#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)

Added 2009-10-06 14:39:00 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)

Added 2009-10-06 14:39:00 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)

Added 2009-10-06 14:19:32 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)

Added 2009-10-06 14:19:32 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)

Added 2009-10-06 14:16:11 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)

Added 2009-10-06 14:16:11 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:10;)

Added 2009-05-11 20:45:34 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:10;)

Added 2009-05-11 20:45:34 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:9;)

Added 2009-02-20 19:15:59 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:9;)

Added 2009-02-20 19:15:59 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:9;)

Added 2009-02-20 19:15:25 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:9;)

Added 2009-02-20 19:15:25 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; sid: 2001716; rev:8;)

Added 2008-02-01 10:46:08 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; sid: 2001716; rev:8;)

Added 2008-02-01 10:46:08 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg: "BLEEDING-EDGE Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; sid: 2001716; rev:7; )

Added 2007-05-31 13:09:54 UTC


#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg: "BLEEDING-EDGE Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftp|http|https)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; sid: 2001716; rev:6; )



Topic revision: r1 - 2009-10-06 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats