<?xml version="1.0" encoding="iso-8859-15" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:wiki="http://purl.org/rss/1.0/modules/wiki/" ><channel rdf:about="http://doc.emergingthreats.net/bin/view/Main">
<title>TWiki's Main web</title>
  <link>http://doc.emergingthreats.net/bin/view/Main</link>
  <description>The web for users, groups and offices. TWiki is an Enterprise Collaboration Platform.</description>
<image rdf:resource="http://doc.emergingthreats.net/pub/TWiki/TWikiLogos/T-logo-140x40-t.gif" />
  <dc:language>en-us</dc:language>
  <dc:rights>Copyright 2008 Emerging Threats and Contributing Authors</dc:rights>
  <dc:publisher>Emerging Admin [jonkman@emergingthreats.net]</dc:publisher>
  <dc:creator>The contributing authors of TWiki</dc:creator>
  <dc:source>TWiki</dc:source>
  <items>
    <rdf:Seq>
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008468" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008469" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008470" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008446" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008466" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008077" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008467" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008176" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008175" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008465" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2001854" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008372" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2001852" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008457" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008371" />
      <rdf:li rdf:resource="http://doc.emergingthreats.net/bin/view/Main/2008423" />
    </rdf:Seq>
  </items>
</channel>
<image rdf:about="http://doc.emergingthreats.net/pub/TWiki/TWikiLogos/T-logo-140x40-t.gif">
  <title>Powered by TWiki.Main</title>
  <link>http://doc.emergingthreats.net/bin/view/Main</link>
  <url>http://doc.emergingthreats.net/pub/TWiki/TWikiLogos/T-logo-140x40-t.gif</url>
</image>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008468">
  <title>2008468</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008468</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN LDPinch Checkin Flowbit set"; flow:established,to server; content:"POST "; depth:5; uricontent ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-24T19:05:03Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008469">
  <title>2008469</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008469</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN LDPinch Checkin v2"; flowbits:isset,ET.PINCH; flow:established,to server; content:"a "; nocase ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-24T19:05:03Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008470">
  <title>2008470</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008470</link>
  <description>alert udp any 53 $HOME NET any (msg:"ET CURRENT EVENTS Excessive NXDOMAIN responses Possible DNS Poisoning Attempt Backscatter"; byte test:1, ,128,2; byte test ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-24T19:05:03Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008446">
  <title>2008446</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008446</link>
  <description>alert udp any 53 $DNS SERVERS any (msg:"ET CURRENT EVENTS Excessive DNS Responses with 1 or more RR's (100 in 10 seconds) possible Cache Poisoning Attempt"; ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-24T16:19:45Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008466">
  <title>2008466</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008466</link>
  <description>alert udp any 53 $HOME NET any (msg:"ET CURRENT EVENTS Excessive NXDOMAIN Responses (not authoritative)"; byte test:1, ,128,2; byte test:1, ,3, 1,relative; threshold ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-24T15:52:36Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008077">
  <title>2008077</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008077</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET CURRENT EVENTS Possible Storm Worm EXE Request (postcard.exe)"; flow:established,to server; content: ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-24T15:44:46Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008467">
  <title>2008467</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008467</link>
  <description>alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB Possible SQL Injection Attempt Danmec related (declare)"; flow:established,to server; uricontent ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-24T13:48:51Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008176">
  <title>2008176</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008176</link>
  <description>alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB Possible SQL Injection (exec)"; flow:established,to server; uricontent:"exec("; nocase; classtype ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-24T13:48:51Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008175">
  <title>2008175</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008175</link>
  <description>alert tcp $EXTERNAL NET any $HOME NET $HTTP PORTS (msg:"ET WEB Possible SQL Injection (varchar)"; flow:established,to server; uricontent:"varchar("; nocase; classtype ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-24T13:48:51Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008465">
  <title>2008465</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008465</link>
  <description>alert udp $HOME NET 1024: $EXTERNAL NET 1024: (msg:"ET TROJAN Backdoor Possible Backdoor.Cow Varient (Backdoor.Win32.Agent.lam) C C traffic"; content:" 6C 3C " ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-23T17:17:48Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2001854">
  <title>2001854</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2001854</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE EZULA Spyware User Agent"; flow: established,to server; content:"User Agent\: ezula"; classtype ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-23T14:00:23Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008372">
  <title>2008372</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008372</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Adsincontext.com Related Spyware User Agent (Connector v1.2)"; flow: established; content:"User ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-23T14:00:23Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2001852">
  <title>2001852</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2001852</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE 404Search Spyware User Agent"; flow:established,to server; content:"User Agent\: 404search"; ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-23T14:00:23Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008457">
  <title>2008457</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008457</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Deepdo Toolbar User Agent (FavUpdate)"; flow:established,to server; content:" 0d 0a User Agent ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-23T14:00:23Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008371">
  <title>2008371</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008371</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Likely Ad ware installation phoning home (success and NSISDL User Agent)"; flow: established ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-23T14:00:23Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.emergingthreats.net/bin/view/Main/2008423">
  <title>2008423</title>
  <link>http://doc.emergingthreats.net/bin/view/Main/2008423</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Suspicious User Agent (CFS Agent)"; flow:established,to server; content:" 0d 0a User Agent\: ... (last changed by TWikiGuest)</description>
  <dc:date>2008-07-23T14:00:23Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.emergingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<!-- <ul>
<li> Set SKIN = rss
</li></ul> 
--></rdf:RDF>