#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)
Added 2009-10-06 14:39:00 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)
Added 2009-10-06 14:39:00 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)
Added 2009-10-06 14:19:32 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)
Added 2009-10-06 14:19:32 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)
Added 2009-10-06 14:16:11 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_IDN; sid: 2001716; rev:11;)
Added 2009-10-06 14:16:11 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:10;)
Added 2009-05-11 20:45:34 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:10;)
Added 2009-05-11 20:45:34 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:9;)
Added 2009-02-20 19:15:59 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:9;)
Added 2009-02-20 19:15:59 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:9;)
Added 2009-02-20 19:15:25 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; reference:url,doc.emergingthreats.net/2001716; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SQL_INJECTION/WEB_IDN; sid: 2001716; rev:9;)
Added 2009-02-20 19:15:25 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; sid: 2001716; rev:8;)
Added 2008-02-01 10:46:08 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; sid: 2001716; rev:8;)
Added 2008-02-01 10:46:08 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg: "BLEEDING-EDGE Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftps?|https?|php)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; sid: 2001716; rev:7; )
Added 2007-05-31 13:09:54 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg: "BLEEDING-EDGE Web IDN url seen.."; flow: established; content:"\://"; nocase; pcre:"/(ftp|http|https)\:\/\/.*&#[0-9]+\;[^\/ \">]*/Ri"; classtype: misc-activity; sid: 2001716; rev:6; )