I am seeing lots of hits on this sig, presumably FPs. Lots more packet
contents if anyone wants themm.
| META |
| SID |
CID |
TimeStamp |
Signature |
Sig ID |
| 1 |
869618 |
2007-09-25 10:21:46 |
WEB-MISC Apache SSI error page cross-site scripting |
11687 |
| Sensor Hostname |
Sensor Interface |
| monitor-itss.insec.auckland.ac.nz |
ITSS sector switch |
|
| IP |
| Source Address |
Dest Address |
Ver |
Hdr Len |
TOS |
length |
ID |
flags |
offset |
TTL |
chksum |
| 130.216.204.57 |
130.216.33.111 |
4 |
5 |
0 |
1500 |
19070 |
2 |
0 |
63 |
63556 |
| Resolved Source |
Resolved Dest |
| t721-120-57.sfac.auckland.ac.nz |
dist.ec.auckland.ac.nz |
|
| TCP |
| Source Port |
Dest Port |
Seq |
Ack |
Offset |
Reserved |
Flags |
Window |
Checksum |
Urgent Ptr |
| 50073 |
80 |
198268277 |
3456460802 |
8 |
0 |
16 |
2003 |
52439 |
0 |
| Flags |
|
| RB 1 |
RB 0 |
URG |
ACK |
PSH |
RST |
SYN |
FIN |
|
|
|
X |
|
|
|
|
|
| DATA |
GET /apt/ubuntu/dists/feisty/main/binary-i386/Packages.bz2 H
TTP/1.1..Host: dist.ec.auckland.ac.nz..Connection: keep-aliv
e..If-Modified-Since: Tue, 17 Apr 2007 18:10:27 GMT..User-Ag
ent: Ubuntu APT-HTTP/1.3 (0.6.46.4ubuntu10)....GET /apt/ubun
tu/dists/feisty/restricted/binary-i386/Packages.bz2 HTTP/1.1
..Host: dist.ec.auckland.ac.nz..Connection: keep-alive..If-M
odified-Since: Tue, 17 Apr 2007 18:10:27 GMT..User-Agent: Ub
untu APT-HTTP/1.3 (0.6.46.4ubuntu10)....GET /apt/ubuntu/dist
s/feisty/universe/binary-i386/Packages.bz2 HTTP/1.1..Host: d
ist.ec.auckland.ac.nz..Connection: keep-alive..If-Modified-S
ince: Tue, 17 Apr 2007 18:11:07 GMT..User-Agent: Ubuntu APT-
HTTP/1.3 (0.6.46.4ubuntu10)....GET /apt/ubuntu/dists/feisty/
multiverse/binary-i386/Packages.bz2 HTTP/1.1..Host: dist.ec.
auckland.ac.nz..Connection: keep-alive..If-Modified-Since: T
ue, 17 Apr 2007 18:11:09 GMT..User-Agent: Ubuntu APT-HTTP/1.
3 (0.6.46.4ubuntu10)....GET /apt/ubuntu/dists/feisty/main/so
urce/Sources.bz2 HTTP/1.1..Host: dist.ec.auckland.ac.nz..Con
nection: keep-alive..If-Modified-Since: Tue, 17 Apr 2007 18:
13:13 GMT..User-Agent: Ubuntu APT-HTTP/1.3 (0.6.46.4ubuntu10
)....GET /apt/ubuntu/dists/feisty/restricted/source/Sources.
bz2 HTTP/1.1..Host: dist.ec.auckland.ac.nz..Connection: keep
-alive..If-Modified-Since: Tue, 17 Apr 2007 18:13:14 GMT..Us
er-Agent: Ubuntu APT-HTTP/1.3 (0.6.46.4ubuntu10)....GET /apt
/ubuntu/dists/feisty/universe/source/Sources.bz2 HTTP/1.1..H
ost: dis
|
|
-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs