#alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SERVER Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; reference:url,www.incidents.org/diary.html?storyid=4405; classtype:web-application-attack; sid:2008207; rev:5; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2018-09-13 19:39:44 UTC
Added 2018-09-13 17:53:47 UTC
#alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SERVER Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; reference:url,www.incidents.org/diary.html?storyid=4405; classtype:web-application-attack; sid:2008207; rev:5; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2017-08-07 21:01:23 UTC
#alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SERVER Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; reference:url,www.incidents.org/diary.html?storyid=4405; classtype:web-application-attack; sid:2008207; rev:5;)
Added 2014-09-12 16:28:25 UTC
#alert http $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; reference:url,www.incidents.org/diary.html?storyid=4405; reference:url,doc.emergingthreats.net/bin/view/Main/2008207; classtype:web-application-attack; sid:2008207; rev:4;)
Added 2014-08-26 19:07:49 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; fast_pattern:only; reference:url,www.incidents.org/diary.html?storyid=4405; reference:url,doc.emergingthreats.net/bin/view/Main/2008207; classtype:web-application-attack; sid:2008207; rev:3;)
Added 2011-10-12 19:24:39 UTC
#alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; fast_pattern:only; classtype:web-application-attack; reference:url,www.incidents.org/diary.html?storyid=4405; reference:url,doc.emergingthreats.net/bin/view/Main/2008207; sid:2008207; rev:3;)
Added 2011-09-14 22:38:07 UTC
alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; fast_pattern:only; classtype:web-application-attack; reference:url,www.incidents.org/diary.html?storyid=4405; reference:url,doc.emergingthreats.net/bin/view/Main/2008207; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/CURRENT_EVENTS/CURRENT_Mass_File_Injections; sid:2008207; rev:3;)
Added 2011-02-04 17:27:18 UTC
alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; reference:url,www.incidents.org/diary.html?storyid=4405; classtype:web-application-attack; reference:url,doc.emergingthreats.net/bin/view/Main/2008207; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/CURRENT_EVENTS/CURRENT_Mass_File_Injections; sid:2008207; rev:2;)
Added 2009-02-06 19:00:54 UTC
alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; reference:url,www.incidents.org/diary.html?storyid=4405; classtype:web-application-attack; reference:url,doc.emergingthreats.net/bin/view/Main/2008207; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/CURRENT_EVENTS/CURRENT_Mass_File_Injections; sid:2008207; rev:2;)
Added 2009-02-06 19:00:54 UTC
alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; reference:url,www.incidents.org/diary.html?storyid=4405; classtype:web-application-attack; sid:2008207; rev:1;)
Added 2008-05-12 15:06:28 UTC
alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; reference:url,www.incidents.org/diary.html?storyid=4405; classtype:web-application-attack; sid:2008207; rev:1;)
Added 2008-05-12 15:04:55 UTC
alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; reference:url,www.incidents.org/diary.html?storyid=4405; classtype:web-application-attack; sid:2008207; rev:1;)
Added 2008-05-12 15:04:55 UTC
alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Possible File Injection Compromise (
HaCKeD? By
BeLa? &
BodyguarD?)"; flow:established,to_server; content:"HaCKeD By
BeLa? &
BodyguarD?"; reference:url,www.incidents.org/diary.html?storyid=4405; classtype:web-application-attack; sid:2008207; rev:1;)
Added 2008-05-12 15:03:50 UTC