Changes between Version 48 and Version 49 of icasIII


Ignore:
Timestamp:
Aug 12, 2011, 9:32:14 AM (13 years ago)
Author:
waue
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • icasIII

    v48 v49  
    302302#!html
    303303
    304 Attack List
    305 
    306 src ip   dst ip  prio    time range      detail  ids     count   dst port list
    307 140.110.114.141 74.125.71.103   1       20110812_085900~20110812_085900 WORM Conficker on HTTP Search   nk7admin        1       80
    308 140.110.114.141 74.125.71.104   1       20110812_085900~20110812_085900 WORM Conficker on HTTP Search   nk7admin        1       80
    309 140.110.116.253 74.125.153.100  1       20110812_085700~20110812_085800 WORM Conficker on HTTP Search   nk7admin        9       80
    310 140.110.134.253 224.0.0.13      2       20110812_081507~20110812_091438 BAD-TRAFFIC IP Proto 103 PIM    snort   122     0
    311 199.93.56.125   140.110.112.4   1       20110812_080600~20110812_080600 EXPLOIT RealNetworks RealPlayer FLV Parsing Two integer overflow vulnerabilities        nk7admin        1       60215
    312 199.93.56.125   140.110.114.136 1       20110812_084500~20110812_084500 EXPLOIT RealNetworks RealPlayer FLV Parsing Two integer overflow vulnerabilities        nk7admin        1       49221
    313 199.93.56.125   140.110.116.253 1       20110812_083200~20110812_083200 EXPLOIT RealNetworks RealPlayer FLV Parsing Two integer overflow vulnerabilities        nk7admin        1       59570
    314 218.10.246.123  140.110.127.250 1       20110812_081800~20110812_081800 TCP SYN nk7admin        1       1433
    315 61.147.112.50   140.110.112.78  1       20110812_080300~20110812_080300 TCP SYN nk7admin        1       1433
    316 61.147.112.50   140.110.127.255 1       20110812_080300~20110812_080300 TCP SYN nk7admin        1       1433
    317 67.195.19.74    140.110.117.190 1       20110812_085500~20110812_085500 EXPLOIT Microsoft Color Management Module Buffer Overflow       nk7admin        1       2549
    318 
    319 Graph Show
    320 
    321 
     304<h1> Attack List </h1><table style="width: 100%;" border="1"><tbody><tr style="background-color: rgb(153, 255, 255);"><td> src ip </td><td> dst ip </td><td> prio </td><td> time range </td><td> detail </td><td> ids </td><td> count </td><td> dst port list </td></tr><tr style="vertical-align: top; background-color: rgb(255, 204, 204);"><td>140.110.114.141</td><td>74.125.71.103</td><td>1</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_085900~20110812_<wbr>085900</td><td>WORM Conficker on HTTP Search</td><td>nk7admin</td><td>1</td><td>80</td></tr><tr style="vertical-align: top; background-color: rgb(255, 204, 204);"><td>140.110.114.141</td><td>74.125.71.104</td><td>1</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_085900~20110812_<wbr>085900</td><td>WORM Conficker on HTTP Search</td><td>nk7admin</td><td>1</td><td>80</td></tr><tr style="vertical-align: top; background-color: rgb(255, 204, 204);"><td>140.110.116.253</td><td>74.125.153.100</td><td>1</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_085700~20110812_<wbr>085800</td><td>WORM Conficker on HTTP Search</td><td>nk7admin</td><td>9</td><td>80</td></tr><tr><td>140.110.134.253</td><td>224.0.0.13</td><td>2</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_081507~20110812_<wbr>091438</td><td>BAD-TRAFFIC IP Proto 103 PIM </td><td>snort</td><td>122</td><td>0</td></tr><tr style="vertical-align: top; background-color: rgb(255, 204, 204);"><td>199.93.56.125</td><td>140.110.112.4</td><td>1</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_080600~20110812_<wbr>080600</td><td>EXPLOIT RealNetworks RealPlayer FLV Parsing Two integer overflow vulnerabilities</td><td>nk7admin</td><td>1</td><td>60215</td></tr><tr style="vertical-align: top; background-color: rgb(255, 204, 204);"><td>199.93.56.125</td><td>140.110.114.136</td><td>1</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_084500~20110812_<wbr>084500</td><td>EXPLOIT RealNetworks RealPlayer FLV Parsing Two integer overflow vulnerabilities</td><td>nk7admin</td><td>1</td><td>49221</td></tr><tr style="vertical-align: top; background-color: rgb(255, 204, 204);"><td>199.93.56.125</td><td>140.110.116.253</td><td>1</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_083200~20110812_<wbr>083200</td><td>EXPLOIT RealNetworks RealPlayer FLV Parsing Two integer overflow vulnerabilities</td><td>nk7admin</td><td>1</td><td>59570</td></tr><tr style="vertical-align: top; background-color: rgb(255, 204, 204);"><td>218.10.246.123</td><td>140.110.127.250</td><td>1</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_081800~20110812_<wbr>081800</td><td>TCP SYN</td><td>nk7admin</td><td>1</td><td>1433</td></tr><tr style="vertical-align: top; background-color: rgb(255, 204, 204);"><td>61.147.112.50</td><td>140.110.112.78</td><td>1</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_080300~20110812_<wbr>080300</td><td>TCP SYN</td><td>nk7admin</td><td>1</td><td>1433</td></tr><tr style="vertical-align: top; background-color: rgb(255, 204, 204);"><td>61.147.112.50</td><td>140.110.127.255</td><td>1</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_080300~20110812_<wbr>080300</td><td>TCP SYN</td><td>nk7admin</td><td>1</td><td>1433</td></tr><tr style="vertical-align: top; background-color: rgb(255, 204, 204);"><td><a href="tel:67.195.19.74" value="+886671951974" target="_blank">67.195.19.74</a></td><td>140.110.117.190</td><td>1</td><td><a href="tel:20110812" value="+88620110812" target="_blank">20110812</a>_085500~20110812_<wbr>085500</td><td>EXPLOIT Microsoft Color Management Module Buffer Overflow</td><td>nk7admin</td><td>1</td><td>2549</td></tr></tbody></table> <br> <h1> Graph Show</h1> <img src="?ui=2&amp;ik=29899eb343&amp;view=att&amp;th=131bb8f958f08560&amp;attid=0.1&amp;disp=emb&amp;zw">
    322305
    323306}}}