It would appear that the default check of version length is a bit
restrictive. We are seeing hundreds of these
Russell
| META |
| SID |
CID |
TimeStamp |
Signature |
Sig ID |
| 6 |
9399487 |
2007-09-19 21:31:11 |
ssh: Server version string overflow |
3 |
| Sensor Hostname |
Sensor Interface |
| monitor-dmzo.isec.auckland.ac.nz |
dmz sensor |
|
| IP |
| Source Address |
Dest Address |
Ver |
Hdr Len |
TOS |
length |
ID |
flags |
offset |
TTL |
chksum |
| 203.173.187.229 |
130.216.34.38 |
4 |
5 |
0 |
84 |
31441 |
2 |
0 |
119 |
23617 |
| Resolved Source |
Resolved Dest |
| 203-173-187-229.dsl.dyn.ihug.co.nz |
wintermute01.cs.auckland.ac.nz |
|
| TCP |
| Source Port |
Dest Port |
Seq |
Ack |
Offset |
Reserved |
Flags |
Window |
Checksum |
Urgent Ptr |
| 2380 |
22 |
461434002 |
3476635556 |
5 |
0 |
24 |
65497 |
22946 |
0 |
| Flags |
|
| RB 1 |
RB 0 |
URG |
ACK |
PSH |
RST |
SYN |
FIN |
|
|
|
X |
X |
|
|
|
|
| DATA |
5353482D312E39392D33
2E322E39205353482053
6563757265205368656C
6C20666F722057696E64
6F77730A
|
SSH-1.99-3
.2.9 SSH S
ecure Shel
l for Wind
ows.
|
|
|
-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs