<?xml version="1.0" encoding="iso-8859-15" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:wiki="http://purl.org/rss/1.0/modules/wiki/" ><channel rdf:about="http://docs.emergingthreats.net/bin/view/Main">
<title>TWiki's Main web</title>
  <link>http://docs.emergingthreats.net/bin/view/Main</link>
  <description>The web for users, groups and offices. TWiki is an Enterprise Collaboration Platform.</description>
<image rdf:resource="http://docs.emergingthreats.net/pub/TWiki/TWikiLogos/T-logo-140x40-t.gif" />
  <dc:language>en-us</dc:language>
  <dc:rights>Copyright 2008 Emerging Threats and Contributing Authors</dc:rights>
  <dc:publisher>Emerging Admin [jonkman@emergingthreats.net]</dc:publisher>
  <dc:creator>The contributing authors of TWiki</dc:creator>
  <dc:source>TWiki</dc:source>
  <items>
    <rdf:Seq>
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008515" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008514" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008513" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008512" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008511" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008510" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008341" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008315" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008314" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008421" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008420" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008509" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008313" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/2008508" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/ScottBlayney" />
      <rdf:li rdf:resource="http://docs.emergingthreats.net/bin/view/Main/RussianBusinessNetwork" />
    </rdf:Seq>
  </items>
</channel>
<image rdf:about="http://docs.emergingthreats.net/pub/TWiki/TWikiLogos/T-logo-140x40-t.gif">
  <title>Powered by TWiki.Main</title>
  <link>http://docs.emergingthreats.net/bin/view/Main</link>
  <url>http://docs.emergingthreats.net/pub/TWiki/TWikiLogos/T-logo-140x40-t.gif</url>
</image>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008515">
  <title>2008515</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008515</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN AZG Checkin"; flow:established,to server; content:"GET "; depth:4; nocase; content:" 0d 0a User ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-20T04:30:23Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008514">
  <title>2008514</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008514</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Suspicious User Agent (AVP2006IE)"; flow:established,to server; content:" 0d 0a User Agent\: ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T22:30:21Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008513">
  <title>2008513</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008513</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Suspicious User Agent (msIE 7.0)"; flow:established,to server; content:" 0d 0a User Agent\: msIE ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T22:30:21Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008512">
  <title>2008512</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008512</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Suspicious User Agent (C\:\\)"; flow:established,to server; content:" 0d 0a User Agent\: C\: ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T22:13:45Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008511">
  <title>2008511</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008511</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Win32/Antivirus2008 Fake AV Install Report"; flow:established,to server; uricontent:"?type scanner ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T20:45:21Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008510">
  <title>2008510</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008510</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Suspicious User Agent Possible Trojan Downloader (\xa2\xa2HttpClient)"; flow:established,to ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T19:00:22Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008341">
  <title>2008341</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008341</link>
  <description>alert tcp $EXTERNAL NET any $HOME NET any (msg:"ET TROJAN Themida Packed Binary Likely Hostile"; flow:established,from server; content:" 2E 69 64 61 74 61 20 ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T19:00:22Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008315">
  <title>2008315</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008315</link>
  <description>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET CURRENT EVENTS Iframe in Purported Image Download (png) Likely SQL Injection Attacks Related"; flow ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T19:00:22Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008314">
  <title>2008314</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008314</link>
  <description>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET CURRENT EVENTS Iframe in Purported Image Download (gif) Likely SQL Injection Attacks Related"; flow ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T19:00:22Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008421">
  <title>2008421</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008421</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET 53 (msg:"ET TROJAN HTTP POST Request on port 53 Very Likely Hostile"; flow:established,to server; content:"POST "; nocase ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T19:00:22Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008420">
  <title>2008420</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008420</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET 53 (msg:"ET TROJAN HTTP GET Request on port 53 Very Likely Hostile"; flow:established,to server; content:"GET "; nocase ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T19:00:22Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008509">
  <title>2008509</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008509</link>
  <description>alert tcp $EXTERNAL NET any $HOME NET any (msg:"ET TROJAN VirtualProtect Packed Binary Likely Hostile"; flow:established,from server; content:" 2E 72 73 72 63 ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T19:00:22Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008313">
  <title>2008313</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008313</link>
  <description>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET CURRENT EVENTS Iframe in Purported Image Download (jpeg) Likely SQL Injection Attacks Related"; flow ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T19:00:22Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/2008508">
  <title>2008508</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/2008508</link>
  <description>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET CURRENT EVENTS Internal User may have Visited an ASPROX Infected Site"; content:""; within:40; nocase ... (last changed by TWikiGuest)</description>
  <dc:date>2008-08-19T18:00:21Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/ScottBlayney">
  <title>ScottBlayney</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/ScottBlayney</link>
  <description>My Links .ATasteOfTWiki view a short introductory presentation on TWiki for beginners .WelcomeGuest starting points on TWiki .TWikiUsersGuide ... (last changed by TWikiRegistrationAgent)</description>
  <dc:date>2008-08-19T12:51:06Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.TWikiRegistrationAgent">
      <rdf:value>TWikiRegistrationAgent</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://docs.emergingthreats.net/bin/view/Main/RussianBusinessNetwork">
  <title>RussianBusinessNetwork</title>
  <link>http://docs.emergingthreats.net/bin/view/Main/RussianBusinessNetwork</link>
  <description>Emerging Threats Russian Business Network (RBN) Snort Intrusion Detection Rules : http://www.emergingthreats.net/rules/emerging rbn.rules http://www.emergingthreats ... (last changed by JamesMcQuaid)</description>
  <dc:date>2008-08-18T21:58:43Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://docs.emergingthreats.net/bin/view?topic=Main.JamesMcQuaid">
      <rdf:value>JamesMcQuaid</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<!-- <ul>
<li> Set SKIN = rss
</li></ul> 
--></rdf:RDF>