alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; depth:8; content:"X-Ultrapeer|3a| True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; classtype:policy-violation; sid:2002761; rev:6; metadata:created_at 2010_07_30, updated_at 2010_07_30;)

Added 2017-08-07 20:56:11 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; depth:8; content:"X-Ultrapeer|3a| True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; classtype:policy-violation; sid:2002761; rev:6;)

Added 2011-10-12 19:12:14 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; depth:8; content:"X-Ultrapeer|3a| True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; sid:2002761; rev:6;)

Added 2011-09-14 22:25:08 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; depth:8; content:"X-Ultrapeer|3a| True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/P2P/P2P_Gnutella; sid:2002761; rev:6;)

Added 2011-02-04 17:22:02 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; offset:0; depth:8; content:"X-Ultrapeer\: True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/P2P/P2P_Gnutella; sid:2002761; rev:3;)

Added 2009-02-10 20:53:06 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; offset:0; depth:8; content:"X-Ultrapeer\: True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/P2P/P2P_Gnutella; sid:2002761; rev:3;)

Added 2009-02-10 20:53:06 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; offset:0; depth:8; content:"X-Ultrapeer\: True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; sid:2002761; rev:2;)

Added 2008-01-29 10:56:39 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; offset:0; depth:8; content:"X-Ultrapeer\: True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; sid:2002761; rev:2;)

Added 2008-01-29 10:56:39 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg: "BLEEDING-EDGE P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; offset:0; depth:8; content:"X-Ultrapeer\: True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; sid:2002761; rev:1;)



Topic revision: r1 - 2017-08-08 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats