[Snort-sigs] Has a rule been created for this?

Adam Richards adam.richards at ...3481...
Tue Apr 13 12:45:11 EDT 2010


Adam Richards,CISSP | CEH

-----Original Message-----
From: evilghost at ...3397... [mailto:evilghost at ...3397...] 
Sent: Tuesday, April 13, 2010 11:40 AM
To: Adam Richards
Cc: snort-sigs at lists.sourceforge.net
Subject: Re: [Snort-sigs] Has a rule been created for this?

PHP is server-side, what behavior were you wanting to alert on 
specifically? Best I can figure you want to detect on upload of this 
file to an HTTPd, correct?


Adam Richards wrote:
> I have been seeing this obfuscated php file around a lot lately and I
> wasn't sure if there was a rule yet for it. There are a few unique
> strings in it that we can look for. 
> n&ct=clnk&gl=us
> Adam Richards,CISSP | CEH
> Download Intel® Parallel Studio Eval
> Try the new software tools for yourself. Speed compiling, find bugs
> proactively, and fine-tune applications for parallel performance.
> See why Intel Parallel Studio got high marks during beta.
> http://p.sf.net/sfu/intel-sw-dev
> _______________________________________________
> Snort-sigs mailing list
> Snort-sigs at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/snort-sigs

More information about the Snort-sigs mailing list