[Snort-sigs] Bleedingsnort.com Daily Update

bleeding at ...2727... bleeding at ...2727...
Fri Aug 4 21:00:12 EDT 2006


[***] Results from Oinkmaster started Fri Aug  4 21:00:12 2006 [***]

[+++]          Added rules:          [+++]

 2003068 - BLEEDING-EDGE Potential SSH Scan OUTBOUND (bleeding-scan.rules)
 2003069 - BLEEDING-EDGE POLICY Anonymous Proxy Traffic from Inside (bleeding-policy.rules)


[+++]  Enabled and modified rules:   [+++]

 2003040 - BLEEDING-EDGE POLICY PCMesh Anonymous Proxy client connect (bleeding-policy.rules)


[///]     Modified active rules:     [///]

 2400000 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
 2400001 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
 2400002 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
 2400003 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
 2400004 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound (bleeding-drop.rules)
 2401000 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
 2401001 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
 2401002 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
 2401003 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)
 2401004 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING SOURCE (bleeding-drop-BLOCK.rules)


[+++]      Added non-rule lines:     [+++]

     -> Added to bleeding-policy.rules (2):
        #Only enable if you do not use and internal Proxy server with your
        #clients or change your HTTP_PORTS to match your Proxy server port

     -> Added to bleeding-sid-msg.map (3):
        2003040 || BLEEDING-EDGE POLICY PCMesh Anonymous Proxy client connect
        2003068 || BLEEDING-EDGE Potential SSH Scan OUTBOUND || url,www.whitedust.net/article/27/Recent%20SSH%20Brute-Force%20Attacks/
        2003069 || BLEEDING-EDGE POLICY Anonymous Proxy Traffic from Inside

[---]     Removed non-rule lines:    [---]

     -> Removed from bleeding-sid-msg.map (1):
        2003040 || BLEEDING-EDGE PCMesh Anonymous Proxy Traffic





More information about the Snort-sigs mailing list