Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

[Snort-sigs] Bleeding Edge Threats Daily Signature Changes

Subject: [Snort-sigs] Bleeding Edge Threats Daily Signature Changes
Date: Thu, 23 Aug 2007 00:00:32 +0000 (UTC)

[***] Results from Oinkmaster started Thu Aug 23 00:00:32 2007 [***]

[+++]          Added rules:          [+++]

 2002997 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list http) 
(bleeding-web.rules)
 2003098 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list ftp) 
(bleeding-web.rules)
 2003935 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list php) 
(bleeding-web.rules)
 2006591 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid SELECT 
(bleeding-web_sql_injection.rules)
 2006592 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid UNION SELECT 
(bleeding-web_sql_injection.rules)
 2006593 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid INSERT 
(bleeding-web_sql_injection.rules)
 2006594 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid DELETE 
(bleeding-web_sql_injection.rules)
 2006595 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid ASCII 
(bleeding-web_sql_injection.rules)
 2006596 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid UPDATE 
(bleeding-web_sql_injection.rules)
 2006597 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass SELECT 
(bleeding-web_sql_injection.rules)
 2006598 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass UNION SELECT 
(bleeding-web_sql_injection.rules)
 2006599 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass INSERT 
(bleeding-web_sql_injection.rules)
 2006600 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass DELETE 
(bleeding-web_sql_injection.rules)
 2006601 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass ASCII 
(bleeding-web_sql_injection.rules)
 2006602 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass UPDATE 
(bleeding-web_sql_injection.rules)
 2007571 - BLEEDING-EDGE POLICY Remote Desktop Connection via non RDP Port 
(bleeding-policy.rules)


[///]     Modified active rules:     [///]

 2001329 - BLEEDING-EDGE POLICY RDP connection request (bleeding-policy.rules)
 2001330 - BLEEDING-EDGE POLICY RDP connection confirm (bleeding-policy.rules)
 2001331 - BLEEDING-EDGE POLICY RDP disconnect request (bleeding-policy.rules)
 2400000 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound 
(bleeding-drop.rules)
 2400001 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound 
(bleeding-drop.rules)
 2400002 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound 
(bleeding-drop.rules)
 2400003 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound 
(bleeding-drop.rules)
 2400004 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound 
(bleeding-drop.rules)
 2401000 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING 
SOURCE (bleeding-drop-BLOCK.rules)
 2401001 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING 
SOURCE (bleeding-drop-BLOCK.rules)
 2401002 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING 
SOURCE (bleeding-drop-BLOCK.rules)
 2401003 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING 
SOURCE (bleeding-drop-BLOCK.rules)
 2401004 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING 
SOURCE (bleeding-drop-BLOCK.rules)
 2402000 - BLEEDING-EDGE DROP Dshield Block Listed Source 
(bleeding-dshield.rules)
 2403000 - BLEEDING-EDGE DROP Dshield Block Listed Source - BLOCKING 
(bleeding-dshield-BLOCK.rules)
 2404000 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 1)  
(bleeding-botcc.rules)
 2404001 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 2)  
(bleeding-botcc.rules)
 2404002 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 3)  
(bleeding-botcc.rules)
 2404003 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 4)  
(bleeding-botcc.rules)
 2404004 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 5)  
(bleeding-botcc.rules)
 2404005 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 6)  
(bleeding-botcc.rules)
 2404006 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 7)  
(bleeding-botcc.rules)
 2404007 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 8)  
(bleeding-botcc.rules)
 2404008 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 9)  
(bleeding-botcc.rules)
 2404009 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 10)  
(bleeding-botcc.rules)
 2404010 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 11)  
(bleeding-botcc.rules)
 2404011 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 12)  
(bleeding-botcc.rules)
 2404012 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 13)  
(bleeding-botcc.rules)
 2405000 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 1) - BLOCKING SOURCE 
(bleeding-botcc-BLOCK.rules)
 2405001 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 2) - BLOCKING SOURCE 
(bleeding-botcc-BLOCK.rules)
 2405002 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 3) - BLOCKING SOURCE 
(bleeding-botcc-BLOCK.rules)
 2405003 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 4) - BLOCKING SOURCE 
(bleeding-botcc-BLOCK.rules)
 2405004 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 5) - BLOCKING SOURCE 
(bleeding-botcc-BLOCK.rules)
 2405005 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 6) - BLOCKING SOURCE 
(bleeding-botcc-BLOCK.rules)
 2405006 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 7) - BLOCKING SOURCE 
(bleeding-botcc-BLOCK.rules)
 2405007 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 8) - BLOCKING SOURCE 
(bleeding-botcc-BLOCK.rules)
 2405008 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 9) - BLOCKING SOURCE 
(bleeding-botcc-BLOCK.rules)
 2405009 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 10) - BLOCKING 
SOURCE (bleeding-botcc-BLOCK.rules)
 2405010 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 11) - BLOCKING 
SOURCE (bleeding-botcc-BLOCK.rules)
 2405011 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 12) - BLOCKING 
SOURCE (bleeding-botcc-BLOCK.rules)
 2405012 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 13) - BLOCKING 
SOURCE (bleeding-botcc-BLOCK.rules)


[---]         Removed rules:         [---]

 2002997 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list http) 
(bleeding-web_sql_injection.rules)
 2003098 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list ftp) 
(bleeding-web_sql_injection.rules)
 2003935 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list php) 
(bleeding-web_sql_injection.rules)
 2006591 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid SELECT (bleeding-web.rules)
 2006592 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid UNION SELECT 
(bleeding-web.rules)
 2006593 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid INSERT (bleeding-web.rules)
 2006594 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid DELETE (bleeding-web.rules)
 2006595 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid ASCII (bleeding-web.rules)
 2006596 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp agentid UPDATE (bleeding-web.rules)
 2006597 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass SELECT (bleeding-web.rules)
 2006598 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass UNION SELECT (bleeding-web.rules)
 2006599 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass INSERT (bleeding-web.rules)
 2006600 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass DELETE (bleeding-web.rules)
 2006601 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass ASCII (bleeding-web.rules)
 2006602 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL 
Injection Attempt -- downloadreport.asp pass UPDATE (bleeding-web.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to bleeding-drop-BLOCK.rules (1):
        #  VERSION 285

     -> Added to bleeding-drop.rules (1):
        #  VERSION 285

     -> Added to bleeding-policy.rules (2):
        #By Scott Melnick
        #Users can connect to remote machines by port forwarding 3389 through 
personal routers.

     -> Added to bleeding-sid-msg.map (4):
        2001329 || BLEEDING-EDGE POLICY RDP connection request
        2001330 || BLEEDING-EDGE POLICY RDP connection confirm
        2001331 || BLEEDING-EDGE POLICY RDP disconnect request
        2007571 || BLEEDING-EDGE POLICY Remote Desktop Connection via non RDP 
Port

     -> Added to bleeding-web.rules (2):
        #Split into 2 rules, so they can be prequalified with a stronger uri 
check
        #Adding a php version, as pointed out by James Riden php also 
recognizes this

[---]     Removed non-rule lines:    [---]

     -> Removed from bleeding-drop-BLOCK.rules (1):
        #  VERSION 284

     -> Removed from bleeding-drop.rules (1):
        #  VERSION 284

     -> Removed from bleeding-sid-msg.map (3):
        2001329 || BLEEDING-EDGE RDP connection request
        2001330 || BLEEDING-EDGE RDP connection confirm
        2001331 || BLEEDING-EDGE RDP disconnect request

     -> Removed from bleeding-web_sql_injection.rules (3):
        #By Blake Hartstein at Demarc
        #Split into 2 rules, so they can be prequalified with a stronger uri 
check
        #Adding a php version, as pointed out by James Riden php also 
recognizes this


-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >>  http://get.splunk.com/
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>