CVS log for snort/rules/sql.rules

(logo)

Help

(back) Up to [cvs] / snort / rules

Request diff between arbitrary revisions


Default branch: MAIN
Bookmark a link to: HEAD / (download)

Revision 1.32 / (view) - annotate - [select for diffs] , Tue Mar 1 18:57:10 2005 UTC (5 years ago) by bmc
Branch: MAIN
CVS Tags: HEAD
Changes since 1.31: +14 -2 lines
Diff to previous 1.31
a ton of new rules

Revision 1.28.2.2 / (view) - annotate - [select for diffs] , Tue Mar 1 18:57:08 2005 UTC (5 years ago) by bmc
Branch: SNORT_2_3
Changes since 1.28.2.1: +14 -2 lines
Diff to previous 1.28.2.1 to branch point 1.28 to next main 1.29
a ton of new rules

Revision 1.23.2.5 / (view) - annotate - [select for diffs] , Tue Mar 1 18:57:06 2005 UTC (5 years ago) by bmc
Branch: SNORT_2_2
Changes since 1.23.2.4: +14 -2 lines
Diff to previous 1.23.2.4 to branch point 1.23 to next main 1.24
a ton of new rules

Revision 1.18.2.8 / (view) - annotate - [select for diffs] , Tue Mar 1 18:57:04 2005 UTC (5 years ago) by bmc
Branch: SNORT_2_1
Changes since 1.18.2.7: +3 -1 lines
Diff to previous 1.18.2.7 to branch point 1.18 to next main 1.19
a ton of new rules

Revision 1.31 / (view) - annotate - [select for diffs] , Thu Feb 10 01:11:04 2005 UTC (5 years, 1 month ago) by bmc
Branch: MAIN
Changes since 1.30: +0 -0 lines
Diff to previous 1.30
a bunch of new rules.  thanks microsoft, I didn't want to sleep on my birthday.  Really.

Revision 1.30 / (view) - annotate - [select for diffs] , Wed Jan 12 15:46:11 2005 UTC (5 years, 2 months ago) by bmc
Branch: MAIN
Changes since 1.29: +1 -1 lines
Diff to previous 1.29
a bunch of new rules.  go sourcefire.

Revision 1.29 / (view) - annotate - [select for diffs] , Wed Oct 13 20:26:07 2004 UTC (5 years, 5 months ago) by bmc
Branch: MAIN
Changes since 1.28: +28 -28 lines
Diff to previous 1.28
tons of new rules, tons of rule updates.  oracle & nntp xpat rules are the important ones

Revision 1.28.2.1 / (view) - annotate - [select for diffs] , Wed Oct 13 20:25:57 2004 UTC (5 years, 5 months ago) by bmc
Branch: SNORT_2_3
CVS Tags: STABLE, SNORT_v2_3_0-RC2, SNORT_v2_3_0-RC1, SNORT_v2_3_0
Changes since 1.28: +28 -28 lines
Diff to previous 1.28
tons of new rules, tons of rule updates.  oracle & nntp xpat rules are the important ones

Revision 1.23.2.4 / (view) - annotate - [select for diffs] , Wed Oct 13 20:25:47 2004 UTC (5 years, 5 months ago) by bmc
Branch: SNORT_2_2
Changes since 1.23.2.3: +28 -28 lines
Diff to previous 1.23.2.3 to branch point 1.23
tons of new rules, tons of rule updates.  oracle & nntp xpat rules are the important ones

Revision 1.18.2.7 / (view) - annotate - [select for diffs] , Wed Oct 13 20:25:36 2004 UTC (5 years, 5 months ago) by bmc
Branch: SNORT_2_1
Changes since 1.18.2.6: +28 -28 lines
Diff to previous 1.18.2.6 to branch point 1.18
tons of new rules, tons of rule updates.  oracle & nntp xpat rules are the important ones

Revision 1.17.2.5 / (view) - annotate - [select for diffs] , Wed Oct 13 20:25:25 2004 UTC (5 years, 5 months ago) by bmc
Branch: SNORT_2_0
Changes since 1.17.2.4: +28 -28 lines
Diff to previous 1.17.2.4 to branch point 1.17 to next main 1.18
tons of new rules, tons of rule updates.  oracle & nntp xpat rules are the important ones

Revision 1.17.2.4 / (view) - annotate - [select for diffs] , Fri Sep 10 18:32:47 2004 UTC (5 years, 6 months ago) by bmc
Branch: SNORT_2_0
Changes since 1.17.2.3: +1 -2 lines
Diff to previous 1.17.2.3 to branch point 1.17
* dedup

Revision 1.23.2.3 / (view) - annotate - [select for diffs] , Thu Aug 26 15:19:52 2004 UTC (5 years, 6 months ago) by bmc
Branch: SNORT_2_2
Changes since 1.23.2.2: +4 -4 lines
Diff to previous 1.23.2.2 to branch point 1.23
* sync sync sync

Revision 1.18.2.6 / (view) - annotate - [select for diffs] , Thu Aug 26 15:18:57 2004 UTC (5 years, 6 months ago) by bmc
Branch: SNORT_2_1
Changes since 1.18.2.5: +4 -4 lines
Diff to previous 1.18.2.5 to branch point 1.18
* sync sync sync

Revision 1.17.2.3 / (view) - annotate - [select for diffs] , Thu Aug 26 15:18:13 2004 UTC (5 years, 6 months ago) by bmc
Branch: SNORT_2_0
Changes since 1.17.2.2: +4 -4 lines
Diff to previous 1.17.2.2 to branch point 1.17
* sync sync sync

Revision 1.28 / (view) - annotate - [select for diffs] , Thu Aug 26 15:01:28 2004 UTC (5 years, 6 months ago) by bmc
Branch: MAIN
Branch point for: SNORT_2_3
Changes since 1.27: +4 -4 lines
Diff to previous 1.27
* wee, more updates.  new rules for NSS SSL foo (judy & me ++)

Revision 1.17.2.2 / (view) - annotate - [select for diffs] , Tue Aug 10 14:01:51 2004 UTC (5 years, 7 months ago) by bmc
Branch: SNORT_2_0
Changes since 1.17.2.1: +25 -25 lines
Diff to previous 1.17.2.1 to branch point 1.17
* massive sync

Revision 1.18.2.5 / (view) - annotate - [select for diffs] , Tue Aug 10 13:59:23 2004 UTC (5 years, 7 months ago) by bmc
Branch: SNORT_2_1
Changes since 1.18.2.4: +25 -25 lines
Diff to previous 1.18.2.4 to branch point 1.18
* massive sync

Revision 1.23.2.2 / (view) - annotate - [select for diffs] , Tue Aug 10 13:52:06 2004 UTC (5 years, 7 months ago) by bmc
Branch: SNORT_2_2
CVS Tags: SNORT_v2_2_0
Changes since 1.23.2.1: +25 -25 lines
Diff to previous 1.23.2.1 to branch point 1.23
* sync sync sync

Revision 1.27 / (view) - annotate - [select for diffs] , Tue Aug 10 13:44:40 2004 UTC (5 years, 7 months ago) by bmc
Branch: MAIN
Changes since 1.26: +25 -25 lines
Diff to previous 1.26
* tons of new rules
* tons of new rule references
* tons of new rule docs
* initial documentation on preprocessor alerts (gen-sid.txt in doc/signatures)
* new build of the manual

Revision 1.23.2.1 / (view) - annotate - [select for diffs] , Fri Jul 23 20:19:27 2004 UTC (5 years, 7 months ago) by bmc
Branch: SNORT_2_2
Changes since 1.23: +1 -1 lines
Diff to previous 1.23
* massive sync here too

Revision 1.26 / (view) - annotate - [select for diffs] , Fri Jul 23 20:15:44 2004 UTC (5 years, 7 months ago) by bmc
Branch: MAIN
Changes since 1.25: +1 -1 lines
Diff to previous 1.25
* sync sync sync
* go ruleteam go

Revision 1.17.2.1 / (view) - annotate - [select for diffs] , Thu Jul 15 19:14:33 2004 UTC (5 years, 8 months ago) by bmc
Branch: SNORT_2_0
Changes since 1.17: +44 -43 lines
Diff to previous 1.17
* massive sync from head

Revision 1.25 / (view) - annotate - [select for diffs] , Thu Jul 15 16:21:28 2004 UTC (5 years, 8 months ago) by bmc
Branch: MAIN
Changes since 1.24: +19 -19 lines
Diff to previous 1.24
* yet another sync, lets go forward in time, not backwards...

Revision 1.24 / (view) - annotate - [select for diffs] , Wed Jul 14 21:16:10 2004 UTC (5 years, 8 months ago) by bmc
Branch: MAIN
Changes since 1.23: +19 -19 lines
Diff to previous 1.23
* massive rule updates (go ruleteam, go)

Revision 1.18.2.4 / (view) - annotate - [select for diffs] , Wed Jun 16 15:11:07 2004 UTC (5 years, 9 months ago) by jhewlett
Branch: SNORT_2_1
Changes since 1.18.2.3: +18 -18 lines
Diff to previous 1.18.2.3 to branch point 1.18
* Syncing changes for rules team

Revision 1.23 / (view) - annotate - [select for diffs] , Tue Jun 15 13:47:08 2004 UTC (5 years, 9 months ago) by bmc
Branch: MAIN
CVS Tags: SNORT_v2_2_0-RC1
Branch point for: SNORT_2_2
Changes since 1.22: +19 -19 lines
Diff to previous 1.22
* lets try this *again*

Revision 1.22 / (view) - annotate - [select for diffs] , Thu Jun 3 20:11:05 2004 UTC (5 years, 9 months ago) by jhewlett
Branch: MAIN
Changes since 1.21: +45 -45 lines
Diff to previous 1.21
* sync with sforge current

Revision 1.18.2.3 / (view) - annotate - [select for diffs] , Thu Jun 3 18:13:38 2004 UTC (5 years, 9 months ago) by jhewlett
Branch: SNORT_2_1
CVS Tags: SNORT_v2_1_3
Changes since 1.18.2.2: +44 -44 lines
Diff to previous 1.18.2.2 to branch point 1.18
* updating 2.1.3 from sforge

Revision 1.18.2.2 / (view) - annotate - [select for diffs] , Fri May 28 19:21:41 2004 UTC (5 years, 9 months ago) by jhewlett
Branch: SNORT_2_1
Changes since 1.18.2.1: +2 -2 lines
Diff to previous 1.18.2.1 to branch point 1.18
* syncing up sfire with sforge 2.1 branch

Revision 1.21 / (view) - annotate - [select for diffs] , Sun Apr 18 20:32:59 2004 UTC (5 years, 11 months ago) by cazz
Branch: MAIN
Changes since 1.20: +2 -2 lines
Diff to previous 1.20
* a ton of new rules, a bunch of updates too.

2447 || WEB-MISC ServletManager access || cve,CAN-2001-1195 || nessus,12122
2448 || WEB-MISC setinfo.hts access || bugtraq,9973 || nessus,12120
2449 || FTP ALLO overflow attempt || bugtraq,9953
2450 || CHAT Yahoo IM successful logon
2451 || CHAT Yahoo IM voicechat
2452 || CHAT Yahoo IM ping
2453 || CHAT Yahoo IM conference invitation
2454 || CHAT Yahoo IM conference logon success
2455 || CHAT Yahoo IM conference message
2456 || CHAT Yahoo IM file transfer request
2457 || CHAT Yahoo IM message
2458 || CHAT Yahoo IM successful chat join
2459 || CHAT Yahoo IM webcam offer invitation
2460 || CHAT Yahoo IM webcam request
2461 || CHAT Yahoo IM webcam watch
2462 || EXPLOIT IGMP IGAP account overflow attempt || bugtraq,9952 || cve,CAN-2004-0176
2463 || EXPLOIT IGMP IGAP message overflow attempt || bugtraq,9952 || cve,CAN-2004-0176
2464 || EXPLOIT EIGRP prefix length overflow attempt || bugtraq,9952 || cve,CAN-2004-0176
2465 || NETBIOS SMB-DS IPC$ share access
2466 || NETBIOS SMB-DS IPC$ share unicode access
2467 || NETBIOS SMB D$ share unicode access
2468 || NETBIOS SMB-DS D$ share access
2469 || NETBIOS SMB-DS D$ share unicode access
2470 || NETBIOS SMB C$ share unicode access
2471 || NETBIOS SMB-DS C$ share access
2472 || NETBIOS SMB-DS C$ share unicode access
2473 || NETBIOS SMB ADMIN$ share unicode access
2474 || NETBIOS SMB-DS ADMIN$ share access
2475 || NETBIOS SMB-DS ADMIN$ share unicode access
2476 || NETBIOS SMB-DS Create AndX Request winreg attempt
2477 || NETBIOS SMB-DS Create AndX Request winreg unicode attempt
2478 || NETBIOS SMB-DS DCERPC bind winreg attempt
2479 || NETBIOS SMB-DS DCERPC bind winreg unicode attempt
2480 || NETBIOS SMB-DS DCERPC shutdown unicode attempt
2481 || NETBIOS SMB-DS DCERPC shutdown unicode little endian attempt
2482 || NETBIOS SMB-DS DCERPC shutdown attempt
2483 || NETBIOS SMB-DS DCERPC shutdown little endian attempt
2484 || WEB-MISC source.jsp access || nessus,12119
2485 || WEB-CLIENT Nortan antivirus sysmspam.dll load attempt || bugtraq,9916
2486 || DOS ISAKMP invalid identification payload attempt || bugtraq,10004
2487 || SMTP WinZip MIME content-type buffer overflow || bugtraq,9758
2488 || SMTP WinZip MIME content-disposition buffer overflow || bugtraq,9758
2489 || EXPLOIT esignal STREAMQUOTE buffer overflow attempt || bugtraq,9978
2490 || EXPLOIT esignal SNAPQUOTE buffer overflow attempt || bugtraq,9978
2491 || NETBIOS SMB-DS DCERPC ISystemActivator unicode bind attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813
2492 || NETBIOS SMB DCERPC ISystemActivator bind attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813
2493 || NETBIOS SMB DCERPC ISystemActivator unicode bind attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813
2494 || NETBIOS DCEPRC ORPCThis request flood attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813
2495 || NETBIOS SMB DCEPRC ORPCThis request flood attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813
2496 || NETBIOS SMB-DS DCEPRC ORPCThis request flood attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2003-0813
2497 || IMAP invalid SSLv3 data version attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120
2498 || IMAP invalid SSLv3 timestamp attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120
2499 || MISC LDAP invalid SSLv3 timestamp attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120
2500 || MISC LDAP invalid SSLv3 data version attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120
2501 || POP3 invalid SSLv3 timestamp attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120
2502 || POP3 invalid SSLv3 data version attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120
2503 || SMTP invalid SSLv3 timestamp attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120
2504 || SMTP invalid SSLv3 data version attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120
2505 || WEB-MISC invalid SSLv3 data version attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120
2506 || WEB-MISC invalid SSLv3 timestamp attempt || url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx || cve,CAN-2004-0120

Revision 1.20 / (view) - annotate - [select for diffs] , Sat Mar 20 21:58:43 2004 UTC (6 years ago) by cazz
Branch: MAIN
Changes since 1.19: +2 -2 lines
Diff to previous 1.19
* Added a ton of rules that include vulnerabilities in many high-profile
  security products, including Checkpoint & ISS gear (see below)
* provided a single high-powered rule for detecting all of the evil virus emails
* added even more docs.  (Go Nigel)

2405 || WEB-PHP phptest.php access || bugtraq,9737
2406 || TELNET APC SmartSlot default admin account attempt || bugtraq,9681
2407 || WEB-MISC util.pl access || bugtraq,9748
2408 || WEB-MISC Invision Power Board search.pl access || bugtraq,9766
2409 || POP3 APOP USER overflow attempt || bugtraq,9794
2410 || WEB-PHP IGeneric Free Shopping Cart page.php access || bugtraq,9773
2411 || WEB-MISC Real Server DESCRIBE buffer overflow attempt || url,www.service.real.com/help/faq/security/rootexploit091103.html || bugtraq,8476
2412 || ATTACK-RESPONSES successful cross site scripting forced download attempt
2413 || EXPLOIT ISAKMP delete hash with empty hash attempt || bugtraq,9416 || bugtraq,CAN-2004-0164
2414 || EXPLOIT ISAKMP initial contact notification without SPI attempt || bugtraq,9416 || bugtraq,CAN-2004-0164
2415 || EXPLOIT ISAKMP second payload initial contact notification without SPI attempt || bugtraq,9416 || bugtraq,CAN-2004-0164
2416 || FTP invalid MDTM command attempt
2417 || FTP format string attempt
2418 || MISC MS Terminal Server no encryption session initiation attmept || url,www.microsoft.com/technet/security/bulletin/MS01-052.asp
2419 || MULTIMEDIA realplayer .ram playlist download attempt
2420 || MULTIMEDIA realplayer .rmp playlist download attempt
2421 || MULTIMEDIA realplayer .smi playlist download attempt
2422 || MULTIMEDIA realplayer .rt playlist download attempt
2423 || MULTIMEDIA realplayer .rp playlist download attempt
2424 || NNTP sendsys overflow attempt || bugtraq,9382 || cve,CAN-2004-00045
2425 || NNTP senduuname overflow attempt || bugtraq,9382 || cve,CAN-2004-00045
2426 || NNTP version overflow attempt || bugtraq,9382 || cve,CAN-2004-00045
2427 || NNTP checkgroups overflow attempt || bugtraq,9382 || cve,CAN-2004-00045
2428 || NNTP ihave overflow attempt || bugtraq,9382 || cve,CAN-2004-00045
2429 || NNTP sendme overflow attempt || bugtraq,9382 || cve,CAN-2004-00045
2430 || NNTP newgroup overflow attempt || bugtraq,9382 || cve,CAN-2004-00045
2431 || NNTP rmgroup overflow attempt || bugtraq,9382 || cve,CAN-2004-00045
2432 || NNTP article post without path attempt
2433 || WEB-CGI MDaemon form2raw.cgi overflow attempt || bugtraq,9317
2434 || WEB-CGI MDaemon form2raw.cgi access || bugtraq,9317
2435 || WEB-CLIENT Microsoft emf metafile access || bugtraq,9707
2436 || WEB-CLIENT Microsoft wmf metafile access || bugtraq,9707
2437 || WEB-CLIENT RealPlayer arbitrary javascript command attempt || bugtraq,8453 || bugtraq,9738 || cve,CAN-2003-0726
2438 || WEB-CLIENT RealPlayer playlist file URL overflow attempt || bugtraq,9579
2439 || WEB-CLIENT RealPlayer playlist http URL overflow attempt || bugtraq,9579
2440 || WEB-CLIENT RealPlayer playlist rtsp URL overflow attempt || bugtraq,9579
2441 || WEB-MISC NetObserve authentication bypass attempt || bugtraq,9319
2442 || WEB-MISC Quicktime User-Agent buffer overflow attempt || cve,CAN-2004-0169
2443 || EXPLOIT ICQ SRV_MULTI/SRV_META_USER first name overflow attempt || url,www.eeye.com/html/Research/Advisories/AD20040318.html
2444 || EXPLOIT ICQ SRV_MULTI/SRV_META_USER first name overflow attempt || url,www.eeye.com/html/Research/Advisories/AD20040318.html
2445 || EXPLOIT ICQ SRV_MULTI/SRV_META_USER last name overflow attempt || url,www.eeye.com/html/Research/Advisories/AD20040318.html
2446 || EXPLOIT ICQ SRV_MULTI/SRV_META_USER email overflow attempt || url,www.eeye.com/html/Research/Advisories/AD20040318.html

Revision 1.18.2.1 / (view) - annotate - [select for diffs] , Tue Jan 20 21:31:38 2004 UTC (6 years, 2 months ago) by jh8
Branch: SNORT_2_1
CVS Tags: SNORT_v2_1_3-RC1, SNORT_v2_1_2, SNORT_v2_1_1-RC1, SNORT_v2_1_1
Changes since 1.18: +2 -1 lines
Diff to previous 1.18
* 2.1.1-RC1

Revision 1.19 / (view) - annotate - [select for diffs] , Sat Jan 17 01:01:01 2004 UTC (6 years, 2 months ago) by cazz
Branch: MAIN
Changes since 1.18: +2 -1 lines
Diff to previous 1.18
* MS-SQL probe response overflow attempt (wee, out before anyone else.  take that ISS)

Revision 1.18 / (view) - annotate - [select for diffs] , Mon Oct 20 15:03:13 2003 UTC (6 years, 5 months ago) by chrisgreen
Branch: MAIN
CVS Tags: version-2-1-0, cmg, SNORT_v2_1_0
Branch point for: SNORT_2_1
Changes since 1.17: +1 -1 lines
Diff to previous 1.17
* Major add/commit of 2.1 feature set...

  Will do a tag and then remove the "moved" files

Revision 1.17 / (view) - annotate - [select for diffs] , Thu Apr 17 00:35:47 2003 UTC (6 years, 11 months ago) by cazz
Branch: MAIN
CVS Tags: version-2-0-6, version-2-0-5, version-2-0-2, version-2-0-1
Branch point for: SNORT_2_0
Changes since 1.16: +3 -1 lines
Diff to previous 1.16
* MASSIVE sync of rules

This is the first major sync of rules since I started working for Sourcefire.

Many of these updates are a direct result of my employment at Sourcefire.  We
have time and resources to test and document rules extensively.  Many people
have contributed to these updates.  Too many to mention here.

You should continue to see awesome updates, rewrites and new rules as
Sourcefire is dedicating serious resources to the Snort project.

Even if you don't buy an appliance from Sourcefire, you should send an
email to info@sourcefire.com to let them know how much you appreciate their
dedication to making snort awesome.

Revision 1.16 / (view) - annotate - [select for diffs] , Wed Mar 5 13:28:02 2003 UTC (7 years ago) by cazz
Branch: MAIN
CVS Tags: version-2-0-0, CMG
Changes since 1.15: +1 -2 lines
Diff to previous 1.15
* oops, dup rule merge.

Revision 1.15 / (view) - annotate - [select for diffs] , Tue Mar 4 21:56:37 2003 UTC (7 years ago) by cazz
Branch: MAIN
Changes since 1.14: +3 -1 lines
Diff to previous 1.14
* merge more rules
2004 || MS-SQL Worm propagation attempt OUTBOUND
2005 || RPC UDP kcms_server request
2006 || RPC TCP kcms_server request
2007 || RPC kcms_server directory traversal attempt
2008 || MISC CVS invalid user authentication response
2009 || MISC CVS invalid repository response
2010 || MISC CVS double free exploit attempt response || bugtraq,6650 || cve,CAN-2003-0015
2011 || MISC CVS invalid directory response || bugtraq,6650 || cve,CAN-2003-0015
2012 || MISC CVS missing cvsroot response
2013 || MISC CVS invalid module response

Revision 1.13.2.2 / (view) - annotate - [select for diffs] , Tue Mar 4 21:47:57 2003 UTC (7 years ago) by cazz
Branch: SNORT_1_9
Changes since 1.13.2.1: +2 -1 lines
Diff to previous 1.13.2.1 to branch point 1.13 to next main 1.14
* merge more rules
2004 || MS-SQL Worm propagation attempt OUTBOUND
2005 || RPC UDP kcms_server request
2006 || RPC TCP kcms_server request
2007 || RPC kcms_server directory traversal attempt
2008 || MISC CVS invalid user authentication response
2009 || MISC CVS invalid repository response
2010 || MISC CVS double free exploit attempt response || bugtraq,6650 || cve,CAN-2003-0015
2011 || MISC CVS invalid directory response || bugtraq,6650 || cve,CAN-2003-0015
2012 || MISC CVS missing cvsroot response
2013 || MISC CVS invalid module response

Revision 1.13.2.1 / (view) - annotate - [select for diffs] , Fri Feb 7 22:05:02 2003 UTC (7 years, 1 month ago) by cazz
Branch: SNORT_1_9
CVS Tags: version-1-9-1
Changes since 1.13: +2 -1 lines
Diff to previous 1.13
* merge merge merge merge merge.  Happy with the merge?

Revision 1.14 / (view) - annotate - [select for diffs] , Sun Jan 26 02:16:39 2003 UTC (7 years, 1 month ago) by cazz
Branch: MAIN
Changes since 1.13: +2 -1 lines
Diff to previous 1.13
* move some policy rules to policy.rules
* move some deleted rules to deleted.rules
* add sid:2003 - rule for the Slammer worm (MS SQL Buff overflow #30052342)

Revision 1.13 / (view) - annotate - [select for diffs] , Sun Aug 18 20:28:43 2002 UTC (7 years, 7 months ago) by cazz
Branch: MAIN
CVS Tags: version-1-9-0
Branch point for: SNORT_1_9
Changes since 1.12: +3 -2 lines
Diff to previous 1.12
* large update of signatures.  CVS disconnected during the last commit, so
  this is a recommit

Revision 1.12 / (view) - annotate - [select for diffs] , Wed Jun 5 14:47:55 2002 UTC (7 years, 9 months ago) by cazz
Branch: MAIN
CVS Tags: beta-1_9_0-beta6, beta-1_9_0-beta5, beta-1_9_0-beta4, beta-1_9_0-beta2
Changes since 1.11: +40 -40 lines
Diff to previous 1.11
* This is a massive change.  Since I'm really busy ATM, this is what changed.

* created imap.rules, nntp.rules, pop3.rules, other-ids.rules, web-client.rules,
   web-php.rules and moved signatures into those.

* added the following signatures:
1793 || PORN fetish
1794 || PORN masturbation
1795 || PORN ejaculation
1796 || PORN virgin
1797 || PORN BDSM
1798 || PORN erotica
1799 || PORN fisting
1800 || VIRUS Klez Incoming

Revision 1.11 / (view) - annotate - [select for diffs] , Wed May 22 00:37:30 2002 UTC (7 years, 10 months ago) by cazz
Branch: MAIN
Changes since 1.10: +2 -1 lines
Diff to previous 1.10
* updated sid:312 - added bugtraq ref
* updated sid:1751 - added CVE ref
* updated sid:499 - corrected MSG
* updated sid:1746,1747 - added cve & BUG references
* updated sid:1547 - removed false negative (print isn't required)
* added the following signatures:
1753 || EXPERIMENTAL WEB-IIS as_web.exe access || bugtraq,4670
1754 || EXPERIMENTAL WEB-IIS as_web4.exe access || bugtraq,4670
1755 || EXPERIMENTAL IMAP PARTIAL BODY attempt
1756 || EXPERIMENTAL WEB-IIS NewsPro administration authentication attempt
1757 || EXPERIMENTAL WEB-MISC b2 arbitrary command execution attempt
1758 || EXPERIMENTAL WEB-MISC b2 acces
1759 || MS-SQL xp_cmdshell program execution (445)

Revision 1.10 / (view) - annotate - [select for diffs] , Wed Feb 13 12:35:50 2002 UTC (8 years, 1 month ago) by cazz
Branch: MAIN
Changes since 1.9: +37 -37 lines
Diff to previous 1.9
* added a few more things to doc/RULES.todo

* updated sid:103  - added url ref
* updated sid:260  - added url ref
* updated sid:967  - added url ref
* updated sid:975  - added url ref
* updated sid:1256 - added url ref
* updated sid:275  - added CVE ref & 2 url refs
* updated sid:271  - cleaned msg

* removed 90% of the depth/offsets from the 1433 signatures re CMG's request

* added sid:1405 - WEB-CGI AHG search.cgi access
* added sid:1406 - WEB-CGI agora.cgi access
* added sid:1407 - WEB-MISC smssend.php access
* added sid:1408 - EXPERIMENTAL MSDTC DoS sig
* added sid:1409 - EXPERIMENTAL SNMP community string overflow (from andrewb)
* added sid:1410 - WEB-CGI dcboard.cgi access

Revision 1.9 / (view) - annotate - [select for diffs] , Wed Jan 16 12:39:10 2002 UTC (8 years, 2 months ago) by cazz
Branch: MAIN
Changes since 1.8: +3 -3 lines
Diff to previous 1.8
* sid:527 - added CVE & CERT refs
* sid:252 - added RFC refs
* sid:268 - added CVE refs
* sid:270 - added CVE & CERT refs
* sid:1398 - corrected second offset (re conversation w/ cmg)
* sid:330 - added CVE refs
* sid:1387 - corrected BID refs (re email from Jensenne @ SecurityFocus)
* sid:1387 - corrected BID refs (re email from Jensenne @ SecurityFocus)

Revision 1.8 / (view) - annotate - [select for diffs] , Fri Dec 21 21:15:48 2001 UTC (8 years, 3 months ago) by cazz
Branch: MAIN
Changes since 1.7: +3 -1 lines
Diff to previous 1.7
* added UPNP, mod-plsql, and ms-sql raiserror signatures

Revision 1.7 / (view) - annotate - [select for diffs] , Wed Dec 19 18:40:05 2001 UTC (8 years, 3 months ago) by cazz
Branch: MAIN
Changes since 1.6: +37 -37 lines
Diff to previous 1.6
* Added more stuff to the TODO list
* moved sid:144 to ftp.rules since thats where it belongs
* updated sid:303,1240 (added flags)
* commited a ton of updates to sql.rules and ftp.rules
  (see diffs for full info) from Ryan @ SecurityFocus. (You rock yo)
* added a bit of info as to why local.rules exists to local.rules

Revision 1.6 / (view) - annotate - [select for diffs] , Mon Oct 29 01:52:54 2001 UTC (8 years, 4 months ago) by roesch
Branch: MAIN
Changes since 1.5: +2 -1 lines
Diff to previous 1.5
* Added copyright notices so that the Intrusion.com people might take our intellectual
  property a bit more seriously

Revision 1.5 / (view) - annotate - [select for diffs] , Tue Sep 25 04:07:41 2001 UTC (8 years, 5 months ago) by cazz
Branch: MAIN
Changes since 1.4: +16 -16 lines
Diff to previous 1.4
* Added descriptions to many of the .rules files.  (More to come soon)
* cleaned up a few any any rules
* cleaned up the name of a few rules
* Created attack-responces.rules (for generic responces of known attacks)
* Created bad-traffic.rules (for signatures that shouldn't happen on a
  'good' network)
* normalized a few msgs.
* changed order telnet.rules to speed up the exploit signatures
* added sml3com access signature (need to write an overflow attempt sig,
  but don't have a 3com router to test it.  any takers?)

Revision 1.4 / (view) - annotate - [select for diffs] , Mon Jun 11 15:29:30 2001 UTC (8 years, 9 months ago) by cazz
Branch: MAIN
Changes since 1.3: +37 -37 lines
Diff to previous 1.3
* added support for SID and REV.
* added sid-msg.map (maps SID to MSG)

SID is a unique ID for each rule.  REV is the rule revision.

Revision 1.3 / (view) - annotate - [select for diffs] , Tue Apr 17 03:32:47 2001 UTC (8 years, 11 months ago) by cazz
Branch: MAIN
Changes since 1.2: +37 -40 lines
Diff to previous 1.2
* Changed default $HOME_NET to any (watch as marty changes it right back :P)
* Added classifications to almost every rule

NOTE:
We are currently using IDMEF's classifications.  This may change soon.
This is an extremely SIMPLE and well defined set of rule classifications
and priorities.  It is completely changeable.  Read sp_priority and
classification.conf for more information.

Revision 1.2 / (view) - annotate - [select for diffs] , Thu Apr 5 15:24:11 2001 UTC (8 years, 11 months ago) by cazz
Branch: MAIN
Changes since 1.1: +6 -5 lines
Diff to previous 1.1
updated broken rules from last database export

Revision 1.1 / (view) - annotate - [select for diffs] , Wed Apr 4 23:39:22 2001 UTC (8 years, 11 months ago) by cazz
Branch: MAIN
added virus.rules & sql.rules.  cleaned up rules to be less false possitive.  removed a few duplicate rules.

This form allows you to request diffs between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.

Diffs between and
Type of Diff should be a

View only Branch:
Sort log by:

snort-team@sourcefire.com