TMS zl Management and Configuration Guide ST.1.1.100226
6-19
Intrusion Detection and Prevention
Threat Detection and Prevention
■ XSS
• HREF and XML entity XSS injections
• Advanced XSS with script and constructors
■ SQL injection
• Classic SQL injection
• Blind SQL injection attempt
• MySQL SPACE or Keyword injection
■ Virus
•AIM Bot
•BugBear
• Trojan Haxdoor
• VBS.Postcard
•Worm Nyxem
■ Malware
• Spyware Abox
• Hotbar
• Adware Zango site
■ Reconnaissance
• AXIS StorPoint Vulnerability
• FTP—Multiple bad login attempts
• HTTP dangerous PUT method
■ Protocol anomaly (cannot disable)
• Invalid ACK number in SYN+ACK Packet
• DNS message pointer loop vulnerability
■ Traffic info
• Welchia worm
• TFTP GET request from outside
• Attempt to download admin.dll using TFTP
■ Gain access
• ASN.1 buffer overflow attempt
• CA BrightStor ARCServ Backup LGServer Arbitrary File Upload
• DNS Bind exploit named 8.2->8.2.1 vulnerability
■ Exploit
• MS-SQL Shellcode attempt
• Access to vulnerable CGI Count.cgi
• Chameleon SMTP buffer overflow