CVS: snort - cazz

Brian Caswell <[email protected]>
Newsgroups gmane.comp.security.ids.snort.cvs
Message-ID <[email protected]>
CVSROOT:	/cvsroot/snort
Module name:	snort
Changes by:	cazz@sc8-pr-cvs1.	2003/06/13 11:25:07

Modified files:
	etc            : sid sid-msg.map 
	rules          : attack-responses.rules backdoor.rules ftp.rules 
	                 icmp-info.rules misc.rules netbios.rules 
	                 policy.rules rpc.rules smtp.rules web-cgi.rules 
	                 web-iis.rules web-misc.rules web-php.rules 

Log message:
* added sid:2123 - ATTACK-RESPONSES Microsoft cmd.exe banner
* added sid:2124 - BACKDOOR Remote PC Access connection attempt
* added sid:2125 - FTP CWD C:\\
* added sid:2126 - MISC Microsoft PPTP Start Control Request buffer overflow attempt
* added sid:2127 - WEB-CGI ikonboard.cgi access
* added sid:2128 - WEB-CGI swsrv.cgi access
* added sid:2129 - WEB-IIS nsiislog.dll access
* added sid:2130 - WEB-IIS IISProtect siteadmin.asp access
* added sid:2131 - WEB-IIS IISProtect access
* added sid:2132 - WEB-IIS Synchrologic Email Accelerator userid list access attempt
* added sid:2133 - WEB-IIS MS BizTalk server access
* added sid:2134 - WEB-IIS register.asp access
* added sid:2135 - WEB-MISC philboard.mdb access
* added sid:2136 - WEB-MISC philboard_admin.asp authentication bypass attempt
* added sid:2137 - WEB-MISC philboard_admin.asp access
* added sid:2138 - WEB-MISC logicworks.ini access
* added sid:2139 - WEB-MISC /*.shtml access
* added sid:2140 - WEB-PHP p-news.php access
* added sid:2141 - WEB-PHP shoutbox.php directory traversal attempt
* added sid:2142 - WEB-PHP shoutbox.php access
* added sid:2143 - WEB-PHP b2 cafelog gm-2-b2.php remote command execution attempt
* added sid:2144 - WEB-PHP b2 cafelog gm-2-b2.php access
* added sid:2145 - WEB-PHP TextPortal admin.php default password (admin) attempt
* added sid:2146 - WEB-PHP TextPortal admin.php default password (12345) attempt
* added sid:2147 - WEB-PHP BLNews objects.inc.php4 remote command execution attempt
* added sid:2148 - WEB-PHP BLNews objects.inc.php4 access
* added sid:2149 - WEB-PHP Turba status.php access
* added sid:2150 - WEB-PHP ttCMS header.php remote command execution attempt
* added sid:2151 - WEB-PHP ttCMS header.php access
* added sid:2152 - WEB-PHP test.php access
* added sid:2153 - WEB-PHP autohtml.php directory traversal attempt
* added sid:2154 - WEB-PHP autohtml.php access
* added sid:2155 - WEB-PHP ttforum remote command execution attempt
* added sid:2156 - WEB-MISC mod_gzip_status access
* added sid:2157 - WEB-IIS IISProtect GlobalAdmin.asp access
* added sid:2158 - MISC BGP invalid length
* added sid:2159 - MISC BGP invalid type (0)
* added sid:2160 - VIRUS OUTBOUND .exe file attachment
* added sid:2161 - VIRUS OUTBOUND .doc file attachment
* added sid:2162 - VIRUS OUTBOUND .hta file attachment
* added sid:2163 - VIRUS OUTBOUND .chm file attachment
* added sid:2164 - VIRUS OUTBOUND .reg file attachment
* added sid:2165 - VIRUS OUTBOUND .ini file attachment
* added sid:2166 - VIRUS OUTBOUND .bat file attachment
* added sid:2167 - VIRUS OUTBOUND .diz file attachment
* added sid:2168 - VIRUS OUTBOUND .cpp file attachment
* added sid:2169 - VIRUS OUTBOUND .dll file attachment
* added sid:2170 - VIRUS OUTBOUND .vxd file attachment
* added sid:2171 - VIRUS OUTBOUND .sys file attachment
* added sid:2172 - VIRUS OUTBOUND .com file attachment
* added sid:2173 - VIRUS OUTBOUND .hsq file attachment
* added sid:2174 - NETBIOS SMB winreg access
* added sid:2175 - NETBIOS SMB winreg access (unicode)
* added sid:2176 - NETBIOS SMB Startup Folder access attempt
* added sid:2177 - NETBIOS SMB Startup Folder access attempt (unicode)



-------------------------------------------------------
This SF.NET email is sponsored by: eBay
Great deals on office technology -- on eBay now! Click here:
http://adfarm.mediaplex.com/ad/ck/711-11697-6916-5
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.