alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:"ET WEB SPECIFIC APPS Possible APC Network Management Card Cross Site Scripting Attempt"; flow:established ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpMyAdmin Remote Code Execution Proof of Concept (c )"; flow:established,to server ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpMyAdmin Remote Code Execution Proof of Concept (p )"; flow:established,to server ...
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET CURRENT EVENTS Possible Microsoft Internet Explorer iepeers.dll Remote Code Execution Attempt (CVE 2010 ...
alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:"ET WEB SPECIFIC APPS Joomla com perchagallery Component id Parameter UNION SELECT SQL Injection Attempt ...
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET WEB SPECIFIC APPS Ask.com Toolbar askBar.dll ActiveX ShortFormat Buffer Overflow Attempt"; flow:established ...
alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:"ET WEB SPECIFIC APPS Joomla com perchagallery Component id Parameter SELECT FROM SQL Injection Attempt ...
alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:"ET WEB SERVER PHP remote file include exploit attempt"; flow: to server,established; content:"GET " ...
alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:"ET WEB SPECIFIC APPS Joomla com perchagallery Component id Parameter UPDATE SET SQL Injection Attempt ...
alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:"ET WEB SPECIFIC APPS Joomla com perchagallery Component id Parameter DELETE FROM SQL Injection Attempt ...
alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:"ET WEB SERVER Oracle Reports OS Command Injection Attempt"; flow:established,to server; content:"GET ...
alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:"ET WEB SPECIFIC APPS SaurusCMS class.writeexcel worksheet.inc.php class path Remote File Inclusion Attempt ...
alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:"ET WEB SPECIFIC APPS SaurusCMS class.writeexcel workbook.inc.php class path Remote File Inclusion Attempt ...
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET WEB CLIENT Foxit Reader ActiveX control OpenFile method Heap Overflow Attempt"; flow:established,to client ...
alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:"ET WEB SPECIFIC APPS Joomla com perchagallery Component id Parameter INSERT INTO SQL Injection Attempt ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Potential Fake AV GET installer 1.exe"; flow:established,to server; content:"GET "; depth:4 ...
alert udp any any any 53 (msg:"ET CURRENT EVENTS DNS BIND 9 Dynamic Update DoS attempt"; byte test:1, ,40,2; byte test:1, ,0,5; byte test:1, ,0,1; content:" 00 ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Potential Fake AV GET installer.1.exe"; flow:established,to server; content:"GET "; depth:4 ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SERVER HP LaserJet Printer Cross Site Scripting Attempt"; flow:established,to server; uricontent ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS Cisco Adaptive Security Appliance WebVPN Cross Site Scripting Attempt"; flow:established ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 multiple login attempts"; flow:to server,established; content:"POST "; depth ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Downloader User Agent Detected (Windows Updates Manager 3.12 ...)"; flow:established,to server ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 Brute Force reg attempt (Bad flow 2)"; flowbits:isset,ET.phpBB3 test; flowbits ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 registration (Step1 GET)"; flow:to server,established; content:"GET "; depth ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET USER AGENTS badly formatted User Agent string (no closing parenthesis)"; flow:established,to server; ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 Brute Force reg attempt (Bad flow 2)"; flowbits:isnotset,ET.phpBB3 register ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 Brute Force reg attempt (Bad pf XXXXX)"; flowbits:isset,ET.phpBB3 test; flow ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN User agent DownloadNetFile Win32.small.hsh downloader"; flow:established,to server; content:"GET ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 possible spammer posting attempts"; flow:to server,established; content:"POST ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Clicker.BC User Agent Detected (linkrunner)"; flow:established,to server; content:" 0d 0a User ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 registration (Step4 POST)"; flow:to server,established; content:"POST "; depth ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 registration (Step3 GET)"; flow:to server,established; content:"GET "; depth ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 registration (Step2 POST)"; flow:to server,established; content:"POST "; depth ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET USER AGENTS Fake Mozilla UA on Forum Registration Spambot Outbound"; flow:established,to server; content ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 registration (Bogus Stage3 GET)"; flow:to server,established; content:"GET ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Win32.Tdss User Agent Detected (Mozzila)"; flow:established,to server; content:" 0d 0a User Agent ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET SCAN IBM NSA User Agent"; flow:established,to server; content:" 0d 0a User Agent\: "; nocase; content ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET USER AGENTS Fake Mozilla UA on Forum Registration Spambot Inbound"; flow:established,to server; content ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET USER AGENTS Suspicious Mozilla User Agent Inbound Likely Fake (Mozilla/5.0)"; flow:to server,established ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Suspicious User Agent Matcash related Trojan Downloader (Ismazo Advanced Loader)"; flow:established ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB SPECIFIC APPS phpBB3 Brute Force reg attempt (Bad pf XXXXX)"; flowbits:isset,ET.phpBB3 test; flow ...
alert tcp $EXTERNAL NET any $HOME NET 25 (msg:"ET EXPLOIT Possible SpamAssassin Milter Plugin Remote Arbitrary Command Injection Attempt"; flow:established,to server ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY msnbot User Agent"; flow:established,to server; content:" 0d 0a User Agent\: "; content:"msnbot ...
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET EXPLOIT Possible Foxit PDF Reader Authentication Bypass Attempt"; flow:established,to client; content ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY python.urllib User Agent Web Crawl"; flow:established,to server; content:" 0d 0a User Agent\: ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY POSSIBLE Web Crawl using Wget"; flow:established,to server; content:" 0d 0a User Agent 3A "; ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY googlebot User Agent"; flow:established,to server; content:" 0d 0a User Agent\: "; content:"googlebot ...
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET WEB CLIENT Foxit PDF Reader Buffer Overflow Attempt"; flow:established,to client; content:"PDF "; nocase ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Blackenergy Bot Checkin to C C (2)"; flow:to server,established; content:"POST "; depth:5; content ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY fetch User Agent"; flow:established,to server; content:" 0d 0a User Agent\: "; nocase; content ...
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET POLICY .pdf File Download With Unescape Method Defined Possibly Hostile"; flow:established,to client ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY Java Url Lib User Agent Web Crawl"; flow:established,to server; content:" 0d 0a User Agent\:" ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY Java Url Lib User Agent"; flow:established,to server; content:" 0d 0a User Agent\:"; nocase; ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY CURL User Agent"; flow:established,to server; content:" 0d 0a User Agent\: "; nocase; content ...
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET CURRENT EVENTS Nginx Serving PDF Possible hostile content (PDF)"; flow:established,from server; content ...
#alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET POLICY Hex Obfuscated arguments.callee Javascript Method in PDF Possibly Hostile PDF"; flow:established ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY POSSIBLE Web Crawl using Curl"; flow:established,to server; content:" 0d 0a User Agent\: "; nocase ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY python.urllib User Agent"; flow:established,to server; content:" 0d 0a User Agent\: "; nocase ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY libwww perl User Agent"; flow:established,to server; content:" 0d 0a User Agent\: "; nocase; ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET SCAN ProxyReconBot POST method to Mail"; content:"POST "; depth:5; content:" 3A 25 HTTP/"; within:200 ...
#alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY Yahoo Crawler User Agent"; flow:established,to server; content:" 0d 0a User Agent\: "; content ...
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET CURRENT EVENTS Possible Adobe Multimedia Doc.media.newPlayer Memory Corruption Attempt"; flow:to client ...
#alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET POLICY Possible Hex Obfuscation of Javascript Declaration Within PDF File Likely Hostile"; flow:established ...
alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET POLICY POSSIBLE Crawl using Fetch"; flow:established,to server; content:" 0d 0a User Agent\: "; nocase ...