This is an extensive listfile, including every network session that was part of the attack, listed individually, one per line. In additon, if there was no network traffic (but perhaps other evidence of an attack) a pseudo-listfile-entry is included here. These pseudo entries are generally indicated by information in the entry being excluded, or entered as a wildcard (*).

For example, if an attack was carried out on the console, there will be and entry here to designate the victim of the attack (Destination field) and the Time/Duration of the console portion of the attack. Or in the case of a sweep or probe that hits all (or most of) a subnet within a small period of time, we might have condensed that attack, manually, into one or more entries using a wildcard of * for the final octet of the destination of victim ip.

In general the Destination field is also the Victim of the attack, however there are circumstances where the Victim is the Source of a tcpconnection, and thus the ip shows up in the Source column. In that situation, the scoring software matches the detected victim with the host in the Source column.


ATTACK: /data/id/1999/5week/thursday/sniffer/attacker/110416.ntinfoscan-129-probe--clear-hume/110416.ntinfoscan-129-probe--clear-hume.exs.list

ID#NameDateStartDurationServiceSourceSrcPortDest.DestPort insider?manual?console?success?aDump?oDumpiDumpBSM?SysLogsFSListingStealthyNew?CategoryOS
54.110416 ntinfoscan 04/08/1999 11:26:37 00:01:01 ftp206.048.044.0181253 172.016.112.10021 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:26:38 00:00:01 ftp-data172.016.112.10020 206.048.044.01820 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:27:38 00:00:01 telnet206.048.044.0181255 172.016.112.10023 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:27:38 00:00:01 http206.048.044.0181256 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:27:38 00:00:01 http206.048.044.0181257 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:27:38 00:00:01 http206.048.044.0181258 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:27:38 00:00:01 http206.048.044.0181259 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:27:38 00:00:01 http206.048.044.0181260 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:27:38 00:00:01 http206.048.044.0181261 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:27:38 00:15:04 http206.048.044.0181262 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:42:42 00:00:01 http206.048.044.0181278 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:42:42 00:00:01 http206.048.044.0181279 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:42:42 00:00:01 http206.048.044.0181280 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:42:42 00:00:01 nbssn206.048.044.0181281 172.016.112.100139 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:42:42 00:00:03 nbssn206.048.044.0181283 172.016.112.100139 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT
54.110416 ntinfoscan 04/08/1999 11:42:45 00:00:01 http206.048.044.0181256 172.016.112.10080 outautoremsuccaDmpoDmpiDmpnotSysLgFSLstClrOldllPROBEllNT