Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-sigs] Crusoe Researches offer new rule for detecting Safari Windows file: DoS |
|---|---|
| Date: | Thu, 24 Apr 2008 17:37:35 -0400 |
this rule wont work. if i remember correctly, i dont think you want ur destination variable as http_servers... On Tue, Apr 22, 2008 at 7:07 AM, rmkml <rmkml@free.fr> wrote:
Hi, Crusoe Researches offering a new rule for detecting Safari Windows DoS: http://www.Crusoe-Researches.com/en/safariwindowsfiledos.txt Credits: Crusoe Researches http://www.Crusoe-Researches.com contact@Crusoe-Researches.com => Crusoe Researches have more than 2806 UNIQ 'snort' rules for Commercial Access (Contact me directly if you are interested) Crusoe Researches support Bro idps v1.3.25 project format rules (http://www.bro-ids.org/): signature sid-92806 { ip-proto == tcp event "WEB-CLIENT Safari file:// and % attempt" tcp-state established,responder http-body /.*[^a-zA-Z0-9][fF][iI][lL][eE]\:\/\/(.){0,2}\%/ } Azwalaro new nidps open source project (WireShark based) http://www.Crusoe-Researches.com/azwalaro/ azwalaro@Crusoe-Researches.com http matches "(?i)[^a-z0-9]file://(.){0,2}%" Regards Rmkml Crusoe-Researches.com ------------------------------------------------------------------------- This SF.net email is sponsored by the 2008 JavaOne(SM) Conference Don't miss this year's exciting event. There's still time to save $100. Use priority code J8TL2D2. http://ad.doubleclick.net/clk;198757673;13503038;p?http://java.sun.com/javaone _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
------------------------------------------------------------------------- This SF.net email is sponsored by the 2008 JavaOne(SM) Conference Don't miss this year's exciting event. There's still time to save $100. Use priority code J8TL2D2. http://ad.doubleclick.net/clk;198757673;13503038;p?http://java.sun.com/javaone
_______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Update to Adware gator rule 7829, Scott, Joshua J. |
|---|---|
| Next by Date: | Re: [Snort-sigs] Crusoe Researches offer new rule for detecting Safari Windows file: DoS, Ureleet |
| Previous by Thread: | Re: [Snort-sigs] Crusoe Researches offer new rule for detecting Safari Windows file: DoS, Ureleet |
| Next by Thread: | [Snort-sigs] SCADA PCAPs, Alex Kirk |
| Indexes: | [Date] [Thread] [Top] [All Lists] |