<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE snort-message-version-0.2>

<file>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="1201" revision="2" priority="2" class="attempted-recon">WEB-MISC 403 Forbidden</signature>
    <timestamp>2002-06-24 10:47:07-05</timestamp>
    <packet>
      <iphdr saddr="64.29.19.233" daddr="68.99.108.41" proto="6" ver="4" hlen="5" len="275" id="6930" ttl="64" csum="6721">
        <tcphdr sport="80" dport="1296" flags="24" seq="2410175922" ack="2418117017" off="5" win="5840" csum="25622">
          <data>485454502F312E312034303320466F7262696464656E0D0A446174653A204D6F6E2C203234204A756E20323030322031343A34373A303720474D540D0A5365727665723A204170616368652F312E332E32332028556E697829206D6F645F73736C2F322E382E37204F70656E53534C2F302E392E362046726F6E74506167652F352E302E322E32363233205048502F342E312E32206D6F645F7468726F74746C652F332E312E320D0A436F6E6E656374696F6E3A20636C6F73650D0A436F6E74656E742D547970653A20746578742F68746D6C3B20636861727365743D69736F2D383835392D310D0A0D0A</data>
        </tcphdr>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:47:07-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64068"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:47:07-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64068"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:47:07-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64067"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:47:07-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64066"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:47:07-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64065"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="1201" revision="2" priority="2" class="attempted-recon">WEB-MISC 403 Forbidden</signature>
    <timestamp>2002-06-24 10:52:12-05</timestamp>
    <packet>
      <iphdr saddr="64.29.19.233" daddr="68.99.108.41" proto="6" ver="4" hlen="5" len="275" id="49004" ttl="64" csum="30182">
        <tcphdr sport="80" dport="1313" flags="24" seq="2737045838" ack="2737971116" off="5" win="5840" csum="1998">
          <data>485454502F312E312034303320466F7262696464656E0D0A446174653A204D6F6E2C203234204A756E20323030322031343A35323A313220474D540D0A5365727665723A204170616368652F312E332E32332028556E697829206D6F645F73736C2F322E382E37204F70656E53534C2F302E392E362046726F6E74506167652F352E302E322E32363233205048502F342E312E32206D6F645F7468726F74746C652F332E312E320D0A436F6E6E656374696F6E3A20636C6F73650D0A436F6E74656E742D547970653A20746578742F68746D6C3B20636861727365743D69736F2D383835392D310D0A0D0A</data>
        </tcphdr>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:52:13-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64068"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:52:13-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64068"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:52:13-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64067"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:52:13-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64066"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:52:13-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64065"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="485" revision="2" priority="3" class="misc-activity">ICMP Destination Unreachable (Communication Administratively Prohibited)</signature>
    <timestamp>2002-06-24 10:56:03-05</timestamp>
    <packet>
      <iphdr saddr="63.209.21.110" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="56" id="20469" ttl="245" csum="52362">
        <icmphdr type="3" code="13" csum="21188">
          <data>000000004500003CDB37400035061308401D13E94223C153C4120071B0E2C339</data>
        </icmphdr>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="1201" revision="2" priority="2" class="attempted-recon">WEB-MISC 403 Forbidden</signature>
    <timestamp>2002-06-24 10:57:08-05</timestamp>
    <packet>
      <iphdr saddr="64.29.19.233" daddr="68.99.108.41" proto="6" ver="4" hlen="5" len="275" id="58610" ttl="64" csum="20576">
        <tcphdr sport="80" dport="1330" flags="24" seq="3049379147" ack="3035548495" off="5" win="5840" csum="23998">
          <data>485454502F312E312034303320466F7262696464656E0D0A446174653A204D6F6E2C203234204A756E20323030322031343A35373A303820474D540D0A5365727665723A204170616368652F312E332E32332028556E697829206D6F645F73736C2F322E382E37204F70656E53534C2F302E392E362046726F6E74506167652F352E302E322E32363233205048502F342E312E32206D6F645F7468726F74746C652F332E312E320D0A436F6E6E656374696F6E3A20636C6F73650D0A436F6E74656E742D547970653A20746578742F68746D6C3B20636861727365743D69736F2D383835392D310D0A0D0A</data>
        </tcphdr>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:57:08-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64068"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:57:09-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64068"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:57:09-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64067"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:57:09-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64066"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 10:57:09-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64065"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="620" revision="1" priority="2" class="attempted-recon">SCAN Proxy attempt</signature>
    <timestamp>2002-06-24 10:59:13-05</timestamp>
    <packet>
      <iphdr saddr="80.116.222.133" daddr="64.65.23.219" proto="6" ver="4" hlen="5" len="48" id="42903" ttl="116" csum="55322">
        <tcphdr sport="2364" dport="8080" flags="2" seq="850735767" ack="0" off="7" win="16384" csum="11769">
          <option code="2" len="4">05AC0101</option>
          <option code="1"/>
          <option code="1"/>
          <option code="4"/>
        </tcphdr>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="1201" revision="2" priority="2" class="attempted-recon">WEB-MISC 403 Forbidden</signature>
    <timestamp>2002-06-24 11:02:09-05</timestamp>
    <packet>
      <iphdr saddr="64.29.19.233" daddr="68.99.108.41" proto="6" ver="4" hlen="5" len="275" id="8283" ttl="64" csum="5368">
        <tcphdr sport="80" dport="1349" flags="24" seq="3365635941" ack="3353020526" off="5" win="5840" csum="19377">
          <data>485454502F312E312034303320466F7262696464656E0D0A446174653A204D6F6E2C203234204A756E20323030322031353A30323A303920474D540D0A5365727665723A204170616368652F312E332E32332028556E697829206D6F645F73736C2F322E382E37204F70656E53534C2F302E392E362046726F6E74506167652F352E302E322E32363233205048502F342E312E32206D6F645F7468726F74746C652F332E312E320D0A436F6E6E656374696F6E3A20636C6F73650D0A436F6E74656E742D547970653A20746578742F68746D6C3B20636861727365743D69736F2D383835392D310D0A0D0A</data>
        </tcphdr>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 11:02:09-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64068"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 11:02:10-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64068"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 11:02:10-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64067"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 11:02:10-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64066"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 11:02:10-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64065"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="498" revision="2" priority="2" class="bad-unknown">ATTACK RESPONSES id check returned root</signature>
    <timestamp>2002-06-24 11:06:37-05</timestamp>
    <packet>
      <iphdr saddr="64.29.19.233" daddr="68.99.108.41" proto="6" ver="4" hlen="5" len="1500" id="31813" ttl="64" csum="46148">
        <tcphdr sport="50352" dport="3306" flags="16" seq="3598559830" ack="3586608353" off="5" win="5840" csum="51035">
          <data>F80A000003494E5345525420494E544F20646D5F72756C65732056414C554553282735272C2741545441434B20524553504F4E534553272C27232052554C455345545F4E414D453D2241545441434B5F524553504F4E5345532E72756C6573222044454C494D495445523D224D4761706379746F574A4B220A232041545441434B20524553504F4E5345530A23205468657365207369676E617475726573206172652074686F7365207768656E20746865792068617070656E2C2069747320757375616C6C7920626563617573652061206D616368696E650A2320686173206265656E20636F6D70726F6D697365642E202054686573652073686F756C64206E6F742066616C73652074686174206F6674656E20616E6420616C6D6F737420616C776179730A23206D65616E206120636F6D70726F6D6973652E0A0A616C657274207463702024485454505F53455256455253203830202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E534553206874747020646972206C697374696E67223B20636F6E74656E743A2022566F6C756D652053657269616C204E756D626572223B20666C6167733A412B3B2020636C617373747970653A6261642D756E6B6E6F776E3B207369643A313239323B207265763A323B290A616C65727420697020616E7920616E79202D3E20616E7920616E7920286D73673A2241545441434B20524553504F4E53455320696420636865636B2072657475726E656420726F6F74223B20636F6E74656E743A20227569643D3028726F6F7429223B20636C617373747970653A6261642D756E6B6E6F776E3B207369643A3439383B207265763A333B290A616C657274207463702024485454505F53455256455253203830202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E53455320636F6D6D616E6420636F6D706C65746564223B20636F6E74656E743A22436F6D6D616E6420636F6D706C65746564223B206E6F636173653B2020666C6167733A412B3B20636C617373747970653A6261642D756E6B6E6F776E3B207369643A3439343B207265763A333B290A616C657274207463702024485454505F53455256455253203830202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E53455320636F6D6D616E64206572726F72223B20636F6E74656E743A2242616420636F6D6D616E64206F722066696C656E616D65223B206E6F636173653B2020666C6167733A412B3B20636C617373747970653A6261642D756E6B6E6F776E3B207369643A3439353B207265763A333B290A23616C657274207463702024485454505F53455256455253203830202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E534553206469726563746F7279206C697374696E67223B20636F6E74656E743A224469726563746F7279206F66223B206E6F636173653B20666C6167733A412B3B2020636C617373747970653A756E6B6E6F776E3B207369643A3439363B207265763A343B290A616C657274207463702024485454505F53455256455253203830202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E5345532066696C6520636F70696564206F6B223B20636F6E74656E743A22312066696C6528732920636F70696564223B206E6F636173653B20666C6167733A412B3B2020636C617373747970653A6261642D756E6B6E6F776E3B207369643A3439373B207265763A333B290A616C657274207463702024485454505F534552564552532038303032202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E534553206F7261636C65206F6E6520686F757220696E7374616C6C223B20666C6167733A412B3B2020636F6E74656E743A224F726163</data>
        </tcphdr>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="498" revision="2" priority="2" class="bad-unknown">ATTACK RESPONSES id check returned root</signature>
    <timestamp>2002-06-24 11:07:06-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="6" ver="4" hlen="5" len="1500" id="10884" ttl="49" csum="5382">
        <tcphdr sport="3306" dport="50367" flags="16" seq="3661424742" ack="3674946622" off="5" win="5840" csum="64047">
          <data>01000001021F00000208646D5F72756C65730B736E6F72745F72756C657303FFFFFF01FC031100001E00000308646D5F72756C65730A72756C65735F747970650364000001FD0301000001000004FED40A0005FCC00A232052554C455345545F4E414D453D2241545441434B5F524553504F4E5345532E72756C6573222044454C494D495445523D224D4761706379746F574A4B220A232041545441434B20524553504F4E5345530A23205468657365207369676E617475726573206172652074686F7365207768656E20746865792068617070656E2C2069747320757375616C6C7920626563617573652061206D616368696E650A2320686173206265656E20636F6D70726F6D697365642E202054686573652073686F756C64206E6F742066616C73652074686174206F6674656E20616E6420616C6D6F737420616C776179730A23206D65616E206120636F6D70726F6D6973652E0A0A616C657274207463702024485454505F53455256455253203830202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E534553206874747020646972206C697374696E67223B20636F6E74656E743A2022566F6C756D652053657269616C204E756D626572223B20666C6167733A412B3B2020636C617373747970653A6261642D756E6B6E6F776E3B207369643A313239323B207265763A323B290A616C65727420697020616E7920616E79202D3E20616E7920616E7920286D73673A2241545441434B20524553504F4E53455320696420636865636B2072657475726E656420726F6F74223B20636F6E74656E743A20227569643D3028726F6F7429223B20636C617373747970653A6261642D756E6B6E6F776E3B207369643A3439383B207265763A333B290A616C657274207463702024485454505F53455256455253203830202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E53455320636F6D6D616E6420636F6D706C65746564223B20636F6E74656E743A22436F6D6D616E6420636F6D706C65746564223B206E6F636173653B2020666C6167733A412B3B20636C617373747970653A6261642D756E6B6E6F776E3B207369643A3439343B207265763A333B290A616C657274207463702024485454505F53455256455253203830202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E53455320636F6D6D616E64206572726F72223B20636F6E74656E743A2242616420636F6D6D616E64206F722066696C656E616D65223B206E6F636173653B2020666C6167733A412B3B20636C617373747970653A6261642D756E6B6E6F776E3B207369643A3439353B207265763A333B290A23616C657274207463702024485454505F53455256455253203830202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E534553206469726563746F7279206C697374696E67223B20636F6E74656E743A224469726563746F7279206F66223B206E6F636173653B20666C6167733A412B3B2020636C617373747970653A756E6B6E6F776E3B207369643A3439363B207265763A343B290A616C657274207463702024485454505F53455256455253203830202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E5345532066696C6520636F70696564206F6B223B20636F6E74656E743A22312066696C6528732920636F70696564223B206E6F636173653B20666C6167733A412B3B2020636C617373747970653A6261642D756E6B6E6F776E3B207369643A3439373B207265763A333B290A616C657274207463702024485454505F534552564552532038303032202D3E202445585445524E414C5F4E455420616E7920286D73673A2241545441434B20524553504F4E534553206F7261636C65206F6E6520686F757220696E737461</data>
        </tcphdr>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="1201" revision="2" priority="2" class="attempted-recon">WEB-MISC 403 Forbidden</signature>
    <timestamp>2002-06-24 11:07:11-05</timestamp>
    <packet>
      <iphdr saddr="64.29.19.233" daddr="68.99.108.41" proto="6" ver="4" hlen="5" len="275" id="8328" ttl="64" csum="5323">
        <tcphdr sport="80" dport="1367" flags="24" seq="3687660935" ack="3662822629" off="5" win="5840" csum="17239">
          <data>485454502F312E312034303320466F7262696464656E0D0A446174653A204D6F6E2C203234204A756E20323030322031353A30373A313120474D540D0A5365727665723A204170616368652F312E332E32332028556E697829206D6F645F73736C2F322E382E37204F70656E53534C2F302E392E362046726F6E74506167652F352E302E322E32363233205048502F342E312E32206D6F645F7468726F74746C652F332E312E320D0A436F6E6E656374696F6E3A20636C6F73650D0A436F6E74656E742D547970653A20746578742F68746D6C3B20636861727365743D69736F2D383835392D310D0A0D0A</data>
        </tcphdr>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 11:07:11-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64068"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 11:07:11-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64068"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 11:07:11-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64067"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 11:07:11-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64066"/>
      </iphdr>
    </packet>
  </event>

  <event version="1.0">
    <sensor encoding="hex" detail="full">
      <interface>eth0</interface>
      <ipaddr version="4">64.29.19.233</ipaddr>
      <hostname>ns1.cyac.net</hostname>
    </sensor>
    <signature id="469" revision="1" priority="2" class="attempted-recon">ICMP PING NMAP</signature>
    <reference system="arachnids">162</reference>
    <timestamp>2002-06-24 11:07:11-05</timestamp>
    <packet>
      <iphdr saddr="68.99.108.41" daddr="64.29.19.233" proto="1" ver="4" hlen="5" len="28" ttl="49" csum="17743">
        <icmphdr type="8" code="0" csum="64065"/>
      </iphdr>
    </packet>
  </event>

</file>
