alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Hotmail Inbox Access"; flow:to_server,established; content:"GET"; http_method; content:"mail.live.com"; http_header; content:"/mail/InboxLight.aspx"; http_uri; depth:21; reference:url,doc.emergingthreats.net/2008238; classtype:policy-violation; sid:2008238; rev:3;)

Added 2011-10-12 19:24:43 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Hotmail Inbox Access"; flow:to_server,established; content:"GET"; http_method; content:"mail.live.com"; http_header; content:"/mail/InboxLight.aspx"; http_uri; depth:21; classtype:policy-violation; reference:url,doc.emergingthreats.net/2008238; sid:2008238; rev:3;)

Added 2011-05-24 18:47:25 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Hotmail Inbox Access"; flow:to_server,established; content:"GET "; depth:4; content:"mail.live.com"; uricontent:"/mail/InboxLight.aspx"; classtype:policy-violation; reference:url,doc.emergingthreats.net/2008238; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/POLICY/POLICY_HOTMAIL_Mail_Use; sid:2008238; rev:2;)

Added 2011-02-04 17:27:20 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Hotmail Inbox Access"; flow:to_server,established; content:"GET "; depth:4; content:"mail.live.com"; uricontent:"/mail/InboxLight.aspx"; classtype:policy-violation; reference:url,doc.emergingthreats.net/2008238; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/POLICY/POLICY_HOTMAIL_Mail_Use; sid:2008238; rev:2;)

Added 2009-02-11 19:15:22 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Hotmail Inbox Access"; flow:to_server,established; content:"GET "; depth:4; content:"mail.live.com"; uricontent:"/mail/InboxLight.aspx"; classtype:policy-violation; reference:url,doc.emergingthreats.net/2008238; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/POLICY/POLICY_HOTMAIL_Mail_Use; sid:2008238; rev:2;)

Added 2009-02-11 19:15:22 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Hotmail Inbox Access"; flow:to_server,established; content:"GET "; depth:4; content:"mail.live.com"; uricontent:"/mail/InboxLight.aspx"; classtype:policy-violation; sid:2008238; rev:1;)

Added 2008-05-20 10:32:39 UTC


Topic revision: r3 - 2009-05-29 - MattJonkman
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats