alert tcp $EXTERNAL_NET any -> $HOME_NET 41080 (msg:"ET WEB_SPECIFIC_APPS Symantec Messaging Gateway 9.5.3-3 - Arbitrary file download 2"; flow:to_server,established; content:"/brightmail/admin/restore/download.do?"; http_uri; content:"&localBackupFileSelection="; http_uri; content:"|2e 2e 2f|"; depth:200; reference:url,www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120827_00; classtype:attempted-user; sid:2016119; rev:2;)
Added 2012-12-28 17:51:13 UTC