Site Scripting

string-tcp

5818-0

Metasploit Shellcode Encoder

string-tcp

5818-1

Metasploit Shellcode Encoder

string-tcp

5818-2

Metasploit Shellcode Encoder

string-tcp

5818-3

Metasploit Shellcode Encoder

string-tcp

5818-4

Metasploit Shellcode Encoder

string-tcp

5818-5

Metasploit Shellcode Encoder

string-tcp

5818-6

Metasploit Shellcode Encoder

string-tcp

5818-7

Metasploit Shellcode Encoder

string-tcp

5818-8

Metasploit Shellcode Encoder

string-tcp

5818-9

Metasploit Shellcode Encoder

string-tcp

5818-10

Metasploit Shellcode Encoder

string-tcp

5818-11

Metasploit Shellcode Encoder

string-tcp

5819-0

Long FTP XCRC/XSHA1/XMD5 Command

string-tcp

5820-0

Symantec AntiVirus and Client Security Buffer Overflow

string-tcp

5821-1

DirectAnimation ActiveX Memory Corruption

string-tcp

5821-2

DirectAnimation ActiveX Memory Corruption

string-tcp

5822-1

Workstation Service Memory Corruption Vulnerability

string-tcp

5822-2

Workstation Service Memory Corruption Vulnerability

string-tcp

5823-0

McAfee Epolicy Overflow

service-http

5824-0

HTTP Header DoS

string-tcp

5825-0

SIP Malformed Invite Packet

atomic-ip

5826-0

EIQ ESA Topology Delete Device Overflow

string-tcp

5827-1

Internet Explorer ActiveX Control Arbitrary Code Execution

string-tcp

5827-2

Internet Explorer ActiveX Control Arbitrary Code Execution

string-tcp

5828-0

Apache Server Side Cross Site Scripting

service-http

5830-0

Cisco Secure Access Control Server HTTP Request Overflow

service-http

5831-0

Cisco Secure Access Control Server RADIUS Accounting Request Vulnerability

atomic-ip

5833-0

Quicktime RTSP URL Vulnerability

string-tcp

5835-0

Cisco IOS SIP DoS Vulnerability

atomic-ip

5835-1

Cisco IOS SIP DoS Vulnerability

atomic-ip

5835-3

Cisco IOS SIP DoS Vulnerability

atomic-ip

5835-4

Cisco IOS SIP DoS Vulnerability

atomic-ip

5835-6

Cisco IOS SIP DoS Vulnerability

atomic-ip

5835-7

Cisco IOS SIP DoS Vulnerability

atomic-ip

5839-0

Internet Explorer FTP Server Response Code Execution

string-tcp

5840-0

Internet Explorer CLSID Code Execution

string-tcp

5840-1

Internet Explorer CLSID Code Execution

string-tcp

5840-2

Internet Explorer CLSID Code Execution

string-tcp

5842-0

Solaris Telnet Authentication Bypass

string-tcp

5843-0

CA BrightStor Tape Engine Overflow

service-msrpc

5845-0

Word Memory Corruption Exploit

string-tcp

5846-0

FTP 230 Reply Code

string-tcp

5848-0

Content Management Service Cross-site Scripting

service-http

5849-0

Microsoft Content Management Server Vulnerability

service-http

5850-0

Snort DCE/RPC Preprocessor Vulnerability

atomic-ip

5851-0

WCS Administrative Directory Access

service-http

5852-0

Word Malformed String Vulnerability

string-tcp

5853-0

SIP Invite DoS

atomic-ip

5854-1

Cisco CUCM/CUPS Denial of Service Vulnerability

string-tcp

5855-0

Helix Remote Code Execution

string-tcp

5856-1

Agent URL Parsing Remote Code Execution

string-tcp

5856-2

Agent URL Parsing Remote Code Execution

string-tcp

5857-1

UPnP Memory Corruption Vulnerability

string-tcp

5857-2

UPnP Memory Corruption Vulnerability

string-tcp

5858-0

DNS Server RPC Interface Buffer Overflow

service-msrpc

5858-2

DNS Server RPC Interface Buffer Overflow

string-tcp

5858-3

DNS Server RPC Interface Buffer Overflow

string-tcp

5858-4

DNS Server RPC Interface Buffer Overflow

atomic-ip

5860-1

IOS FTPd Successful Login

string-tcp

5861-0

Cisco CNS Netflow Collection Engine Default Password

service-http

5861-1

Cisco CNS Netflow Collection Engine Default Password

string-tcp

5862-0

Outlook Web Access UTF Character Script Execution

multi-string

5863-1

Internet Explorer CAPICOM.Certificates Remote Code Execution

string-tcp

5863-2

Internet Explorer CAPICOM.Certificates Remote Code Execution

string-tcp

5864-0

Exchange Server IMAP Literal Processing Vulnerability

string-tcp

5865-1

Microsoft WMS Arbitrary File Rewrite Vulnerability

string-tcp

5865-2

Microsoft WMS Arbitrary File Rewrite Vulnerability

string-tcp

5866-0

IBM Lotus Domino IMAP CRAM-MD5 Overflow

string-tcp

5868-0

IE Navigation Cancel Page Spoofing Vulnerability

string-tcp

5869-0

Internet Explorer CSS Tag Memory Corruption

string-tcp

5870-0

Win32 API Vulnerability

string-tcp

5871-0

Urlmon.dll COM Object Instantiation

string-tcp

5873-0

Microsoft Speech API 4 ActiveX Overflow

string-tcp

5874-0

Microsoft Speech API 4 ActiveX Overflow

string-tcp

5876-0

WinZip ActiveX Control Instantiation

string-tcp

5877-0

IE Protocol Handler Command Execution

string-tcp

6004-0

IOS HTTP Server Iframe Command Injection

string-tcp

6005-0

Unencrypted SSL Traffic

service-http

6007-0

Management Console Cross-Site Scripting

string-tcp

6008-0

First 4 Internet XCP Uninstallation ActiveX Control

string-tcp

6009-0

SYN Flood DOS

atomic-ip

6011-0

Internet Explorer FTP Command Injection

string-tcp

6012-0

EIQ License Buffer Overflow

string-tcp

6013-0

IRCBOT_JK DNS Lookup

string-udp

6013-1

IRCBOT_JK DNS Lookup

atomic-ip

6050-0

DNS HINFO Request

service-dns

6050-1

DNS HINFO Request

service-dns

6051-0

DNS Zone Transfer

service-dns

6051-1

DNS Zone Transfer

service-dns

6052-0

DNS Zone Transfer from High Port

service-dns

6052-1

DNS Zone Transfer from High Port

service-dns

6053-0

DNS Request for All Records

service-dns

6053-1

DNS Request for All Records

service-dns

6054-0

DNS Version Request

service-dns

6054-1

DNS Version Request

service-dns

6055-0

DNS Inverse Query Buffer Overflow

service-dns

6055-1

DNS Inverse Query Buffer Overflow

service-dns

6055-2

DNS Inverse Query Buffer Overflow

service-dns

6056-0

DNS NXT Buffer Overflow

service-dns

6056-1

DNS NXT Buffer Overflow

service-dns

6056-2

DNS NXT Buffer Overflow

service-dns

6057-0

DNS SIG Buffer Overflow

service-dns

6057-1

DNS SIG Buffer Overflow

service-dns

6057-2

DNS SIG Buffer Overflow

service-dns

6058-0

DNS SRV DoS

service-dns

6058-1

DNS SRV DoS

service-dns

6059-0

DNS TSIG Overflow

service-dns

6059-1

DNS TSIG Overflow

service-dns

6059-2

DNS TSIG Overflow

service-dns

6060-0

DNS Complain Overflow

service-dns

6060-1

DNS Complain Overflow

service-dns

6060-2

DNS Complain Overflow

service-dns

6060-3

DNS Complain Overflow

service-dns

6061-0

DNS Infoleak

service-dns

6061-1

DNS Infoleak

service-dns

6062-0

DNS Authors Request

service-dns

6062-1

DNS Authors Request

service-dns

6063-0

DNS Incremental Zone Transfer

service-dns

6063-1

DNS Incremental Zone Transfer

service-dns

6064-0

BIND Large OPT Record DoS

service-dns

6065-0

DNS Query Name Loop DoS

service-dns

6066-0

DNS Tunneling

service-dns

6067-0

DNS TSIG Bugtraq Overflow

atomic-ip

6100-0

RPC Port Registration

service-rpc

6100-1

RPC Port Registration

service-rpc

6101-0

RPC Port Unregistration

service-rpc

6101-1

RPC Port Unregistration

service-rpc

6102-0

RPC Dump

service-rpc

6102-1

RPC Dump

service-rpc

6103-0

Proxied RPC Request

service-rpc

6103-1

Proxied RPC Request

service-rpc

6104-0

RPC Port Reg Spoof

service-rpc

6104-1

RPC Port Reg Spoof

service-rpc

6105-0

RPC Port UnReg Spoof

service-rpc

6105-1

RPC Port UnReg Spoof

service-rpc

6120-0

RPC RSTATD Request

service-rpc

6120-1

RPC RSTATD Request

service-rpc

6121-0

RPC RUSESRD Request

service-rpc

6121-1

RPC RUSESRD Request

service-rpc

6122-0

RPC NFS Request

service-rpc

6122-1

RPC NFS Request

service-rpc

6123-0

RPC MOUNTD Request

service-rpc

6123-1

RPC MOUNTD Request

service-rpc

6124-0

RPC YPASSWDD Request

service-rpc

6124-1

RPC YPASSWDD Request

service-rpc

6125-0

RPC SELECTION SVC Request

service-rpc

6125-1

RPC SELECTION SVC Request

service-rpc

6126-0

RPC REXD Request

service-rpc

6126-1

RPC REXD Request

service-rpc

6127-0

RPC STATUS Request

service-rpc

6127-1

RPC STATUS Request

service-rpc

6128-0

RPC TTDB Request

service-rpc

6128-1

RPC TTDB Request

service-rpc

6130-0

Microsoft Message Queuing Overflow

service-msrpc

6130-1

Microsoft Message Queuing Overflow

string-tcp

6130-2

Microsoft Message Queuing Overflow

string-tcp

6130-4

Microsoft Message Queuing Overflow

string-tcp

6130-6

Microsoft Message Queuing Overflow

service-msrpc

6130-7

Microsoft Message Queuing Overflow

string-tcp

6130-8

Microsoft Message Queuing Overflow

string-tcp

6130-10

Microsoft Message Queuing Overflow

string-tcp

6131-0

Microsoft Plug and Play Overflow

string-tcp

6131-1

Microsoft Plug and Play Overflow

string-tcp

6131-6

Microsoft Plug and Play Overflow

string-tcp

6150-0

ypserv Portmap Request

service-rpc

6150-1

ypserv Portmap Request

service-rpc

6151-0

ypbind Portmap Request

service-rpc

6151-1

ypbind Portmap Request

service-rpc

6152-0

yppasswdd Portmap Request

service-rpc

6152-1

yppasswdd Portmap Request

service-rpc

6153-0

ypupdated Portmap Request

service-rpc

6153-1

ypupdated Portmap Request

service-rpc

6154-0

ypxfrd Portmap Request

service-rpc

6154-1

ypxfrd Portmap Request

service-rpc

6155-0

mountd Portmap Request

service-rpc

6155-1

mountd Portmap Request

service-rpc

6175-0

rexd Portmap Request

service-rpc

6175-1

rexd Portmap Request

service-rpc

6180-0

rexd Attempt

service-rpc

6180-1

rexd Attempt

service-rpc

6188-0

statd dot dot

service-rpc

6189-0

statd automount attack

service-rpc

6189-1

statd automount attack

service-rpc

6190-0

statd Buffer Overflow

service-rpc

6190-1

statd Buffer Overflow

service-rpc

6191-0

RPC.tooltalk Buffer Overflow

service-rpc

6191-1

RPC.tooltalk Buffer Overflow

service-rpc

6192-0

RPC mountd Buffer Overflow

service-rpc

6192-1

RPC mountd Buffer Overflow

service-rpc

6193-0

RPC CMSD Buffer Overflow

service-rpc

6193-1

RPC CMSD Buffer Overflow

service-rpc

6194-0

sadmind Buffer Overflow

service-rpc

6194-1

sadmind Buffer Overflow

service-rpc

6195-0

Sadmind RPC Buffer Overflow

service-rpc

6195-1

Sadmind RPC Buffer Overflow

service-rpc

6196-0

snmpXdmid Buffer Overflow

service-rpc

6196-1

snmpXdmid Buffer Overflow

service-rpc

6197-0

rpc yppaswdd overflow

service-rpc

6197-1

rpc yppaswdd overflow

service-rpc

6198-0

Long rwalld Message

service-rpc

6198-1

Long rwalld Message

service-rpc

6199-0

Cachefsd Overflow

service-rpc

6199-1

Cachefsd Overflow

service-rpc

6203-0

sadmind directory traversal command exec

string-udp

6203-1

sadmind directory traversal command exec

atomic-ip

6210-0

LPR Format String Overflow

state

6211-0

LPD NoOp Sled

string-tcp

6232-0

Distributed Transaction Coordinator Overflow

service-msrpc

6251-0

Telnet Authorization Failure

string-tcp

6252-0

Rlogin Authorization Failure

string-tcp

6256-0

HTTP Authorization Failure

atomic-ip

6275-0

SGI fam Attempt

service-rpc

6275-1

SGI fam Attempt

service-rpc

6276-0

TooltalkDB overflow

service-rpc

6276-1

TooltalkDB overflow

service-rpc

6277-0

Show Mount Recon

service-rpc

6277-1

Show Mount Recon

service-rpc

6303-0

PingTunnel ICMP Tunneling

string-icmp

6350-0

MS-SQL Query Abuse

string-tcp

6500-0

RingZero Trojan

service-http

6500-1

RingZero Trojan

service-http

6505-0

Trinoo Client Request

string-udp

6505-1

Trinoo Client Request

atomic-ip

6506-0

Trinoo Server Reply

string-udp

6506-1

Trinoo Server Reply

atomic-ip

6508-0

Mstream Control Traffic

string-tcp

6508-1

Mstream Control Traffic

string-udp

6508-2

Mstream Control Traffic

atomic-ip

6921-0

Microsoft Word Code Execution

string-tcp

Moving your apps to Amazon or Miscrosoft Clouds?

We can help you analyze your existing infrastructure, identify the cost savings we can achieve by migrating to a cloud provider. We can then execute end-to-end migration plan of your infrastructure and bringing down your TCO.

Cloud Computing

Ready for IPv6 Migration?

The Internet is running out of the equivalent of phone numbers - familiar problem, non-trivial solution.

The world has to move to IPv6, with its 128-bit addresses. But that's easier said than done.

IPv6 Migration

Are you fluent in "Linux"?

Learn Linux from a leading expert and quickly master you Linux skills.

Learn how to simplify your workflow and increase your productivity using tips and techniques of the pros.

Ideal training for Corporate IT Beginners and Advanced IT Admins alike.

Corporate Linux Training

Who's Online

We have 3 guests and no members online