logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

Bleeding Edge Threats Daily Signature Changes: msg#00127

security.ids.snort.bleedingsnort

Subject: Bleeding Edge Threats Daily Signature Changes


[***] Results from Oinkmaster started Thu Jan 18 20:00:06 2007 [***]

[+++] Added rules: [+++]

2003928 - BLEEDING-EDGE MALWARE KMIP.net Spyware (bleeding-malware.rules)
2003929 - BLEEDING-EDGE TROJAN psyBNC IRC Server Connection
(bleeding-virus.rules)


[///] Modified active rules: [///]

2003102 - BLEEDING-EDGE EXPLOIT Microsoft Multimedia Controls - ActiveX
controls spline function call CSLID (bleeding-exploit.rules)
2003292 - BLEEDING-EDGE WORM Allaple ICMP Sweep Ping Outbound
(bleeding-virus.rules)
2003293 - BLEEDING-EDGE WORM Allaple ICMP Sweep Reply Inbound
(bleeding-virus.rules)
2003294 - BLEEDING-EDGE WORM Allaple ICMP Sweep Ping Inbound
(bleeding-virus.rules)
2003295 - BLEEDING-EDGE WORM Allaple ICMP Sweep Reply Outbound
(bleeding-virus.rules)
2400000 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound
(bleeding-drop.rules)
2400001 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound
(bleeding-drop.rules)
2400002 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound
(bleeding-drop.rules)
2400003 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound
(bleeding-drop.rules)
2400004 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound
(bleeding-drop.rules)
2401000 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING
SOURCE (bleeding-drop-BLOCK.rules)
2401001 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING
SOURCE (bleeding-drop-BLOCK.rules)
2401002 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING
SOURCE (bleeding-drop-BLOCK.rules)
2401003 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING
SOURCE (bleeding-drop-BLOCK.rules)
2401004 - BLEEDING-EDGE DROP Spamhaus DROP Listed Traffic Inbound - BLOCKING
SOURCE (bleeding-drop-BLOCK.rules)
2402000 - BLEEDING-EDGE DROP Dshield Block Listed Source
(bleeding-dshield.rules)
2403000 - BLEEDING-EDGE DROP Dshield Block Listed Source - BLOCKING
(bleeding-dshield-BLOCK.rules)
2404000 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 1)
(bleeding-botcc.rules)
2404001 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 2)
(bleeding-botcc.rules)
2404002 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 3)
(bleeding-botcc.rules)
2404003 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 4)
(bleeding-botcc.rules)
2404004 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 5)
(bleeding-botcc.rules)
2404005 - BLEEDING-EDGE DROP Known Bot C&C Server Traffic (group 6)
(bleeding-botcc.rules)
2405000 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 1) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405001 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 2) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405002 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 3) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405003 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 4) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405004 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 5) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)
2405005 - BLEEDING-EDGE DROP Known Bot C&C Traffic (group 6) - BLOCKING SOURCE
(bleeding-botcc-BLOCK.rules)


[+++] Added non-rule lines: [+++]

-> Added to bleeding-drop-BLOCK.rules (1):
# VERSION 59

-> Added to bleeding-drop.rules (1):
# VERSION 59

-> Added to bleeding-malware.rules (1):
#from spyware listeningpost data, by matt Jonkman

-> Added to bleeding-sid-msg.map (3):
2003102 || BLEEDING-EDGE EXPLOIT Microsoft Multimedia Controls -
ActiveX controls spline function call CSLID || cve,2006-4446 ||
url,www.osvdb.org/displayvuln.php?osvdb_id=28841
2003928 || BLEEDING-EDGE MALWARE KMIP.net Spyware || url,www.kmip.net
2003929 || BLEEDING-EDGE TROJAN psyBNC IRC Server Connection

-> Added to bleeding-virus.rules (1):
#Another start, psyBNC servers don't always use a join, info from Reg
Quinton

[---] Removed non-rule lines: [---]

-> Removed from bleeding-drop-BLOCK.rules (1):
# VERSION 57

-> Removed from bleeding-drop.rules (1):
# VERSION 57

-> Removed from bleeding-sid-msg.map (1):
2003102 || BLEEDING-EDGE EXPLOIT Microsoft Multimedia Controls -
ActiveX control's spline function call CSLID || cve,2006-4446 ||
url,www.osvdb.org/displayvuln.php?osvdb_id=28841


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
qnx.openqnx.dev...    gcc.libstdc++.c...    solaris.opensol...    information-ret...    misc.misterhous...    web.catalyst.ge...    apache.webservi...    redhat.release....    hardware.lirc/2...    kernel.autofs/2...    technology.sust...    linux.vdr/2003-...    editors.lyx.gen...    org.user-groups...    netbsd.devel.pk...    xdg.devel/2004-...    version-control...    jakarta.slide.d...    debian.packages...    creativecommons...    ports.ppc.embed...    bug-tracking.bu...   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe

Navigation