Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

[Snort-sigs] Rules about keylogging

Subject: [Snort-sigs] Rules about keylogging
Date: Wed, 7 Jun 2006 10:15:55 +0200
I have already submitted these two rules to  
snort-sigs@lists.sourceforge.net. It seems that nobody is interested.
Since I don't understand exactly the system with the two sig depositories, I 
try again and  propose these two beautiful signatures to  the bleeding sigs. 
Don't worry, it will be my last try.

alert tcp $HOME_NET any -> any 25 (msg:"Bleeding snort - elitekeylogger v1.0 
report"; flow:established;content:"MAIL FROM|3a|<logs@logs.com>";
tag:session,60,seconds;classtype:policy-violation;sid:1200604131;rev:1;)


A second rule about  XP keylogger v2.1 :

alert tcp any any -> any 25 (msg:"Bleeding snort - XP keylogger v2.1 mail 
report"; flow:established;content:"X-Mailer|3a| JMail 4.3.0 Free Version by 
Dimac";content:"<H2=3EAbout the use of the PC</H2=3E";
classtype:policy-violation;sid:1200604181;rev:1;)

Thierry



_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>
  • [Snort-sigs] Rules about keylogging, Chich Thierry <=