Security Basics mailing list archives

TippingPoint IPS SQL injections?


From: erika_cissp () yaho com
Date: 13 May 2008 12:34:54 -0000

Any ideas as to what they are attempting to do in the logs below? 

9 0474: MS-SQL/SMB: sp_OACreate Program Execution Major 4 10.1.4.x 10.1.4.x Permit

10 0472:MS-SQL/SMB: sp_password Password Change Major 4 0.1.4.x 10.1.4.x Permit

22 0460: MS-SQL/SMB: raiserror Access 
Major 2 10.1.4.x 10.1.4.x Permit

These are the only "permits" I have seen; they are always "blocked". 

Typical "normal" log entry:

23 3885: HTTP: PHP File Include Exploit 
Critical 2 80.93.207.x 10.1.4.x Block

Any insight would be greatly appreciated.


Current thread: