Hi Reinhold,
I just created a alert report for Snort Acid, but the lines are a bit confusing to me, cant figure out what the lines mean, maybe you (or someone else) can clear things up for me?
This is the report I have, the IP adress 000.000.000.000 is my External IP adress on eth1
Generated by ACID v0.9.6b23 on Sun, 11 Sep 2005 15:10:40 +0200
#1-1| [2005-09-11 12:40:03] 000.000.000.000:1264 -> 80.200.153.61:80 [bugtraq/9879] [snort/2565] WEB-PHP modules.php access
#1-2| [2005-09-11 12:40:06] 000.000.000.000:1264 -> 80.200.153.61:80 [bugtraq/9879] [snort/2565] WEB-PHP modules.php access
#1-3| [2005-09-11 12:40:12] 000.000.000.000:1264 -> 80.200.153.61:80 [bugtraq/9879] [snort/2565] WEB-PHP modules.php access
#1-4| [2005-09-11 12:40:14] 000.000.000.000:1264 -> 80.200.153.61:80 [bugtraq/9879] [snort/2565] WEB-PHP modules.php access
#1-5| [2005-09-11 12:40:51] 000.000.000.000:1266 -> 80.200.153.61:80 [bugtraq/9879] [snort/2565] WEB-PHP modules.php access
#1-6| [2005-09-11 12:44:20] 000.000.000.000:1325 -> 207.68.177.124:80 [snort/2] (http_inspect) DOUBLE DECODING ATTACK
#1-7| [2005-09-11 12:47:46] 000.000.000.000:1334 -> 195.154.195.154:80 [bugtraq/2527] [snort/1054] WEB-MISC weblogic/tomcat .jsp view source attempt
#1-8| [2005-09-11 12:48:44] 222.179.217.131:1958 -> 000.000.000.000:1434 urlnessus[cve/2002-0649] [icat/2002-0649] [bugtraq/5311] [bugtraq/5310] [snort/2004] MS-SQL Worm propagation attempt OUTBOUND
#1-9| [2005-09-11 13:05:39] 000.000.000.000:1342 -> 216.17.211.37:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-10| [2005-09-11 13:05:42] 000.000.000.000:1343 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-11| [2005-09-11 13:05:53] 000.000.000.000:1343 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-12| [2005-09-11 13:06:16] 000.000.000.000:1345 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-13| [2005-09-11 13:06:24] 000.000.000.000:1345 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-14| [2005-09-11 13:06:40] 000.000.000.000:1351 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-15| [2005-09-11 13:08:29] 000.000.000.000:1354 -> 216.17.211.37:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-16| [2005-09-11 13:08:33] 000.000.000.000:1355 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-17| [2005-09-11 13:36:53] 218.75.30.34:1033 -> 000.000.000.000:1434 urlnessus[cve/2002-0649] [icat/2002-0649] [bugtraq/5311] [bugtraq/5310] [snort/2004] MS-SQL Worm propagation attempt OUTBOUND
#1-18| [2005-09-11 14:38:08] 222.178.5.234:2066 -> 000.000.000.000:1434 urlnessus[cve/2002-0649] [icat/2002-0649] [bugtraq/5311] [bugtraq/5310] [snort/2004] MS-SQL Worm propagation attempt OUTBOUND
#1-19| [2005-09-11 14:57:17] 000.000.000.000:1515 -> 216.17.211.37:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-20| [2005-09-11 14:57:19] 000.000.000.000:1517 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-21| [2005-09-11 14:57:34] 000.000.000.000:1525 -> 216.17.211.37:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-22| [2005-09-11 14:57:36] 000.000.000.000:1526 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-23| [2005-09-11 15:00:26] 000.000.000.000:1583 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-24| [2005-09-11 15:00:43] 000.000.000.000:1583 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-25| [2005-09-11 15:00:55] 000.000.000.000:1583 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-26| [2005-09-11 15:01:37] 000.000.000.000:1587 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-27| [2005-09-11 15:07:01] 000.000.000.000:1593 -> 216.17.211.37:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
#1-28| [2005-09-11 15:07:04] 000.000.000.000:1594 -> 216.17.211.20:80 nessus[cve/2003-0486] [icat/2003-0486] [bugtraq/7979] [snort/2229] WEB-PHP viewtopic.php access
Regards,
Molski