[Snort-sigs] new rule for detect DOS Counter Strike 2D attempt

rmkml rmkml at ...324...
Wed Dec 14 09:18:02 EST 2005


please check and maybe add this new rule :

dos.rules:alert udp $EXTERNAL_NET any <> $HOME_NET 36963 (msg:"DOS Counter Strike 2D attempt"; content:"|FA FA 0D 0A|"; content:"|CE 7B E2 45 63 90 00 00|"; reference:osvdb,19492; reference:url,www.securiteam.com/exploits/5UP0E0UGVO.html; classtype:attempted-dos; )

look url on securiteam for more info.

Improve/comments are welcome.


More information about the Snort-sigs mailing list