CVS log for snort/rules/rservices.rules |
|
Help |
Request diff between arbitrary revisions
a bunch of new rules. thanks microsoft, I didn't want to sleep on my birthday. Really.
a bunch of new rules. go sourcefire.
* dedup
* sync sync sync
* massive sync here too
* sync sync sync * go ruleteam go
* massive sync from head
* yet another sync, lets go forward in time, not backwards...
* massive rule updates (go ruleteam, go)
* Syncing changes for rules team
* lets try this *again*
* sync with sforge current
* updating 2.1.3 from sforge
* syncing up sfire with sforge 2.1 branch
* a ton of new rules, a bunch of updates too. 2447 || WEB-MISC ServletManager access || cve,CAN-2001-1195 || nessus,12122 2448 || WEB-MISC setinfo.hts access || bugtraq,9973 || nessus,12120 2449 || FTP ALLO overflow attempt || bugtraq,9953 2450 || CHAT Yahoo IM successful logon 2451 || CHAT Yahoo IM voicechat 2452 || CHAT Yahoo IM ping 2453 || CHAT Yahoo IM conference invitation 2454 || CHAT Yahoo IM conference logon success 2455 || CHAT Yahoo IM conference message 2456 || CHAT Yahoo IM file transfer request 2457 || CHAT Yahoo IM message 2458 || CHAT Yahoo IM successful chat join 2459 || CHAT Yahoo IM webcam offer invitation 2460 || CHAT Yahoo IM webcam request 2461 || CHAT Yahoo IM webcam watch 2462 || EXPLOIT IGMP IGAP account overflow attempt || bugtraq,9952 || cve,CAN-2004-0176 2463 || EXPLOIT IGMP IGAP message overflow attempt || bugtraq,9952 || cve,CAN-2004-0176 2464 || EXPLOIT EIGRP prefix length overflow attempt || bugtraq,9952 || cve,CAN-2004-0176 2465 || NETBIOS SMB-DS IPC$ share access 2466 || NETBIOS SMB-DS IPC$ share unicode access 2467 || NETBIOS SMB D$ share unicode access 2468 || NETBIOS SMB-DS D$ share access 2469 || NETBIOS SMB-DS D$ share unicode access 2470 || NETBIOS SMB C$ share unicode access 2471 || NETBIOS SMB-DS C$ share access 2472 || NETBIOS SMB-DS C$ share unicode access 2473 || NETBIOS SMB ADMIN$ share unicode access 2474 || NETBIOS SMB-DS ADMIN$ share access 2475 || NETBIOS SMB-DS ADMIN$ share unicode access 2476 || NETBIOS SMB-DS Create AndX Request winreg attempt 2477 || NETBIOS SMB-DS Create AndX Request winreg unicode attempt 2478 || NETBIOS SMB-DS DCERPC bind winreg attempt 2479 || NETBIOS SMB-DS DCERPC bind winreg unicode attempt 2480 || NETBIOS SMB-DS DCERPC shutdown unicode attempt 2481 || NETBIOS SMB-DS DCERPC shutdown unicode little endian attempt 2482 || NETBIOS SMB-DS DCERPC shutdown attempt 2483 || NETBIOS SMB-DS DCERPC shutdown little endian attempt 2484 || WEB-MISC source.jsp access || nessus,12119 2485 || WEB-CLIENT Nortan antivirus sysmspam.dll load attempt || bugtraq,9916 2486 || DOS ISAKMP invalid identification payload attempt || bugtraq,10004 2487 || SMTP WinZip MIME content-type buffer overflow || bugtraq,9758 2488 || SMTP WinZip MIME content-disposition buffer overflow || bugtraq,9758 2489 || EXPLOIT esignal STREAMQUOTE buffer overflow attempt || bugtraq,9978 2490 || EXPLOIT esignal SNAPQUOTE buffer overflow attempt || bugtraq,9978 2491 || NETBIOS SMB-DS DCERPC ISystemActivator unicode bind attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813 2492 || NETBIOS SMB DCERPC ISystemActivator bind attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813 2493 || NETBIOS SMB DCERPC ISystemActivator unicode bind attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813 2494 || NETBIOS DCEPRC ORPCThis request flood attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813 2495 || NETBIOS SMB DCEPRC ORPCThis request flood attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813 2496 || NETBIOS SMB-DS DCEPRC ORPCThis request flood attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813 2497 || IMAP invalid SSLv3 data version attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120 2498 || IMAP invalid SSLv3 timestamp attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120 2499 || MISC LDAP invalid SSLv3 timestamp attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120 2500 || MISC LDAP invalid SSLv3 data version attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120 2501 || POP3 invalid SSLv3 timestamp attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120 2502 || POP3 invalid SSLv3 data version attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120 2503 || SMTP invalid SSLv3 timestamp attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120 2504 || SMTP invalid SSLv3 data version attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120 2505 || WEB-MISC invalid SSLv3 data version attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120 2506 || WEB-MISC invalid SSLv3 timestamp attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120
* Added a ton of rules that include vulnerabilities in many high-profile security products, including Checkpoint & ISS gear (see below) * provided a single high-powered rule for detecting all of the evil virus emails * added even more docs. (Go Nigel) 2405 || WEB-PHP phptest.php access || bugtraq,9737 2406 || TELNET APC SmartSlot default admin account attempt || bugtraq,9681 2407 || WEB-MISC util.pl access || bugtraq,9748 2408 || WEB-MISC Invision Power Board search.pl access || bugtraq,9766 2409 || POP3 APOP USER overflow attempt || bugtraq,9794 2410 || WEB-PHP IGeneric Free Shopping Cart page.php access || bugtraq,9773 2411 || WEB-MISC Real Server DESCRIBE buffer overflow attempt || url,www.service.real.com/help/faq/security/rootexploit091103.html || bugtraq,8476 2412 || ATTACK-RESPONSES successful cross site scripting forced download attempt 2413 || EXPLOIT ISAKMP delete hash with empty hash attempt || bugtraq,9416 || bugtraq,CAN-2004-0164 2414 || EXPLOIT ISAKMP initial contact notification without SPI attempt || bugtraq,9416 || bugtraq,CAN-2004-0164 2415 || EXPLOIT ISAKMP second payload initial contact notification without SPI attempt || bugtraq,9416 || bugtraq,CAN-2004-0164 2416 || FTP invalid MDTM command attempt 2417 || FTP format string attempt 2418 || MISC MS Terminal Server no encryption session initiation attmept || url,www.microsoft.com/technet/security/bulletin/MS01-052.asp 2419 || MULTIMEDIA realplayer .ram playlist download attempt 2420 || MULTIMEDIA realplayer .rmp playlist download attempt 2421 || MULTIMEDIA realplayer .smi playlist download attempt 2422 || MULTIMEDIA realplayer .rt playlist download attempt 2423 || MULTIMEDIA realplayer .rp playlist download attempt 2424 || NNTP sendsys overflow attempt || bugtraq,9382 || cve,CAN-2004-00045 2425 || NNTP senduuname overflow attempt || bugtraq,9382 || cve,CAN-2004-00045 2426 || NNTP version overflow attempt || bugtraq,9382 || cve,CAN-2004-00045 2427 || NNTP checkgroups overflow attempt || bugtraq,9382 || cve,CAN-2004-00045 2428 || NNTP ihave overflow attempt || bugtraq,9382 || cve,CAN-2004-00045 2429 || NNTP sendme overflow attempt || bugtraq,9382 || cve,CAN-2004-00045 2430 || NNTP newgroup overflow attempt || bugtraq,9382 || cve,CAN-2004-00045 2431 || NNTP rmgroup overflow attempt || bugtraq,9382 || cve,CAN-2004-00045 2432 || NNTP article post without path attempt 2433 || WEB-CGI MDaemon form2raw.cgi overflow attempt || bugtraq,9317 2434 || WEB-CGI MDaemon form2raw.cgi access || bugtraq,9317 2435 || WEB-CLIENT Microsoft emf metafile access || bugtraq,9707 2436 || WEB-CLIENT Microsoft wmf metafile access || bugtraq,9707 2437 || WEB-CLIENT RealPlayer arbitrary javascript command attempt || bugtraq,8453 || bugtraq,9738 || cve,CAN-2003-0726 2438 || WEB-CLIENT RealPlayer playlist file URL overflow attempt || bugtraq,9579 2439 || WEB-CLIENT RealPlayer playlist http URL overflow attempt || bugtraq,9579 2440 || WEB-CLIENT RealPlayer playlist rtsp URL overflow attempt || bugtraq,9579 2441 || WEB-MISC NetObserve authentication bypass attempt || bugtraq,9319 2442 || WEB-MISC Quicktime User-Agent buffer overflow attempt || cve,CAN-2004-0169 2443 || EXPLOIT ICQ SRV_MULTI/SRV_META_USER first name overflow attempt || url,www.eeye.com/html/Research/Advisories/AD20040318.html 2444 || EXPLOIT ICQ SRV_MULTI/SRV_META_USER first name overflow attempt || url,www.eeye.com/html/Research/Advisories/AD20040318.html 2445 || EXPLOIT ICQ SRV_MULTI/SRV_META_USER last name overflow attempt || url,www.eeye.com/html/Research/Advisories/AD20040318.html 2446 || EXPLOIT ICQ SRV_MULTI/SRV_META_USER email overflow attempt || url,www.eeye.com/html/Research/Advisories/AD20040318.html
* 44 new rules, 52 updates. see snort-sigs mailing list in a few days for the full details. The cool rules are: (For ISS buffer overflow detection!) NETBIOS SMB Session Setup AndX request username overflow attempt NETBIOS SMB Data Service Session Setup AndX request username overflow attempt NETBIOS SMB Session Setup AndX request unicode username overflow attempt NETBIOS SMB Data Service Session Setup AndX request unicode username overflow attempt (For FW1 ISAKMP buffer overflow detection!) EXPLOIT ISAKMP first payload certificate request length overflow attempt EXPLOIT ISAKMP second payload certificate request length overflow attempt EXPLOIT ISAKMP third payload certificate request length overflow attempt EXPLOIT ISAKMP forth payload certificate request length overflow attempt EXPLOIT ISAKMP fifth payload certificate request length overflow attempt
* Major add/commit of 2.1 feature set... Will do a tag and then remove the "moved" files
* major push of rules. see snort-sigs email for all the changes.
* merge merge merge merge merge. Happy with the merge?
* updated sid:1293 - reduce false positives * updated sid:1294 - reduce false positives * updated sid:604 - corrected references * updated sid:1200 - added reference * moved sid:307 - moved to more appropriate category * moved sid:1382 - moved to more appropriate category Thanks to: Bob Dehnhardt Mathew Johnston Andrew Hintz Jon Hart
* large update of signatures. CVS disconnected during the last commit, so this is a recommit
woohoo. Biggest change we've made in a while. We've removed "flags:A+" in favor of "flow:established". Initial testing shows that this change is about a 200% speed increase. NOTE: I know that not all of the signatures have been converted. There are 144 signatures with flags left to be looked at. I'll commit them later today, but this the majority of them.
* updated sid:605 - removed dup ; (Caught by Chad Kreimendahl) * updated sid:1431 - added classtype (caught by Chad Kreimendahl)
* Added the following signatures: 1428 || EXPERIMENTAL audio galaxy keepalive 1429 || EXPERIMENTAL poll.gotomypc.com access || url,www.gotomypc.com/help2.tmpl 1430 || EXPERIMENTAL TELNET solaris memory mismanagement exploit attempt 1431 || EXPERIMENTAL BAD TRAFFIC syn to multicast address 1432 || INFO GNUTella GET 1433 || WEB-MISC .history access 1434 || WEB-MISC .bash_history access 1435 || DNS named authors attempt || arachnids,480 1436 || MULTIMEDIA Quicktime User Agent access 1437 || MULTIMEDIA Windows Media audio download 1438 || MULTIMEDIA Windows Media Video download 1439 || MULTIMEDIA Shoutcast playlist redirection 1440 || MULTIMEDIA Icecast playlist redirection 1441 || TFTP GET nc.exe 1442 || TFTP GET shadow 1443 || TFTP GET passwd 1444 || TFTP Get 1445 || FTP file_id.diz access 1446 || SMTP vrfy root * Massive flow updates. I hope nobody is using these signatures with 1.8.*
* regened sid-msg.map * moved frontpage to be after web-iis * updated sid:1398 - added classtype * added sid:1399 - EXPERIMENTAL PHP-Nuke remote file include attempt * moved sid:612 - Belongs in rpc.rules instead of rservices.rules * updated sid:601 - s/rsh/rlogin/ * updated sid:602 - s/rsh/rlogin/ * updated sid:603 - s/rsh/rlogin/ * updated sid:604 - s/rsh/rlogin/ * updated sid:605 - s/rsh/rlogin/ * updated sid:606 - s/rsh/rlogin/ * updated sid:607 - s/rlogin/rsh/ * updated sid:608 - s/rlogin/rsh/ * updated sid:609 - s/rlogin/rsh/ * updated sid:610 - s/rlogin/rsh/ * updated sid:611 - s/rlogin/rsh/ * disabled sid:617 - wtf does this look for? nobody knows, lets turn it off * updated sid:976 - added url REFs. Removed & from content * updated sid:1042 - added bugtraq REF * disabled sid:1045 - generic sig when we have a tight sig * updated sid:1201 - added depth
* Added copyright notices so that the Intrusion.com people might take our intellectual property a bit more seriously
* added support for SID and REV. * added sid-msg.map (maps SID to MSG) SID is a unique ID for each rule. REV is the rule revision.
* Changed default $HOME_NET to any (watch as marty changes it right back :P) * Added classifications to almost every rule NOTE: We are currently using IDMEF's classifications. This may change soon. This is an extremely SIMPLE and well defined set of rule classifications and priorities. It is completely changeable. Read sp_priority and classification.conf for more information.
Don't let vim add $ Log $ when I don't tell it to
Added x11.rules, x11.rules, and virus.rules
* Disabled reseerved bits scan detection, false positives for ECN traffic aren't detectable with the current code and I'm seeing a lot of noise out there about this... * committed the new rules set from Forster/Caswell
| snort-team@sourcefire.com |