# $Id: s2b-augment.cfg 797 2004-11-27 20:26:50Z rwinslow $
active T
comment WEB-CGI emumail.cgi access
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-cgi.rules
active T
comment RPC portmap kcms_server request UDP
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/rpc.rules
active T
comment WEB-CGI htsearch arbitrary configuration file attempt
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-cgi.rules
active T
comment SMTP chameleon overflow
comment pcre: /^HELP\s[^\n]{500}/ism
payload /((^)|(\n+))[hH][eE][lL][pP][\x20\x09\x0b][^\n]{500}/
sigaction SIG_LOG
requires-reverse-signature ! smtp_server_fail
snort-rule-file s2b_data_on_weed/rules2.1/smtp.rules
payload /.*[hH][eE][lL][pP]/
active T
comment WEB-IIS MDAC Content-Type overflow attempt
requires-signature http_iis_server
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-iis.rules
active T
comment FINGER . query
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/finger.rules
active T
comment WEB-CGI dcforum.cgi access
comment "informational only"
comment "too general but low occurence"
requires-reverse-signature ! http_error
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/web-cgi.rules
active T
comment MS-SQL sp_password - password change
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/sql.rules
active T
comment WEB-CGI admentor admin.asp access
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-cgi.rules
active T
comment ATTACK-RESPONSES rexec username too long response
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/attack-responses.rules
active T
comment WEB-MISC SalesLogix Eviewer access
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-misc.rules
active T
comment WEB-CGI a1stats a1disp3.cgi access
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-cgi.rules
active T
comment SNMP PROTOS test-suite-req-app attempt
requires-reverse-signature snmp_userver_ok_return
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/snmp.rules
active T
comment "MISC LDAP SSLv3 Server_Hello request"
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/misc.rules
active T
comment "DNS EXPLOIT x86 Linux overflow attempt"
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/dns.rules
active T
comment "WEB-CGI webdist.cgi arbitrary command attempt"
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-cgi.rules
active T
comment "WEB-MISC Demarc SQL injection attempt"
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-misc.rules
active T
comment "WEB-FRONTPAGE _vti_rpc access"
requires-signature http_iis_server
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-frontpage.rules
active T
comment "WEB-CGI admin.pl access"
requires-reverse-signature ! http_error
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/web-cgi.rules
active T
comment "FTP wu-ftp bad file completion attempt {"
sigaction SIG_LOG
payload /.*~.{1}.*\{/
ftp /.{2,} ~.?\{/
snort-rule-file snort_rules/rules2.2/ftp.rules
active T
comment "WEB-MISC ftp.pl access"
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-misc.rules
active T
comment "RPC rpc.xfsmd xfs_export attempt TCP"
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/rpc.rules
active T
comment "CHAT IRC channel join"
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/chat.rules
active T
comment "WEB-PHP Opt-X header.php remote file include attempt"
comment pcre: /systempath=(http|https|ftp)/i
payload /.*[sS][yY][sS][tT][eE][mM][pP][aA][tT][hH]=([hH][tT]{2}[pP][sS]?)|([fF][tT][pP])/
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-php.rules
payload /.*[sS][yY][sS][tT][eE][mM][pP][aA][tT][hH]=/
active T
comment "WEB-IIS bdir.htr access"
requires-signature http_iis_server
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-iis.rules
active T
comment "WEB-CGI alchemy http server PRN arbitrary command execution attempt"
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-cgi.rules
active T
comment "NETBIOS SMB-DS DCERPC NTLMSSP invalid mechlistMIC attempt"
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/netbios.rules
active T
comment "ORACLE misparsed login response"
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/oracle.rules
active T
comment "WEB-PHP read_body.php access attempt"
comment "java script squirrel mail exploit: just add to signature "
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-php.rules
http /.*[fF][rR][oO][mM]\x3a.*\x3cscript\x3e.*document.cookie.*\x3c\x2fscript\x3e/
active T
comment "WEB-MISC Annex Terminal DOS attempt"
requires-reverse-signature ! http_error
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/web-misc.rules
active T
comment WEB-MISC Real Server DESCRIBE buffer overflow attempt
comment "pcre: /^DESCRIBE\s[^\n]{300}/smi"
http "/((^)|(\n+))[dD][eE][sS][cC][rR][iI][bB][eE][\x20\x09\x0b][^\n]{300}/"
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-misc.rules
payload "/.*[dD][eE][sS][cC][rR][iI][bB][eE].{1}.*\.\.\//"
active T
comment POP3 PASS overflow attempt
comment "pcre: /^PASS\s[^\n]{50}/smi"
payload "/((^)|(\n+))[pP][aA][sS][sS][\x20\x09\x0b][^\n]{50}/"
requires-reverse-signature ! pop_return_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/pop3.rules
payload "/.*[pP][aA][sS][sS]/"
active T
comment "RPC portmap NFS request TCP"
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/rpc.rules
active T
comment "WEB-ATTACKS echo command attempt"
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-attacks.rules
active F
comment "ICMP Datagram Conversion Error undefined code"
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/icmp-info.rules
active F
comment "ICMP Destination Unreachable Network Unreachable"
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/icmp-info.rules
active T
comment "WEB-PHP b2 cafelog gm-2-b2.php remote file include attempt"
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-php.rules
active F
comment "ICMP unassigned type 2 undefined code"
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/icmp-info.rules
active T
comment "RPC portmap rpc.xfsmd request UDP"
sigaction SIG_FILE
snort-rule-file snort_rules/rules2.2/rpc.rules
active T
comment "NETBIOS SMB trans2open buffer overflow attempt"
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/netbios.rules
active T
comment "WEB-FRONTPAGE shtml.dll access"
requires-signature http_iis_server
requires-reverse-signature ! http_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/web-frontpage.rules
active T
comment "FTP .rhosts"
requires-reverse-signature ! ftp_server_error
sigaction SIG_LOG
snort-rule-file snort_rules/rules2.2/ftp.rules
ftp /.*\.rhosts/
payload /.*\.rhosts/
active T
dst-ip == local_nets
http /.*[\/\\]imageFolio\.cgi\?.*