[Snort-sigs] Bleedingsnort.com Daily Update

bleeding at ...2727... bleeding at ...2727...
Sun Feb 20 17:00:51 EST 2005


[***] Results from Oinkmaster started Sun Feb 20 20:00:11 2005 [***]

[+++]          Added rules:          [+++]

     -> Added to bleeding-web.rules (1):
        alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"BLEEDING-EDGE WEB PHP vBulletin Remote Command Execution Attempt"; flow:established,to_server; uricontent:"forumdisplay.php?"; nocase; uricontent:"comma="; nocase; classtype:web-application-attack; reference:bugtraq,12542; sid:2001738; rev:2;)

[+++]      Added non-rule lines:     [+++]

     -> Added to bleeding-sid-msg.map (1):
        2001738 || BLEEDING-EDGE WEB PHP vBulletin Remote Command Execution Attempt || bugtraq,12542

[---]     Removed non-rule lines:    [---]

     -> Removed from bleeding-web.rules (1):
        alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"BLEEDING-EDGE WEB PHP vBulletin Remote Command Execution Attempt"; flow:established,to_server; uricontent:"forumdisplay.php?"; nocase; uricontent:"comma="; nocase; classtype:web-application-attack; reference:bugtraq,12542; rev:1;)

[*] Added files: [*]
    None.





More information about the Snort-sigs mailing list