Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-sigs] Signature research |
|---|---|
| Date: | Fri, 23 Sep 2005 08:38:13 -0400 |
Thank you!
Joel Esler SOURCEfire
On Sep 5, 2005, at 5:01 AM, security@information-object.com wrote:
Hello,
This signature exists so I've only included the ID and some info. you may wish to add. The blank fields are already filled out on the website. Pleae let me know if this is OK or not. Thanks.
Rule: SCAN UPnP service discover attempt
-- Sid: 1:1917
-- Summary:
-- Impact:
-- Detailed Information:
-- Affected Systems:
-- Attack Scenarios:
-- Ease of Attack:
-- False Positives:
File sharing software like Bittorrent can trigger this alert.
-- False Negatives:
-- Corrective Action:
Determine if file-sharing is a permited practice, bring awareness to users of proper file sharing practice. Unregulated file-sharing may introduce malicious software and use excessive bandwith.
-- Contributors:
Rudi Starcevic <security@informationobject.com>
-- Additional References:
-------------------------------------------------------
SF.Net email is sponsored by:
Tame your development challenges with Apache's Geronimo App Server. Download
it for free - -and be entered to win a 42" plasma tv or your very own
Sony(tm)PSP. Click here to play: http://sourceforge.net/geronimo.php
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
------------------------------------------------------- SF.Net email is sponsored by: Tame your development challenges with Apache's Geronimo App Server. Download it for free - -and be entered to win a 42" plasma tv or your very own Sony(tm)PSP. Click here to play: http://sourceforge.net/geronimo.php _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Emailing: 721.txt, Alan Johnson |
|---|---|
| Next by Date: | Re: [Snort-sigs] (snort decoder) Bad Traffic Same Src/Dst IP {trying to supress alerts from certain IP's}, Joel Esler |
| Previous by Thread: | [Snort-sigs] Signature research, security |
| Next by Thread: | [Snort-sigs] Sid: 1917 triggered by MSN messenger, Adrian Chitoni |
| Indexes: | [Date] [Thread] [Top] [All Lists] |