[Snort-sigs] new rule for detect DOS Counter Strike 2D attempt
rmkml at ...324...
Wed Dec 14 09:18:02 EST 2005
please check and maybe add this new rule :
dos.rules:alert udp $EXTERNAL_NET any <> $HOME_NET 36963 (msg:"DOS Counter Strike 2D attempt"; content:"|FA FA 0D 0A|"; content:"|CE 7B E2 45 63 90 00 00|"; reference:osvdb,19492; reference:url,www.securiteam.com/exploits/5UP0E0UGVO.html; classtype:attempted-dos; )
look url on securiteam for more info.
Improve/comments are welcome.
More information about the Snort-sigs