r1 - 07 Jun 2008 - 00:49:01 - TWikiGuestYou are here: TWiki >  Main Web > 2007671

alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET POLICY Binary Download Smaller than 1 MB Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:7;)

Added 2008-06-06 20:49:01 UTC

 


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET POLICY Binary Download Smaller than 1 MB Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:7;)

Added 2008-06-06 20:49:01 UTC


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:6;)

Added 2008-01-31 18:48:10 UTC


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:6;)

Added 2008-01-31 18:48:10 UTC


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:5;)

Added 2007-11-09 01:01:50 UTC


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:5;)

Added 2007-11-09 01:01:50 UTC


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:3;)

Added 2007-11-08 23:46:05 UTC


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:3;)

Added 2007-11-08 23:46:05 UTC


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:2;)

Added 2007-11-08 04:28:13 UTC


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:2;)

Added 2007-11-08 04:28:13 UTC


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:1;)

Added 2007-11-08 01:16:52 UTC


Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r1 | More topic actions
 
Emerging Threats
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback