Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

[Snort-sigs] Snort Community Rules Update

Subject: [Snort-sigs] Snort Community Rules Update
Date: Wed, 21 Sep 2005 15:40:07 -0400
This message is to announce the availability of an update for the Sourcefire community rule set, which can be downloaded free of cost or registration from http://www.snort.org/pub-bin/downloads.cgi.

New rules in this release are identified as SIDs 100000133-100000156. They cover several vulnerabilities, including arbitrary command execution on web servers running Twiki, buffer overflows in the MDaemon IMAP server, directory traversal in the Ipswitch Imail system, and name server spoofing attacks against Microsoft IIS servers.

Sourcefire would like to thank rmkml for submitting several rules, as well as Chas Tomlin for submitting the Twiki rule. As a reminder, anyone who wishes to submit rules may do so at http://www.snort.org/reg-bin/rulesubmit.cgi.

A list of new rules and their SIDs follows.

Alex Kirk
Community Rules Maintainer
Sourcefire, Inc.

100000133 || COMMUNITY WEB-DoS Xeneo Server Question Mark GET Request
100000134 || COMMUNITY DOS Tcpdump rsvp attack
100000135 || COMMUNITY IMAP GNU Mailutils request tag format string vulnerability
100000136 || COMMUNITY IMAP GNU imapd search format string attempt
100000137 || COMMUNITY MISC BAD-SSL tcp detect
100000138 || COMMUNITY WEB-IIS Remote IIS Server Name spoof attempt localhost
100000139 || COMMUNITY WEB-IIS Remote IIS Server Name spoof attempt loopback IP
100000140 || COMMUNITY WEB-MISC MaxDB Web Tool Remote Stack Overflow
100000141 || COMMUNITY WEB-MISC Ipswitch Imail web calendaring .jsp directory traversal attempt
100000142 || COMMUNITY WEB-MISC Ipswitch Imail web calendaring .jpg directory traversal attempt
100000143 || COMMUNITY WEB-MISC Ipswitch Imail web calendaring .gif directory traversal attempt
100000144 || COMMUNITY WEB-MISC Ipswitch Imail web calendaring .wav directory traversal attempt
100000145 || COMMUNITY WEB-MISC Ipswitch Imail web calendaring .css directory traversal attempt
100000146 || COMMUNITY WEB-MISC Ipswitch Imail web calendaring .htm directory traversal attempt
100000147 || COMMUNITY WEB-MISC MaxDB Web Tool Remote Stack Overflow
100000148 || COMMUNITY WEB-MISC Barracuda img.pl attempt
100000149 || COMMUNITY WEB-MISC Jboss % attempt
100000150 || COMMUNITY WEB-MISC HTTP Transfer-Content Request Smuggling attempt
100000151 || COMMUNITY WEB-PHP piranha default passwd attempt
100000152 || COMMUNITY IMAP MDaemon authentication protocol decode
100000153 || COMMUNITY IMAP MDaemon authentication multiple packet overflow attempt
100000154 || COMMUNITY IMAP MDaemon authentication okay protocol decode
100000155 || COMMUNITY IMAP MDaemon authentication overflow single packet attempt
100000156 || COMMUNITY WEB-MISC Twiki shell command execution



------------------------------------------------------- SF.Net email is sponsored by: Tame your development challenges with Apache's Geronimo App Server. Download it for free - -and be entered to win a 42" plasma tv or your very own Sony(tm)PSP. Click here to play: http://sourceforge.net/geronimo.php _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>