alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET
P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; depth:8; content:"X-Ultrapeer|3a| True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; classtype:policy-violation; sid:2002761; rev:6; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2018-09-13 19:38:13 UTC
Added 2018-09-13 17:52:56 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET
P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; depth:8; content:"X-Ultrapeer|3a| True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; classtype:policy-violation; sid:2002761; rev:6; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2017-08-07 20:56:11 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET
P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; depth:8; content:"X-Ultrapeer|3a| True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; classtype:policy-violation; sid:2002761; rev:6;)
Added 2011-10-12 19:12:14 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET
P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; depth:8; content:"X-Ultrapeer|3a| True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; sid:2002761; rev:6;)
Added 2011-09-14 22:25:08 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET
P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; depth:8; content:"X-Ultrapeer|3a| True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/P2P/P2P_Gnutella; sid:2002761; rev:6;)
Added 2011-02-04 17:22:02 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET
P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; offset:0; depth:8; content:"X-Ultrapeer\: True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/P2P/P2P_Gnutella; sid:2002761; rev:3;)
Added 2009-02-10 20:53:06 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET
P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; offset:0; depth:8; content:"X-Ultrapeer\: True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; reference:url,doc.emergingthreats.net/bin/view/Main/2002761; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/P2P/P2P_Gnutella; sid:2002761; rev:3;)
Added 2009-02-10 20:53:06 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET
P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; offset:0; depth:8; content:"X-Ultrapeer\: True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; sid:2002761; rev:2;)
Added 2008-01-29 10:56:39 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET
P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; offset:0; depth:8; content:"X-Ultrapeer\: True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; sid:2002761; rev:2;)
Added 2008-01-29 10:56:39 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg: "BLEEDING-EDGE
P2P? Gnutella TCP Ultrapeer Traffic"; flow: established,to_server; content:"GNUTELLA"; offset:0; depth:8; content:"X-Ultrapeer\: True"; nocase; threshold: type both,track by_src,count 5,seconds 3600; classtype: policy-violation; sid:2002761; rev:1;)