This URL is used to retrieve the alert details.
Resource URL
GET /alerts/<alert_uuid>?sensorId=<sensor_id>&manager=<manager_name>
Request Parameters
Query Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Alert uuid | Number | Yes |
| Sensor id | Number | Yes |
| Name of the Manager. Required in case a multiple Managers are monitored with a single Manager. | String | No |
Response Parameters
Following fields are returned.
Field Name | Description | Data Type |
|---|---|---|
name | Name | String |
uniqueAlertId | Unique alert id | String |
alertState | Alert state | String |
summary | Summary | Object |
details | Details | Object |
description | Description | Object |
Example
Request
GET https://<NSM_IP>/sdkapi/alerts/6245941293374080682
Response
{
"name": "DNS: IQUERY Buffer Overflow",
"uniqueAlertId": "6806386691967877137",
"alertState": "UnAcknowledged",
"assignTo": "---",
"summary": {
"event": {
"application": "Not Available",
"protocol": "telnet",
"domain": "/My Company",
"manager": null,
"device": "vm600-nsmapi-cc",
"deviceId": "1001",
"interface": "1-2",
"matchedPolicy": "Default Prevention",
"zone": null,
"vlan": "-10",
"detection": "Application anomaly",
"time": "Apr 23, 2020 22:26:13",
"direction": "Inbound",
"result": "Inconclusive",
"attackCount": 1,
"relevance": "Unknown",
"alertId": "6806386691964665876"
},
"attacker": {
"ipAddrs": "60.131.8.49",
"port": 17561,
"hostName": null,
"country": null,
"os": "Microsoft Windows Server 2008",
"vmName": null,
"proxyIP": null,
"user": "Unknown",
"risk": "N/A",
"networkObject": "---"
},
"target": {
"ipAddrs": "0.20.209.51",
"port": 58004,
"hostName": null,
"country": null,
"os": "Microsoft Windows Server 2003 Service Pack 1",
"vmName": null,
"proxyIP": null,
"user": "Unknown",
"risk": "N/A",
"networkObject": "---"
},
"source": null,
"destination": null,
"zoombie": null,
"cAndcServer": null,
"fastFluxAgent": null,
"attackedHIPEndpoint": null,
"compromisedEndpoint": null
},
"details": {
"matchedSignature": {
"signatureName": "IQUERY-overflow-iquery.c",
"signature": {
"name": "Signature#1",
"conditions": [
"condition 1",
" dns-request-hdr-opcode == 1 ( unsigned )",
"[AND] dns-request-answer-type == 1 ( unsigned )",
"[AND] dns-request-answer-class == 1 ( unsigned )",
"[AND] dns-request-answer-rdata matches \"(\\xeb\\x6e\\x5e\\xc6\\x06\\x9a\\x31\\xc9\\x89\\x4e\\x01|\\x80\\xe8\\xd7\\xff\\xff\\xff/bin/sh)\" ( case-sensitive )"
]
}
},
"layer7": null,
"malwareFile": null,
"hostSweep": null,
"portScan": null,
"fastFlux": null,
"triggeredComponentAttacks": null,
"sqlInjection": null,
"callbackDetectors": null,
"exceededThreshold": null,
"communicationRuleMatch": null
},
"description": {
"definition": "BIND is used by most UNIX DNS servers, and implements the Domain Name Service (DNS) protocol. Certain versions of BIND do not properly bounds check a memory copy when responding to an inverse query (IQUERY) request. An improperly or maliciously formatted inverse query in a TCP stream can crash the server or allow an attacker to execute arbitrary code, possibly gaining root privileges.\n\nBuffer overflow vulnerabilities can be exploited to cause a denial of service or enable the execution of arbitrary code with the privileges of the affected server or process.\n\nThe inverse query feature is disabled by default, so only those systems that have been explicitly configured to allow it are vulnerable. Inverse queries can be disabled with little ill effect to prevent this attack.\n\nUpgrade to the latest applicable version of BIND as listed in CERT Advisory CA-98.05. Upgrading to the latest version of BIND 8 is recommended. <br> <br> For SunOS 2.x, apply the necessary patch as listed in Sun Microsystems, Inc. Security Bulletin #00180.\n\nSoftware Packages <br>Internet Software Consortium BIND<ul><ul><li>4.9.6 to 4.9.6</li></ul><ul><li>8.1 to 8.1.1</li></ul></ul>",
"btp": "Low",
"rfSB": "Yes",
"protectionCategory": "[Server Protection/Name Servers]",
"target": "Server",
"httpResponseAttack": "No",
"priority": "High",
"protocols": "dns",
"attackCategory": "Exploit",
"attackSubCategory": "Buffer Overflow",
"snortEngine": "---",
"versionAdded": "10.8.1.6",
"versionUpdated": "10.8.1.6",
"reference": {
"nspId": "0x40300200",
"cveId": "CVE-1999-0009",
"microsoftId": "",
"bugtraqId": "134",
"certId": null,
"arachNidsId": "",
"additionInfo": "http://www.cert.org/advisories/CA-98.05.bind_problems.html"
},
"signatures": [
{
"name": "Signature#1",
"conditions": [
"condition 1",
" dns-request-hdr-opcode == 1 ( unsigned )",
"[AND] dns-request-answer-type == 1 ( unsigned )",
"[AND] dns-request-answer-class == 1 ( unsigned )",
"[AND] dns-request-answer-rdata matches \"(\\xeb\\x6e\\x5e\\xc6\\x06\\x9a\\x31\\xc9\\x89\\x4e\\x01|\\x80\\xe8\\xd7\\xff\\xff\\xff/bin/sh)\" ( case-sensitive )"
]
},
{
"name": "Signature#2",
"conditions": [
"condition 1",
" dns-request-hdr-opcode == 1 ( unsigned )",
"[AND] dns-request-answer-type == 1 ( unsigned )",
"[AND] dns-request-answer-class == 1 ( unsigned )",
"[AND] dns-request-answer-rdata matches \"(\\xff\\xff\\xff/usr/bin/X11/xterm\\xff-display|\\xe8\\xd7\\xff\\xff\\xff/tmp/hi)\" ( case-sensitive )"
]
},
{
"name": "Signature#3",
"conditions": [
"condition 1",
" dns-request-hdr-opcode == 1 ( unsigned )",
"[AND] dns-error-code == host-ip-addr-len-too-long ( unsigned )",
"[AND THEN] condition 2",
"[Any Of]",
" System Event Name=\"shellcode-detected-for-arch-i386\" ",
"[OR] System Event Name=\"shellcode-detected-for-arch-sparc\" ",
"[OR] System Event Name=\"shellcode-detected-for-arch-powerpc\" "
]
},
{
"name": "Signature#4",
"conditions": [
"condition 1",
" dns-request-hdr-opcode == 1 ( unsigned )",
"[AND] dns-error-code == iquery-overflow ( unsigned )",
"[AND THEN] condition 2",
"[Any Of]",
" System Event Name=\"shellcode-detected-for-arch-i386\" ",
"[OR] System Event Name=\"shellcode-detected-for-arch-sparc\" ",
"[OR] System Event Name=\"shellcode-detected-for-arch-powerpc\" "
]
},
{
"name": "Signature#5",
"conditions": [
"condition 1",
" dns-request-hdr-opcode == 1 ( unsigned )",
"[AND] dns-error-code == iquery-overflow ( unsigned )"
]
}
],
"componentAttacks": [],
"comments": {
"comments": "",
"availabeToChildDomains": true,
"parentDomainComments": null
}
}
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 9803 | Invalid alert id |
2 | 404 | 9803 | Sensor id is required |
3 | 404 | 9803 | Manager name is required |