Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Bleeding Edge Threats Daily Signature Changes |
|---|---|
| Date: | Thu, 23 Aug 2007 00:00:32 +0000 (UTC) |
[***] Results from Oinkmaster started Thu Aug 23 00:00:32 2007 [***]
[+++] Added rules: [+++]
2002997 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list http)
(bleeding-web.rules)
2003098 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list ftp)
(bleeding-web.rules)
2003935 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list php)
(bleeding-web.rules)
2006591 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid SELECT
(bleeding-web_sql_injection.rules)
2006592 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid UNION SELECT
(bleeding-web_sql_injection.rules)
2006593 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid INSERT
(bleeding-web_sql_injection.rules)
2006594 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid DELETE
(bleeding-web_sql_injection.rules)
2006595 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid ASCII
(bleeding-web_sql_injection.rules)
2006596 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid UPDATE
(bleeding-web_sql_injection.rules)
2006597 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass SELECT
(bleeding-web_sql_injection.rules)
2006598 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass UNION SELECT
(bleeding-web_sql_injection.rules)
2006599 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass INSERT
(bleeding-web_sql_injection.rules)
2006600 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass DELETE
(bleeding-web_sql_injection.rules)
2006601 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass ASCII
(bleeding-web_sql_injection.rules)
2006602 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass UPDATE
(bleeding-web_sql_injection.rules)
2007571 - BLEEDING-EDGE POLICY Remote Desktop Connection via non RDP Port
(bleeding-policy.rules)
[///] Modified active rules: [///]
2001329 - BLEEDING-EDGE POLICY RDP connection request (bleeding-policy.rules)
2001330 - BLEEDING-EDGE POLICY RDP connection confirm (bleeding-policy.rules)
2001331 - BLEEDING-EDGE POLICY RDP disconnect request (bleeding-policy.rules)
2400000 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound
(bleeding-drop.rules)
2400001 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound
(bleeding-drop.rules)
2400002 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound
(bleeding-drop.rules)
2400003 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound
(bleeding-drop.rules)
2400004 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound
(bleeding-drop.rules)
2401000 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING
SOURCE (bleeding-drop-BLOCK.rules)
2401001 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING
SOURCE (bleeding-drop-BLOCK.rules)
2401002 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING
SOURCE (bleeding-drop-BLOCK.rules)
2401003 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING
SOURCE (bleeding-drop-BLOCK.rules)
2401004 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING
SOURCE (bleeding-drop-BLOCK.rules)
2402000 - BLEEDING-EDGE DROP Dshield Block Listed Source
(bleeding-dshield.rules)
2403000 - BLEEDING-EDGE DROP Dshield Block Listed Source - BLOCKING
(bleeding-dshield-BLOCK.rules)
2404000 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 1)
(bleeding-botcc.rules)
2404001 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 2)
(bleeding-botcc.rules)
2404002 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 3)
(bleeding-botcc.rules)
2404003 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 4)
(bleeding-botcc.rules)
2404004 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 5)
(bleeding-botcc.rules)
2404005 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 6)
(bleeding-botcc.rules)
2404006 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 7)
(bleeding-botcc.rules)
2404007 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 8)
(bleeding-botcc.rules)
2404008 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 9)
(bleeding-botcc.rules)
2404009 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 10)
(bleeding-botcc.rules)
2404010 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 11)
(bleeding-botcc.rules)
2404011 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 12)
(bleeding-botcc.rules)
2404012 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 13)
(bleeding-botcc.rules)
2405000 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 1) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405001 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 2) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405002 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 3) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405003 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 4) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405004 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 5) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405005 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 6) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405006 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 7) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405007 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 8) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405008 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 9) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405009 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 10) - BLOCKING
SOURCE (bleeding-botcc-BLOCK.rules)
2405010 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 11) - BLOCKING
SOURCE (bleeding-botcc-BLOCK.rules)
2405011 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 12) - BLOCKING
SOURCE (bleeding-botcc-BLOCK.rules)
2405012 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 13) - BLOCKING
SOURCE (bleeding-botcc-BLOCK.rules)
[---] Removed rules: [---]
2002997 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list http)
(bleeding-web_sql_injection.rules)
2003098 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list ftp)
(bleeding-web_sql_injection.rules)
2003935 - BLEEDING-EDGE WEB PHP Remote File Inclusion (monster list php)
(bleeding-web_sql_injection.rules)
2006591 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid SELECT (bleeding-web.rules)
2006592 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid UNION SELECT
(bleeding-web.rules)
2006593 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid INSERT (bleeding-web.rules)
2006594 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid DELETE (bleeding-web.rules)
2006595 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid ASCII (bleeding-web.rules)
2006596 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp agentid UPDATE (bleeding-web.rules)
2006597 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass SELECT (bleeding-web.rules)
2006598 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass UNION SELECT (bleeding-web.rules)
2006599 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass INSERT (bleeding-web.rules)
2006600 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass DELETE (bleeding-web.rules)
2006601 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass ASCII (bleeding-web.rules)
2006602 - BLEEDING-EDGE WEB Novell ZENworks Patch Management (ZPM) SQL
Injection Attempt -- downloadreport.asp pass UPDATE (bleeding-web.rules)
[+++] Added non-rule lines: [+++]
-> Added to bleeding-drop-BLOCK.rules (1):
# VERSION 285
-> Added to bleeding-drop.rules (1):
# VERSION 285
-> Added to bleeding-policy.rules (2):
#By Scott Melnick
#Users can connect to remote machines by port forwarding 3389 through
personal routers.
-> Added to bleeding-sid-msg.map (4):
2001329 || BLEEDING-EDGE POLICY RDP connection request
2001330 || BLEEDING-EDGE POLICY RDP connection confirm
2001331 || BLEEDING-EDGE POLICY RDP disconnect request
2007571 || BLEEDING-EDGE POLICY Remote Desktop Connection via non RDP
Port
-> Added to bleeding-web.rules (2):
#Split into 2 rules, so they can be prequalified with a stronger uri
check
#Adding a php version, as pointed out by James Riden php also
recognizes this
[---] Removed non-rule lines: [---]
-> Removed from bleeding-drop-BLOCK.rules (1):
# VERSION 284
-> Removed from bleeding-drop.rules (1):
# VERSION 284
-> Removed from bleeding-sid-msg.map (3):
2001329 || BLEEDING-EDGE RDP connection request
2001330 || BLEEDING-EDGE RDP connection confirm
2001331 || BLEEDING-EDGE RDP disconnect request
-> Removed from bleeding-web_sql_injection.rules (3):
#By Blake Hartstein at Demarc
#Split into 2 rules, so they can be prequalified with a stronger uri
check
#Adding a php version, as pointed out by James Riden php also
recognizes this
-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems? Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Bleeding Edge Threats Daily Signature Changes, bleeding |
|---|---|
| Next by Date: | [Snort-sigs] Bleeding Edge Threats Daily Signature Changes, bleeding |
| Previous by Thread: | [Snort-sigs] Bleeding Edge Threats Daily Signature Changes, bleeding |
| Next by Thread: | [Snort-sigs] Bleeding Edge Threats Daily Signature Changes, bleeding |
| Indexes: | [Date] [Thread] [Top] [All Lists] |