Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Network Intrusion Detection, Third Edition.pdf
Скачиваний:
213
Добавлен:
15.03.2015
Размер:
2.58 Mб
Скачать

prober - - [11/Dec/1998:15:28:26 -0500] "GET /cgi-bin/phf/ HTTP/1.0" 404 165 prober - - [11/Dec/1998:15:28:26 -0500] "GET /cgi-bin/php.cgi/ HTTP/1.0" 404 169

prober - - [11/Dec/1998:15:28:26 -0500] "GET /cgi-bin/campas/ HTTP/1.0" 404 168

prober - - [11/Dec/1998:15:28:26 -0500] "GET /cgi-bin/htmlscript/ HTTP/1.0" 404 172

prober - - [11/Dec/1998:15:28:27 -0500] "GET /cgi-bin/aglimpse/ HTTP/1.0" 404 170

prober - - [11/Dec/1998:15:28:27 -0500] "GET /cgi-bin/websendmail/ HTTP/1.0" 404 173

prober - - [11/Dec/1998:15:28:27 -0500] "GET /cgi-bin/view-source/ HTTP/1.0" 404 173

prober - - [11/Dec/1998:15:28:27 -0500] "GET /cgi-bin/handler/ HTTP/1.0" 404 169

prober - - [11/Dec/1998:15:28:28 -0500] "GET /cgi-bin/webdist.cgi/ HTTP/1.0" 404 173

prober - - [11/Dec/1998:15:28:28 -0500] "GET /cgi-bin/pfdispaly.cgi/ HTTP/1.0" 404 175

prober - - [11/Dec/1998:15:29:50 -0500] "GET /cgi-bin/phf/ HTTP/1.0" 404 165 prober - - [11/Dec/1998:15:29:51 -0500] "GET /cgi-bin/php.cgi/ HTTP/1.0" 404 169

prober - - [11/Dec/1998:15:29:51 -0500] "GET /cgi-bin/campas/ HTTP/1.0" 404 168

prober - - [11/Dec/1998:15:29:51 -0500] "GET /cgi-bin/htmlscript/ HTTP/1.0" 404 172

prober - - [11/Dec/1998:15:29:52 -0500] "GET /cgi-bin/aglimpse/ HTTP/1.0" 404 170

prober - - [11/Dec/1998:15:29:52 -0500] "GET /cgi-bin/websendmail/ HTTP/1.0" 404 173

prober - - [11/Dec/1998:15:29:52 -0500] "GET /cgi-bin/view-source/ HTTP/1.0" 404 173

prober - - [11/Dec/1998:15:29:52 -0500] "GET /cgi-bin/handler/ HTTP/1.0" 404 169

prober - - [11/Dec/1998:15:29:53 -0500] "GET /cgi-bin/webdist.cgi/ HTTP/1.0" 404 173

prober - - [11/Dec/1998:15:29:53 -0500] "GET /cgi-bin/pfdispaly.cgi/ HTTP/1.0" 404 175

IP-Proto-191

To the very best of my understanding, this cannot be an exploit and probably isn't an immediate prelude to one. I wanted to include it, however, because IP protocol types that are not TCP, UDP, or ICMP are not that uncommon as scans.

What is ip-proto-191? Durned if I know. An 8-bit protocol field in the IP header was set to 191:

00:32:28.164183 prober > 192.168.0.255: ip-proto-191 48 00:32:28.164663 192.168.4.5 > prober: icmp:192.168.0.255 unreach 00:32:30.192825 prober > 192.168.1.255: ip-proto-191 48 00:32:33.203521 prober > 192.168.2.255: ip-proto-191 48 00:32:36.219821 prober > 192.168.3.255: ip-proto-191 48 00:32:36.220302 192.168.4.5 > prober: icmp:192.168.3.255 unreach 00:32:38.243973 prober > 255.255.255.255: ip-proto-191 48 00:32:41.254622 prober > 192.168.5.255: ip-proto-191 48 00:32:44.262961 prober > 192.168.6.255: ip-proto-191 48 00:32:47.276258 prober > 192.168.7.255: ip-proto-191 48 00:32:50.285609 prober > 192.168.8.255: ip-proto-191 48

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]