Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Announcement: Try the Ask AI chatbot for answers to your technical questions about Juniper products and solutions.

close
header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Junos CLI Reference
Table of Contents Expand all
list Table of Contents

show security idp attack attack-list policy

date_range 19-Nov-23

Syntax

content_copy zoom_out_map
show security idp attack attack-list (policy Default | predefined-policy policy-name) (recursive)

Description

Display a list of all attacks that belong to a specified IDP policy.

Specify any configured IDP policy name to determine the attacks available in that particular IDP policy.

Options

policy Default—Specify the default IDP policy name.

predefined-policy policy-name—Specify the predefined IDP policy name.

predefined-group group-name—Specify the predefined IDP policy group name.

recursive—Recursively search through nested policies and attack-groups.

Required Privilege Level

view

With just Rule base IDP Attacks Configured

show security idp attack attack-list policy Default

Check attack-list against the default policy.

content_copy zoom_out_map
user@host> show security idp attack attack-list policy Default
Processing your request, results will show up shortly!
Please use show security idp attack attack-list predefined-group/dynamic-group command if there are any nested attack-groups listed below to further display attacks
RULEBASE IPS ATTACKS
 Recommended-CTS-1-Year-Old
 Recommended-STC-1-Year-Old
 Recommended-CTS-2-Years-Old
 Recommended-STC-2-Years-Old

Sample Output

With both Rule Base and Rule Base Exempt Configured

run show security idp attack attack-list predefined-group FTP

content_copy zoom_out_map
user@host# run show security idp attack attack-list policy idpengine
Processing your request, results will show up shortly!
Please use show security idp attack attack-list predefined-group/dynamic-group command if there are any nested attack-groups listed below to further display attacks
RULEBASE IPS ATTACKS
  HTTP:AUDIT:REQ-LONG-UTF8CODE
  HTTP:CISCO:VOIP:STREAM-ID-REQ
  HTTP:BROWSER:ICQ
  HTTP:INFO-LEAK:SNOOP-DISLOSURE
  HTTP:CGI:NULL-ENCODING
  HTTP:INFO:MWS-SEARCH-OF1
  HTTP:INFO:TMICRO-PROXY-REQ
  HTTP:AUDIT:URL
  HTTP:TOMCAT:REAL-PATH-REQ
  HTTP:TOMCAT:JSP-BUFFER
  HTTP:TOMCAT:JSP-COMMENTS
  HTTP:TOMCAT:JSP-PAGE
  HTTP:TOMCAT:JSP-DEC-INT-OF
  HTTP:TOMCAT:SOURCE-MAL-REQ
  HTTP:REQERR:BIN-DATA-ACC-ENC
  HTTP:TUNNEL:TELNET
  HTTP:TUNNEL:CHAT-YIM
  HTTP:TUNNEL:CHAT-AOL-IM
  HTTP:UNIX-CMD:UNIX-CMD-A-L
  HTTP:UNIX-CMD:UNIX-CMD-M-Z
  HTTP:TUNNEL:ALTNET-OVER-HTTP
  HTTP:TUNNEL:PROXY
  HTTP:MISC:MOODLOGIC-CLIENT
  HTTP:STREAM:QUICKTIME-CLIENT
  HTTP:TUNNEL:CHAT-MSN-IM
  HTTP:AUDIT:FW1-SCHEME-OF
  HTTP:HOTMAIL:FILE-DOWNLOAD
  HTTP:HOTMAIL:ZIP-DOWNLOAD
  HTTP:INFO:HTTPPOST-GETSTYLE
  HTTP:EXT:DOT-CHM
  HTTP:INFO-LEAK:HTTP-SHARE-ENUM
  HTTP:3COM:ADMIN-LOGOUT
  HTTP:PROXY:HTTP-PROXY-GET
  HTTP:HOTMAIL:FILE-UPLOAD
  HTTP:EXT:DOT-RAT
  HTTP:GMAIL:FILE-UPLOAD
  HTTP:PHP:BZOPEN-OF
  HTTP:COLDFUSION:CF-CLASS-DWLD
  HTTP:AUDIT:ROBOTS.TXT
  HTTP:STREAM:GOOGLE-VIDEO
  HTTP:STREAM:ITUNES-USERAGENT
  HTTP:INFO-LEAK:CC-CLEAR-VAR
  HTTP:IIS:ENCODING:UNICODE
  HTTP:DOMINO:INFO-LEAK
  HTTP:STREAM:YOUTUBE-REQ 
  HTTP:PASSWD:COMMON
  HTTP:PROXY:LIST:PUBWEBPROXIES
  HTTP:PROXY:ANON:PROXY-2
  HTTP:PROXY:LIST:PROXYFIND
  HTTP:PROXY:ANON:CGIPROXY
  HTTP:EXT:DOT-VML
  HTTP:EXT:DOT-RPT
  HTTP:PROXY:ANON:CONCEAL-WS
  HTTP:PROXY:WPAD-CONNECTION
  HTTP:PROXY:CAW-URI-RES
  HTTP:XDOMAINXML
  HTTP:INFO-LEAK:SSN-CLEARTEXT
  HTTP:AUDIT:LENGTH-OVER-256
  HTTP:AUDIT:LENGTH-OVER-512
  HTTP:AUDIT:LENGTH-OVER-1024
  HTTP:AUDIT:LENGTH-OVER-2048
  HTTP:INFO:FACEBOOK
  HTTP:INFO:MS-UPDATE
  HTTP:YAHOO:ATTACHMENT-UPLOAD
  HTTP:YAHOO:ATTACHMENT-DOWNLOAD
  HTTP:INFO:YOUTUBE
  HTTP:INFO:FARK
  HTTP:HOTMAIL:LIVE-ACTIVITY
  HTTP:YAHOO:ACTIVITY
  HTTP:EXT:DOT-PPT
  HTTP:INFO:SPIDER-ROBOT
  HTTP:PROXY:ANON:PHPROXY
  HTTP:UA:WGET
  HTTP:UA:CURL
  HTTP:TUNNEL:ANCHORFREE-CLIENT
  HTTP:PHP:PHPINFO-QUERY
  HTTP:UA:SKIPFISH
  HTTP:STREAM:AAJTAK-STREAM
  HTTP:STREAM:FLV
  HTTP:STREAM:STARTV-STREAM
  HTTP:MISC:APPLE-MAPS-APP
  HTTP:AUDIT:HTTP-VER-1.0
  HTTP:INFO:YOUTUBE-APP
  HTTP:UA:MOBILE
  HTTP:UA:CRAZY-BROWSER
  HTTP:UA:GOOGLEBOT
  HTTP:UA:MSN-BINGBOT
  HTTP:UA:NUTCH
  HTTP:UA:MOREOVER
  HTTP:EK-RED-SIMPLETDS-GO
  HTTP:TUNNEL:PSIPHON-TUNNEL
  FTP:AUDIT:REQ-BINARY-DATA
  FTP:AUDIT:REQ-INVALID-CMD-SEQ
  FTP:AUDIT:REQ-NESTED-REQUEST
  FTP:AUDIT:REQ-UNKNOWN-CMD
  FTP:AUDIT:LOGIN-FAILED
  FTP:USER:ANONYMOUS
  FTP:PASSWORD:COMMON-PASSWD
  FTP:PASSWORD:DEFAULT-USERNM-PW
  FTP:EXT:DOT-PDF
  FTP:FILE:RETR
  FTP:FILE:STOR
RULEBASE EXEMPT ATTACKS
  FTP:AUDIT:REQ-BINARY-DATA
  FTP:AUDIT:REQ-INVALID-CMD-SEQ
  FTP:AUDIT:REQ-NESTED-REQUEST
  FTP:AUDIT:REQ-UNKNOWN-CMD
  FTP:AUDIT:LOGIN-FAILED
  FTP:USER:ANONYMOUS
  FTP:PASSWORD:COMMON-PASSWD
  FTP:PASSWORD:DEFAULT-USERNM-PW
  FTP:EXT:DOT-PDF
  FTP:FILE:RETR
  FTP:FILE:STOR

Release Information

Command introduced in Junos OS Release 18.4R1.

footer-navigation