alert tcp any any -> any 4660:4799 (msg:"ET
P2P? ed2k request part"; flow: to_server,established; content:"|e3|"; offset: 0; depth: 1; content:"|00000047|"; offset: 2; depth: 4; reference:url,www.giac.org/practical/GCIH/Ian_Gosling_GCIH.pdf; classtype: policy-violation; sid: 2000332; rev:6;)
Added 2008-01-29 10:56:39 UTC
alert tcp any any -> any 4660:4799 (msg:"ET
P2P? ed2k request part"; flow: to_server,established; content:"|e3|"; offset: 0; depth: 1; content:"|00000047|"; offset: 2; depth: 4; reference:url,www.giac.org/practical/GCIH/Ian_Gosling_GCIH.pdf; classtype: policy-violation; sid: 2000332; rev:6;)
Added 2008-01-29 10:56:39 UTC
alert tcp any any -> any 4660:4799 (msg: "BLEEDING-EDGE
P2P? ed2k request part"; flow: to_server,established; content:"|e3|"; offset: 0; depth: 1; content:"|00000047|"; offset: 2; depth: 4; reference:url,www.giac.org/practical/GCIH/Ian_Gosling_GCIH.pdf; classtype: policy-violation; sid: 2000332; rev:5; )