# $Id: s2b-augment.cfg 797 2004-11-27 20:26:50Z rwinslow $ active T comment WEB-CGI emumail.cgi access requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-cgi.rules active T comment RPC portmap kcms_server request UDP sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/rpc.rules active T comment WEB-CGI htsearch arbitrary configuration file attempt requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-cgi.rules active T comment SMTP chameleon overflow comment pcre: /^HELP\s[^\n]{500}/ism payload /((^)|(\n+))[hH][eE][lL][pP][\x20\x09\x0b][^\n]{500}/ sigaction SIG_LOG requires-reverse-signature ! smtp_server_fail snort-rule-file s2b_data_on_weed/rules2.1/smtp.rules payload /.*[hH][eE][lL][pP]/ active T comment WEB-IIS MDAC Content-Type overflow attempt requires-signature http_iis_server requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-iis.rules active T comment FINGER . query sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/finger.rules active T comment WEB-CGI dcforum.cgi access comment "informational only" comment "too general but low occurence" requires-reverse-signature ! http_error sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/web-cgi.rules active T comment MS-SQL sp_password - password change sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/sql.rules active T comment WEB-CGI admentor admin.asp access requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-cgi.rules active T comment ATTACK-RESPONSES rexec username too long response sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/attack-responses.rules active T comment WEB-MISC SalesLogix Eviewer access requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-misc.rules active T comment WEB-CGI a1stats a1disp3.cgi access requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-cgi.rules active T comment SNMP PROTOS test-suite-req-app attempt requires-reverse-signature snmp_userver_ok_return sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/snmp.rules active T comment "MISC LDAP SSLv3 Server_Hello request" sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/misc.rules active T comment "DNS EXPLOIT x86 Linux overflow attempt" sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/dns.rules active T comment "WEB-CGI webdist.cgi arbitrary command attempt" requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-cgi.rules active T comment "WEB-MISC Demarc SQL injection attempt" requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-misc.rules active T comment "WEB-FRONTPAGE _vti_rpc access" requires-signature http_iis_server requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-frontpage.rules active T comment "WEB-CGI admin.pl access" requires-reverse-signature ! http_error sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/web-cgi.rules active T comment "FTP wu-ftp bad file completion attempt {" sigaction SIG_LOG payload /.*~.{1}.*\{/ ftp /.{2,} ~.?\{/ snort-rule-file snort_rules/rules2.2/ftp.rules active T comment "WEB-MISC ftp.pl access" requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-misc.rules active T comment "RPC rpc.xfsmd xfs_export attempt TCP" sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/rpc.rules active T comment "CHAT IRC channel join" sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/chat.rules active T comment "WEB-PHP Opt-X header.php remote file include attempt" comment pcre: /systempath=(http|https|ftp)/i payload /.*[sS][yY][sS][tT][eE][mM][pP][aA][tT][hH]=([hH][tT]{2}[pP][sS]?)|([fF][tT][pP])/ requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-php.rules payload /.*[sS][yY][sS][tT][eE][mM][pP][aA][tT][hH]=/ active T comment "WEB-IIS bdir.htr access" requires-signature http_iis_server requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-iis.rules active T comment "WEB-CGI alchemy http server PRN arbitrary command execution attempt" requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-cgi.rules active T comment "NETBIOS SMB-DS DCERPC NTLMSSP invalid mechlistMIC attempt" sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/netbios.rules active T comment "ORACLE misparsed login response" sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/oracle.rules active T comment "WEB-PHP read_body.php access attempt" comment "java script squirrel mail exploit: just add to signature " requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-php.rules http /.*[fF][rR][oO][mM]\x3a.*\x3cscript\x3e.*document.cookie.*\x3c\x2fscript\x3e/ active T comment "WEB-MISC Annex Terminal DOS attempt" requires-reverse-signature ! http_error sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/web-misc.rules active T comment WEB-MISC Real Server DESCRIBE buffer overflow attempt comment "pcre: /^DESCRIBE\s[^\n]{300}/smi" http "/((^)|(\n+))[dD][eE][sS][cC][rR][iI][bB][eE][\x20\x09\x0b][^\n]{300}/" requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-misc.rules payload "/.*[dD][eE][sS][cC][rR][iI][bB][eE].{1}.*\.\.\//" active T comment POP3 PASS overflow attempt comment "pcre: /^PASS\s[^\n]{50}/smi" payload "/((^)|(\n+))[pP][aA][sS][sS][\x20\x09\x0b][^\n]{50}/" requires-reverse-signature ! pop_return_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/pop3.rules payload "/.*[pP][aA][sS][sS]/" active T comment "RPC portmap NFS request TCP" sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/rpc.rules active T comment "WEB-ATTACKS echo command attempt" requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-attacks.rules active F comment "ICMP Datagram Conversion Error undefined code" sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/icmp-info.rules active F comment "ICMP Destination Unreachable Network Unreachable" sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/icmp-info.rules active T comment "WEB-PHP b2 cafelog gm-2-b2.php remote file include attempt" requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-php.rules active F comment "ICMP unassigned type 2 undefined code" sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/icmp-info.rules active T comment "RPC portmap rpc.xfsmd request UDP" sigaction SIG_FILE snort-rule-file snort_rules/rules2.2/rpc.rules active T comment "NETBIOS SMB trans2open buffer overflow attempt" sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/netbios.rules active T comment "WEB-FRONTPAGE shtml.dll access" requires-signature http_iis_server requires-reverse-signature ! http_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/web-frontpage.rules active T comment "FTP .rhosts" requires-reverse-signature ! ftp_server_error sigaction SIG_LOG snort-rule-file snort_rules/rules2.2/ftp.rules ftp /.*\.rhosts/ payload /.*\.rhosts/ active T dst-ip == local_nets http /.*[\/\\]imageFolio\.cgi\?.*