[Snort-sigs] new rule for detect DOS Trend Micro ServerProtect EarthAgent attempt

rmkml rmkml at ...324...
Thu Dec 15 01:04:00 EST 2005


Hi,

please check and maybe add this new rule :

dos.rules:alert tcp $EXTERNAL_NET any <> $HOME_NET 5005 (msg:"DOS Trend 
Micro ServerProtect EarthAgent attempt"; content:"|21 43 65 87|"; 
reference:cve,2005-1928; classtype:attempted-dos; )

this rule is NOT tested !

Improve/comments are welcome.

Regards
Rmkml




More information about the Snort-sigs mailing list