Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

Re: [Snort-sigs] Crusoe Researches offer new rule for detecting Safari W

Subject: Re: [Snort-sigs] Crusoe Researches offer new rule for detecting Safari Windows file: DoS
Date: Thu, 24 Apr 2008 17:37:35 -0400
this rule wont work.  if i remember correctly, i dont think you want ur
destination variable as http_servers...

On Tue, Apr 22, 2008 at 7:07 AM, rmkml <rmkml@free.fr> wrote:

Hi,

Crusoe Researches offering a new rule for detecting Safari Windows DoS:
 http://www.Crusoe-Researches.com/en/safariwindowsfiledos.txt

Credits:
Crusoe Researches
http://www.Crusoe-Researches.com
contact@Crusoe-Researches.com
=> Crusoe Researches have more than 2806 UNIQ 'snort' rules for Commercial
Access
        (Contact me directly if you are interested)

Crusoe Researches support Bro idps v1.3.25 project format rules
(http://www.bro-ids.org/):
signature sid-92806 {
  ip-proto == tcp
  event "WEB-CLIENT Safari file:// and % attempt"
  tcp-state established,responder
  http-body /.*[^a-zA-Z0-9][fF][iI][lL][eE]\:\/\/(.){0,2}\%/
  }


Azwalaro new nidps open source project (WireShark based)
 http://www.Crusoe-Researches.com/azwalaro/
 azwalaro@Crusoe-Researches.com
 http matches "(?i)[^a-z0-9]file://(.){0,2}%"

Regards
Rmkml
Crusoe-Researches.com

-------------------------------------------------------------------------
This SF.net email is sponsored by the 2008 JavaOne(SM) Conference
Don't miss this year's exciting event. There's still time to save $100.
Use priority code J8TL2D2.

http://ad.doubleclick.net/clk;198757673;13503038;p?http://java.sun.com/javaone
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs

-------------------------------------------------------------------------
This SF.net email is sponsored by the 2008 JavaOne(SM) Conference 
Don't miss this year's exciting event. There's still time to save $100. 
Use priority code J8TL2D2. 
http://ad.doubleclick.net/clk;198757673;13503038;p?http://java.sun.com/javaone
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
<Prev in Thread] Current Thread [Next in Thread>