CVS: snort - cazz
Brian Caswell <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.cvs |
|---|---|
| Message-ID | <[email protected]> |
CVSROOT: /cvsroot/snort Module name: snort Changes by: cazz@sc8-pr-cvs1. 2003/06/13 11:25:07 Modified files: etc : sid sid-msg.map rules : attack-responses.rules backdoor.rules ftp.rules icmp-info.rules misc.rules netbios.rules policy.rules rpc.rules smtp.rules web-cgi.rules web-iis.rules web-misc.rules web-php.rules Log message: * added sid:2123 - ATTACK-RESPONSES Microsoft cmd.exe banner * added sid:2124 - BACKDOOR Remote PC Access connection attempt * added sid:2125 - FTP CWD C:\\ * added sid:2126 - MISC Microsoft PPTP Start Control Request buffer overflow attempt * added sid:2127 - WEB-CGI ikonboard.cgi access * added sid:2128 - WEB-CGI swsrv.cgi access * added sid:2129 - WEB-IIS nsiislog.dll access * added sid:2130 - WEB-IIS IISProtect siteadmin.asp access * added sid:2131 - WEB-IIS IISProtect access * added sid:2132 - WEB-IIS Synchrologic Email Accelerator userid list access attempt * added sid:2133 - WEB-IIS MS BizTalk server access * added sid:2134 - WEB-IIS register.asp access * added sid:2135 - WEB-MISC philboard.mdb access * added sid:2136 - WEB-MISC philboard_admin.asp authentication bypass attempt * added sid:2137 - WEB-MISC philboard_admin.asp access * added sid:2138 - WEB-MISC logicworks.ini access * added sid:2139 - WEB-MISC /*.shtml access * added sid:2140 - WEB-PHP p-news.php access * added sid:2141 - WEB-PHP shoutbox.php directory traversal attempt * added sid:2142 - WEB-PHP shoutbox.php access * added sid:2143 - WEB-PHP b2 cafelog gm-2-b2.php remote command execution attempt * added sid:2144 - WEB-PHP b2 cafelog gm-2-b2.php access * added sid:2145 - WEB-PHP TextPortal admin.php default password (admin) attempt * added sid:2146 - WEB-PHP TextPortal admin.php default password (12345) attempt * added sid:2147 - WEB-PHP BLNews objects.inc.php4 remote command execution attempt * added sid:2148 - WEB-PHP BLNews objects.inc.php4 access * added sid:2149 - WEB-PHP Turba status.php access * added sid:2150 - WEB-PHP ttCMS header.php remote command execution attempt * added sid:2151 - WEB-PHP ttCMS header.php access * added sid:2152 - WEB-PHP test.php access * added sid:2153 - WEB-PHP autohtml.php directory traversal attempt * added sid:2154 - WEB-PHP autohtml.php access * added sid:2155 - WEB-PHP ttforum remote command execution attempt * added sid:2156 - WEB-MISC mod_gzip_status access * added sid:2157 - WEB-IIS IISProtect GlobalAdmin.asp access * added sid:2158 - MISC BGP invalid length * added sid:2159 - MISC BGP invalid type (0) * added sid:2160 - VIRUS OUTBOUND .exe file attachment * added sid:2161 - VIRUS OUTBOUND .doc file attachment * added sid:2162 - VIRUS OUTBOUND .hta file attachment * added sid:2163 - VIRUS OUTBOUND .chm file attachment * added sid:2164 - VIRUS OUTBOUND .reg file attachment * added sid:2165 - VIRUS OUTBOUND .ini file attachment * added sid:2166 - VIRUS OUTBOUND .bat file attachment * added sid:2167 - VIRUS OUTBOUND .diz file attachment * added sid:2168 - VIRUS OUTBOUND .cpp file attachment * added sid:2169 - VIRUS OUTBOUND .dll file attachment * added sid:2170 - VIRUS OUTBOUND .vxd file attachment * added sid:2171 - VIRUS OUTBOUND .sys file attachment * added sid:2172 - VIRUS OUTBOUND .com file attachment * added sid:2173 - VIRUS OUTBOUND .hsq file attachment * added sid:2174 - NETBIOS SMB winreg access * added sid:2175 - NETBIOS SMB winreg access (unicode) * added sid:2176 - NETBIOS SMB Startup Folder access attempt * added sid:2177 - NETBIOS SMB Startup Folder access attempt (unicode) ------------------------------------------------------- This SF.NET email is sponsored by: eBay Great deals on office technology -- on eBay now! Click here: http://adfarm.mediaplex.com/ad/ck/711-11697-6916-5