本帖最后由 wjcharles 于 2012-12-7 15:50 编辑
NIS2013 ips拦截,又下载不到LZ发的样本了
类别: 入侵防护
日期和时间,风险,活动,状态,推荐的操作,IPS 警报名称,默认操作,采取的操作,攻击电脑,攻击者网址,目标地址,源地址,通信说明,类别
2012/12/7 15:13:42,高,阻止了 littleknobnsack.us 的入侵企图,已阻止,不需要操作,Web Attack: JRE Concurrency CVE-2012-0507,不需要操作,不需要操作,"littleknobnsack.us (37.221.170.88, 80)",littleknobnsack.us/data/1.jar,"-PC (..97.14, 5166)",37.221.170.88 (37.221.170.88),"TCP, www-http",
2012/12/7 15:13:42,信息,“入侵防护签名自动阻止”已阻止 IP 地址 37.221.170.88 的时间为 30 分钟,已检测,不需要操作,,不需要操作,不需要操作,,,,,,入侵防护
2012/12/7 15:13:42,高,阻止了 -PC 的入侵企图,已阻止,不需要操作,Web Attack: JRE Concurrency CVE-2012-0507 6,不需要操作,不需要操作,"-PC (..97.14, 5166)",littleknobnsack.us/data/1.jar,"littleknobnsack.us (37.221.170.88, 80)",..97.14 (..97.14),"TCP, 端口 5166",
2012/12/7 15:13:42,高,阻止了 littleknobnsack.us 的入侵企图,已阻止,不需要操作,Web Attack: Malicious JAR Download CVE-2012-4681 3,不需要操作,不需要操作,"littleknobnsack.us (37.221.170.88, 80)",littleknobnsack.us/data/jre.jar,"-PC (..97.14, 5164)",37.221.170.88 (37.221.170.88),"TCP, www-http",
|