<?xml version="1.0" encoding="iso-8859-1"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>EmergingThreats's Main web</title>
<subtitle>The web for users, groups and offices. TWiki is an Enterprise Collaboration Platform.</subtitle>
<link rel="self" type="application/atom+xml" href="http://doc.emergingthreats.net/bin/view/Main/WebAtom"/>
<id>http://doc.emergingthreats.net/bin/view/Main</id>
<rights>Copyright 2013 Emerging Threats and Contributing Authors</rights>
<updated>2013-05-24T23:11:21Z</updated>
<entry>
 <title>2016923</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016923?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016923</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS KaiXin Exploit Kit Java Class 1 May 24 2013`; flow:to client,established; file data; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016926</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016926?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016926</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS KaiXin Exploit Landing Page 2 May 24 2013`; flow:to client,established; file data; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2015624</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2015624?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2015624</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET any (msg:`ET TROJAN Backdoor.Win32.Gh0st Checkin (5 12 Byte keyword)`; flow:to server,established; dsize: Added 2013 05 24 ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016928</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016928?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016928</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS HellSpawn EK Landing 2 May 24 2013`; flow:to client,established; file data; content:`FlashPlayer ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016922</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016922?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016922</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET any (msg:`ET TROJAN Backdoor family PCRat/Gh0st CnC traffic`; flow:to server,established; byte jump:4,5,from beginning,little ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016384</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016384?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016384</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:`ET WEB SPECIFIC APPS WordPress CommentLuv Plugin ajax nonce Parameter XSS Attempt`; flow:established ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016929</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016929?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016929</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:`ET CURRENT EVENTS Possible HellSpawn EK Fake Flash May 24 2013`; flow:to server,established; content:`/FlashPlayer ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016832</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016832?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016832</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET any (msg:`ET CURRENT EVENTS HellSpawn EK Requesting Jar`; flow:established,to server; content:`/j21.jar`; http uri; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016930</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016930?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016930</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:`ET CURRENT EVENTS Possible HellSpawn EK Java Artifact May 24 2013`; flow:to server,established; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016924</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016924?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016924</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS KaiXin Exploit Kit Java Class 2 May 24 2013`; flow:to client,established; file data; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2015575</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2015575?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2015575</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS KaiXin Exploit Kit Java Class`; flow:to client,established; file data; content:`Gond` ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016925</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016925?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016925</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS KaiXin Exploit Landing Page 1 May 24 2013`; flow:to client,established; file data; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016927</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016927?t=2013-05-24T23:11:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016927</id>
 <updated>2013-05-24T23:11:21Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS HellSpawn EK Landing 1 May 24 2013`; flow:to client,established; file data; content:`function ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016918</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016918?t=2013-05-24T00:38:13Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016918</id>
 <updated>2013-05-24T00:38:13Z</updated>
 <summary>alert tcp $EXTERNAL NET any $HTTP SERVERS $HTTP PORTS (msg:`ET WEB SERVER Possible NGINX Overflow CVE 2013 2028 Exploit Specific`; flow:established,to server; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016921</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016921?t=2013-05-23T23:39:37Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016921</id>
 <updated>2013-05-23T23:39:37Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:`ET INFO Suspicious Mozilla UA with no Space after colon`; flow:established,to server; content:`User Agent ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2016919</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2016919?t=2013-05-23T23:39:37Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2016919</id>
 <updated>2013-05-23T23:39:37Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:`ET CURRENT EVENTS Malicious Redirect URL`; flow:established,to server; content:`/8gcf744Waxolp752.php`; ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
 <!-- <ul>
<li> Set SKIN = rssatom
</li></ul> 
-->
</feed>