Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Snort Community Rules Update |
|---|---|
| Date: | Tue, 05 Sep 2006 10:37:12 -0400 |
This message is to announce the availability of an update for the Sourcefire community rule set, which can be downloaded free of cost or registration from http://www.snort.org/pub-bin/downloads.cgi. New rules in this release are identified as SIDs 100000874-100000891. These rules cover detection of TOR and Google Talk traffic, which may be policy violations in some environments; cross-site scripting attempts against the Roller Weblog system; a buffer overflow attempt against ImageMagick; remote file inclusion attacks against PHP Live Helper and Inlink; SQL injection against SimpleBlog; and other attacks against the pHNews, Proxima, pmwiki, tikiwiki, yappa-ng, and Webmin/Usermin systems. Sourcefire would like to thank the following submitters for their contributions: * Dan Ramaswami for SIDs 100000874-100000875 * Will Young for 100000876-100000877 * p3rlhax@gmail.com for SIDs 100000878-100000880 As a reminder, anyone who wishes to submit rules may do so at http://www.snort.org/reg-bin/rulesubmit.cgi. A list of modified rules and their SIDs follows. Alex Kirk Community Rules Maintainer Sourcefire, Inc. 100000874 || COMMUNITY MISC DLR-TOR Directory server response 100000875 || COMMUNITY MISC DLR-TOR Client Traffic 100000876 || COMMUNITY MISC Google Talk Version Check 100000877 || COMMUNITY MISC Google Talk Startup 100000878 || COMMUNITY WEB-CGI Roller Weblog XSS exploit 100000879 || COMMUNITY WEB-CGI Roller Weblog XSS exploit 100000880 || COMMUNITY WEB-CGI Roller Weblog XSS exploit 100000881 || COMMUNITY WEB-CLIENT ImageMagick SGI ZSIZE Header Information Overflow Attempt 100000882 || COMMUNITY WEB-PHP PHP Live Helper globals.php remote file include 100000883 || COMMUNITY WEB-PHP Inlink remote file inclusion exploit 100000884 || COMMUNITY WEB-MISC SimpleBlog Remote SQL Injection attempt 100000885 || COMMUNITY WEB-PHP pHNews access attempt 100000886 || COMMUNITY WEB-PHP Proxima access attempt 100000887 || COMMUNITY WEB-PHP pmwiki exploit attempt 100000888 || COMMUNITY WEB-PHP tikiwiki exploit attempt 100000889 || COMMUNITY WEB-PHP yappa-ng exploit attempt 100000890 || COMMUNITY WEB-MISC Webmin null char attempt 100000891 || COMMUNITY WEB-MISC Usermin null char attempt ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] two new rules for detect Webmin/Usermin null char, rmkml |
|---|---|
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
| Previous by Thread: | [Snort-sigs] two new rules for detect Webmin/Usermin null char, rmkml |
| Next by Thread: | [Snort-sigs] Snort Community Rules Update, Sourcefire VRT |
| Indexes: | [Date] [Thread] [Top] [All Lists] |