alert tcp $HOME_NET any -> $EXTERNAL_NET 6661:6668 (msg: "ET ATTACK RESPONSE IRC - dns request on non-std port"; flow: to_server,established; content:"USERHOST "; nocase; offset: 0; depth: 9; tag: session,300,seconds; classtype: policy-violation; sid: 2000352; rev:6;)
Added 2008-01-23 10:46:27 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET 6661:6668 (msg: "ET ATTACK RESPONSE IRC - dns request on non-std port"; flow: to_server,established; content:"USERHOST "; nocase; offset: 0; depth: 9; tag: session,300,seconds; classtype: policy-violation; sid: 2000352; rev:6;)
Added 2008-01-23 10:46:27 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET 6661:6668 (msg: "BLEEDING-EDGE ATTACK RESPONSE IRC - dns request on non-std port"; flow: to_server,established; content:"USERHOST "; nocase; offset: 0; depth: 9; tag: session,300,seconds; classtype: policy-violation; sid: 2000352; rev:5; )