|
|
November 23, 2007
- Re: Duplicate sids: 207644 207665, Frank Knobbe
- Re: Bleeding Threats, Frank Knobbe
- Re: Bleeding Threats, System Administrator
- Re: Blackhole DNS, David Glosser
- Re: Bleeding Threats, System Administrator
- Re: Bleeding Threats, Frank Knobbe
- RE: Bleeding Threats, Darren Williams
- RE: Bleeding Threats, Darren Williams
- Re: Bleeding Threats, Albert E. Whale
- Duplicate sids: 207644 207665, Reg Quinton
- Re: Bleeding Threats, System Administrator
- Re: Bleeding Threats, System Administrator
- Re: Bleeding Threats, Colin Lowther
- Re: Bleeding Threats, System Administrator
- Re: Bleeding Threats, Frank Knobbe
- Re: Bleeding Threats, Colin Lowther
- Re: Bleeding Threats, CunningPike
November 08, 2007
- Re: RBN CIDRs - RussianBusinessNetworkIPs.txt, Markus Lude
- Re: New phpshell Sigs, James Pleger
- Re: New phpshell Sigs, James Pleger
- Re: New phpshell Sigs, Matt Jonkman
- Re: Alerting on exe file download size -- Rule Work, Matt Jonkman
- Re: Alerting on exe file download size, Matt Jonkman
- Re: Alerting on exe file download size, Erik Fichtner
- Re: RBN CIDRs - RussianBusinessNetworkIPs.txt, Matt Jonkman
- Re: Alerting on exe file download size -- Stream Relativity, Matt Jonkman
- Re: Alerting on exe file download size - Header Carving, Matt Jonkman
- Re: Alerting on exe file download size, Matt Jonkman
November 01, 2007
- Re: first shot (untested) at a sig for the mac trojan calling home...., Matt Jonkman
- Re: first shot (untested) at a sig for the mac trojan calling home...., Russell Fulton
- Re: DNS Rebinding Signatures, Matt Jonkman
- Off-Topic, Matt Jonkman
- Re: first shot (untested) at a sig for the mac trojan calling home...., Matt Jonkman
- Re: first shot (untested) at a sig for the mac trojan calling home...., Matt Jonkman
- Re: first shot (untested) at a sig for the mac trojan calling home...., Matt Jonkman
- Re: first shot (untested) at a sig for the mac trojan calling home...., Matt Jonkman
- Re: first shot (untested) at a sig for the mac trojan calling home...., Matt Jonkman
- Off-Topic, Matt Jonkman
- Re: DNS Rebinding Signatures, Darren Spruell
- Re: first shot (untested) at a sig for the mac trojan calling home...., Russell Fulton
- first shot (untested) at a sig for the mac trojan calling home...., Russell Fulton
October 30, 2007
- Re: RBN CIDRs - RussianBusinessNetworkIPs.txt, Markus Lude
- Re: proxifier/anonymizer sites, dhottinger-+D6Uf2+aGuUzapb4NPdxy3JwqO3YJu/x
- Re: proxifier/anonymizer sites, David J. Bianco
- RBN Networks DNS, Jim McQuaid
- Re: RBN CIDRs - RussianBusinessNetworkIPs.txt, Markus Lude
- Re: RBN CIDRs - RussianBusinessNetworkIPs.txt, Russell Fulton
- Re: proxifier/anonymizer sites, Matt Jonkman
- Re: RBN CIDRs - RussianBusinessNetworkIPs.txt, Matt Jonkman
- proxifier/anonymizer sites, dhottinger-+D6Uf2+aGuUzapb4NPdxy3JwqO3YJu/x
- Re: RBN CIDRs - RussianBusinessNetworkIPs.txt, Jeremy
- Re: RBN CIDRs - RussianBusinessNetworkIPs.txt, Matt Jonkman
October 16, 2007
- more fps for storm sigs, Russell Fulton
- Re: Storm TCP Sigs, Russell Fulton
- Re: Agent Alt hits - Followup, Jack Pepper
- FP on 2007641 (Storm TCP), Niklas Schiffler
- Agent Alt hits, Jack Pepper
- RE: Encrypted Storm Traffic, Henmi, Anne
- RE: Encrypted Storm Traffic, Henmi, Anne
- Re: Encrypted Storm Traffic, Matt Jonkman
August 11, 2007
- Re: Rules bad again: unknown keyword ' metadata'in rule, Matt Jonkman
- Re: Rules bad again: unknown keyword ' metadata'in rule, RPG
- Re: Rules bad again: unknown keyword ' metadata' in rule, RPG
- RE: Bleeding Edge Threats Weekly Signature Changes, Michael Scheidell
- RE: Rules bad again: unknown keyword ' metadata'in rule, Michael Scheidell
- Re: Rules bad again: unknown keyword ' metadata' in rule, Matt Jonkman
- Re: Rules bad again: unknown keyword ' metadata' in rule, Matt Jonkman
- Rules bad again: unknown keyword ' metadata' in rule, Michael Scheidell
- Re: Bleeding Edge Threats Weekly Signature Changes, Matt Jonkman
- RE: Bleeding Edge Threats Weekly Signature Changes, Michael Scheidell
- Re: FPs for BLEEDING-EDGE WEB Possible SQL Injection Attempt -- UPDATE SET, Matt Jonkman
- Re: DNS Rebinding Sigs, Matt Jonkman
- Re: DNS Rebinding Sigs, Matt Jonkman
July 30, 2007
- Re: Duplicate SID 2006447, Matt Jonkman
- Duplicate SID 2006447, Jack Pepper
- RE: (no subject), Lees, Christian
- (no subject), Lees, Christian
- RE: ecard download rule (SQL Injection), M. Shirk
- RE: ecard download rule (SQL Injection), Reg Quinton
- Re: LibSSH Sig, RPG
- Re: ecard download rule (SQL Injection), Matt Jonkman
July 26, 2007
- Re: [Snort-devel] Snort 2.7 Segfaults w/bleeding-exploit, Steven Sturges
- Re: Snort 2.7 Segfaults w/bleeding-exploit, Bamm Visscher
- RE: ecard download rule, Reg Quinton
- RE: ecard download rule, M. Shirk
- ecard download rule, Jack Pepper
- Re: Snort 2.7 Segfaults w/bleeding-exploit, Bamm Visscher
- RE: Snort 2.7 Segfaults w/bleeding-exploit, Reg Quinton
- Re: Snort 2.7 Segfaults w/bleeding-exploit, Bamm Visscher
- Re: Snort 2.7 Segfaults w/bleeding-exploit, Joel Esler
- Re: [Snort-devel] Snort 2.7 Segfaults w/bleeding-exploit, Matt Jonkman
- Re: [Snort-devel] Snort 2.7 Segfaults w/bleeding-exploit, Todd Wease
- Re: Re: [Snort-devel] Snort 2.7 Segfaults w/bleeding-exploit, Matt Jonkman
- Re: [Snort-devel] Snort 2.7 Segfaults w/bleeding-exploit, Todd Wease
- New Job Listing, Matt Jonkman
July 19, 2007
- Re: Re: [Snort-sigs] STILL no word from Sourcefire about their License Changes, Matt Jonkman
- Re: RE: [Snort-users] What's up with Snort's lice nse?, Matt Jonkman
- RE: [Snort-users] RE: What's up with Snort's license?, Alan Shimel
- Re: [Snort-sigs] STILL no word from Sourcefire about their License Changes, Paul Schmehl
- RE: RE: [Snort-users] What's up with Snort's lice nse?, Detore, Mario R.
- Re: Malicious HTTP Servers on non-standard ports -- PLEASE TEST!, Surya Batchu
- Re: Malicious HTTP Servers on non-standard ports -- PLEASE TEST!, Matt Jonkman
- Re: Malicious HTTP Servers on non-standard ports -- PLEASE TEST!, Matt Jonkman
- Re: Malicious HTTP Servers on non-standard ports -- PLEASE TEST!, Surya Batchu
- Re: PHP Proxy Sigs, Matt Jonkman
- Storm Worm Sig, Matt Jonkman
- Re: PHP Proxy Sigs, Will Metcalf
- PHP Proxy Sigs, Matt Jonkman
- RE: Malicious HTTP Servers on non-standard ports -- PLEASE TEST!, Matt Jonkman
- RE: [Snort-users] What's up with Snort's license?, Matt Jonkman
- RE: Malicious HTTP Servers on non-standard ports, Matt Jonkman
June 03, 2007
- typos in msgs (sids 2003194/2002773), Markus Lude
- Re: Re: Bleeding-sigs Digest, Vol 9, Issue 4, Matt Jonkman
- IIS Auth Bypass Signature, Matt Jonkman
- Re: Bleeding-sigs Digest, Vol 9, Issue 4, Jim McQuaid
- Re: Bleeding-sigs Digest, Vol 9, Issue 4, Jim McQuaid
- Malware, Virus - Categorization, Surya Batchu
May 08, 2007
- Re: Downloader.VB.TX false positives, Matt Jonkman
- Downloader.VB.TX false positives, David J. Bianco
- Re: "BLEEDING-EDGE Behavioral Unusually fast Terminal, Matt Jonkman
- Re: "BLEEDING-EDGE Behavioral Unusually fast Terminal, Jeff Kell
- Re: "BLEEDING-EDGE Behavioral Unusually fast Terminal Server Traffic, Potential Scan or Infection", Matt Jonkman
- Re: Report to bleedingsigs?, Matt Jonkman
- 2003591 falses?, Matt Jonkman
- Report to bleedingsigs?, Michael Scheidell
- Re: "BLEEDING-EDGE Behavioral Unusually fast Terminal Server Traffic, Potential Scan or Infection", Russell Fulton
- Re: "BLEEDING-EDGE Behavioral Unusually fast Terminal Server Traffic, Potential Scan or Infection", Matt Jonkman
April 18, 2007
- Google Calendar, Matt Jonkman
- Re: Rinbot sig - MS DNS Worm, Matt Jonkman
- Re: ANI on ISC, Matt Jonkman
- Re: ANI on ISC, Andre Ludwig
- ANI on ISC, Matt Jonkman
- Re: Rinbot sig - MS DNS Worm, axn jxn
- Re: Rinbot sig - MS DNS Worm, axn jxn
- RE: Rinbot sig - MS DNS Worm, Weir, Jason
- Cleaning Up, Matt Jonkman
- Re: Rinbot sig - MS DNS Worm, Matt Jonkman
- Re: Rinbot sig - MS DNS Worm, axn jxn
- Re: Rinbot sig - MS DNS Worm, Matt Jonkman
- Re: Rinbot sig - MS DNS Worm, Matt Jonkman
- Re: Rinbot sig - MS DNS Worm, Matt Jonkman
- Re: Rinbot sig - MS DNS Worm, dajackman
- Re: Rinbot sig - MS DNS Worm, dajackman
- Re: Rinbot sig - MS DNS Worm, Matt Jonkman
- Re: Rinbot sig - MS DNS Worm, Reg Quinton
- Re: Rinbot sig - MS DNS Worm, dajackman
- Re: Rinbot sig - MS DNS Worm, Matt Jonkman
- Re: Rinbot sig - MS DNS Worm, dajackman
March 01, 2007
- Re: P0F in Snort - Available for download, Matt Jonkman
- Re: P0F in Snort - Available for download, Jack Pepper
- Re: P0F in Snort - Available for download, Jason
- Re: Edonkey sigs, Matt Jonkman
- Re: P0F in Snort - Available for download, Matt Jonkman
- Unknown Bot, Matt Jonkman
- Re: Edonkey sigs, M. Shirk
- Re: Edonkey sigs, Markus Lude
- Re: Unknown P2P Packets, Matt Jonkman
- Re: Unknown P2P Packets, Matt Jonkman
- Re: Unknown P2P Packets, Jeff Kell
February 14, 2007
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Frank Knobbe
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Chris Byrd
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Frank Knobbe
- Re: Find text before a content match, using content first?, Matt Jonkman
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Matt Jonkman
- Re: Find text before a content match, using content first?, Jason
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Frank Knobbe
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Frank Knobbe
February 13, 2007
- Re: Find text before a content match, using content first?, Mathew Rowley
- Guard.zip Phish, Very targeted, Sig Available, Matt Jonkman
- Re: Find text before a content match, using content first?, Martin Holste
- Re: Find text before a content match, using content first?, Mathew Rowley
- Re: Find text before a content match, using content first?, Matt Jonkman
- Find text before a content match, using content first?, Mathew Rowley
- RE: [Bleeding-sigs] NST v.1.5.0 Released…, David Scott
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Matt Jonkman
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Reg Quinton
- NST v.1.5.0 Released…, Matt Jonkman
February 12, 2007
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day (Important!)], Matt Jonkman
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day (Important!)], Matt Jonkman
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day (Important!)], Matt Jonkman
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day (Important!)], Matt Jonkman
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Matt Jonkman
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day (Important!)], Frank Knobbe
- RE: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Michael Scheidell
- RE: [Fwd: Re: [Dshield] Solaris Telnet 0-day(Important!)], Michael Scheidell
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day (Important!)], Chris Byrd
- Re: [Fwd: Re: [Dshield] Solaris Telnet 0-day (Important!)], Chris Byrd
- [Fwd: Re: [Dshield] Solaris Telnet 0-day (Important!)], Matt Jonkman
January 31, 2007
- Re: Unusually High Client DNS Query Volume -- lots of hits., Matt Jonkman
- Re: Unusually High Client DNS Query Volume -- lots of hits., Russell Fulton
- Re: P0F in Snort?, Jack Pepper
- 5 Years of Castlecops!!, Matt Jonkman
- Re: Stormy P2P bot Sigs -- may be SKYPE ?, Matt Jonkman
- Re: Stormy P2P bot Sigs -- may be SKYPE ?, Matt Jonkman
- Re: P0F in Snort?, Matt Jonkman
- IDS Policy Manager v2.0.2 Released, Matt Jonkman
- Re: P0F in Snort?, Jack Pepper
- Re: Stormy P2P bot Sigs -- may be SKYPE ?, Matt Jonkman
- Re: Stormy P2P bot Sigs -- may be SKYPE ?, Dave Killion
January 29, 2007
- Re: Stormy P2P bot Sigs -- may be SKYPE ?, Matt Jonkman
- Re: P0F in Snort?, Matt Jonkman
- Re: P0F in Snort?, Matt Jonkman
- Re: P0F in Snort?, Mike Guiterman
- Re: P0F in Snort?, Martin Holste
- Re: Stormy P2P bot Sigs -- may be SKYPE ?, Matt Jonkman
- Re: P0F in Snort?, Matt Jonkman
- Re: P0F in Snort?, Matt Jonkman
- Re: P0F in Snort?, tom
- Re: Unusually High Client DNS Query Volume -- lots of hits., Matt Jonkman
- Re: Unusually High Client DNS Query Volume -- lots of hits., Chris Byrd
- RE: P0F in Snort?, Michael Scheidell
- Unusually High Client DNS Query Volume -- lots of hits., Russell Fulton
- Re: Stormy P2P bot Sigs -- may be SKYPE ?, Russell Fulton
January 24, 2007
- Rule Submit: Centrality IP Phone (PA-168 Chipset) Session Hijacking, Blake Hartstein
- Snort_inline 2.6.1.2 BETA 1 released!, Matt Jonkman
- Re: Rule Submit: NCTAudioFile2 ActiveX SetFormatLikeSample() Buffer Overflow, Matt Jonkman
- Rule Submit: NCTAudioFile2 ActiveX SetFormatLikeSample() Buffer Overflow, Blake Hartstein
- Rule Submit: Apple Quicktime RTSP Overflow, Blake Hartstein
- Re: Rule Submit: Apple Quicktime RTSP Overflow, Blake Hartstein
- RE: New sig for unknown bot, Raitz, Alex
- Re: New sig for unknown bot, Matt Jonkman
- RE: New sig for unknown bot, Raitz, Alex
- Re: New sig for unknown bot, Jack Pepper
January 15, 2007
- Re: Error With Flowbit dce.bind.netware_cs, Bamm Visscher
- Error With Flowbit dce.bind.netware_cs, Bamm Visscher
- Re: definition, Bamm Visscher
- Re: definition, Jason
- Bleeding Edge Threats Daily Signature Changes, bleeding-WwB1pFISwSkm7effSn6vN9HuzzzSOjJt
- Re: Allaplw Trojan Sig, Matt Jonkman
- Re: Allaplw Trojan Sig, Robert Grabowsky
- Re: definition, Bamm Visscher
- Re: definition, Matt Jonkman
- Re: definition, Jason
- New Socks Proxy sigs — For bots, Matt Jonkman
- Allaplw Trojan Sig, Matt Jonkman
January 12, 2007
- Re: definition, Jason
- Re: Rule Load Formula, Martin Holste
- Adobe Sigs, Matt Jonkman
- Re: Rule Load Formula, Alex Kirk
- Re: Rule Load Formula, Alex Kirk
- Re: dedup, Alex Kirk
- Bleeding Edge Threats Daily Signature Changes, bleeding-WwB1pFISwSkm7effSn6vN9HuzzzSOjJt
- Re: dedup, Gentoo-Wally
- Re: dedup, Matt Jonkman
- Re: dedup (was: definition), Gentoo-Wally
- Re: Rule Load Formula, Sushant Sinha
- Re: definition, Matt Jonkman
- Re: definition, Mike Guiterman
- WMF Exploit Sig, Matt Jonkman
- Re: definition, Jason Brvenik
- Re: What is the list policy on posting binaries ? and a suggestion for a wiki., Matt Jonkman
- Re: definition, Jason
- Re: definition, Matt Jonkman
January 11, 2007
- Re: definition, Jason
- Re: What is the list policy on posting binaries ? and a suggestion for a wiki., Jack Pepper
- Re: Rule Load Formula, Jack Pepper
- Re: Rule Load Formula, Martin Holste
- Symantec port 2967 sig, Matt Jonkman
- What is the list policy on posting binaries ? and a suggestion for a wiki., Russell Fulton
- Re: Rule Load Formula, Martin Holste
- Re: Rule Load Formula, Jason
- Re: Rule Load Formula, Matt Jonkman
- Re: Rule Load Formula, Martin Holste
- Re: Rule Load Formula, Matt Jonkman
- Re: Rule Load Formula, Gentoo-Wally
- Re: Rule Load Formula, Gentoo-Wally
- Rule Load Formula, Martin Holste
- Bleeding Edge Threats Daily Signature Changes, bleeding-WwB1pFISwSkm7effSn6vN9HuzzzSOjJt
- Re: definition, Matt Jonkman
- Re: definition, Matt Jonkman
- Re: definition, Matt Jonkman
- Re: dedup (was: definition), Matt Jonkman
- Re: PDF Signature update, Matt Jonkman
- Re: definition, Jason
- Re: definition, Mike Guiterman
- Re: definition, Mike Guiterman
- Re: definition, Michael Scheidell
- Re: definition, Michael Scheidell
- Re: definition, Bamm Visscher
- Re: definition, Michael Scheidell
- Re: definition, Bamm Visscher
- Re: definition, Michael Scheidell
- dedup (was: definition), Gentoo-Wally
- Re: definition, Jason
- Re: definition, Andre Ludwig
- Re: definition, Gentoo-Wally
- Re: definition, Michael Scheidell
- Re: definition, Jason
- Re: definition, Jason
- Re: definition, Jason Ish
- Re: definition, Bamm Visscher
- Re: definition, Matt Jonkman
- Re: rule morphing (was: definition), Jack Pepper
- Re: definition, Matt Jonkman
- Re: definition, Matt Jonkman
- Re: definition, Andre Ludwig
- Re: definition, Jason
- Re: definition, Jason
- Re: rule morphing (was: definition), Gentoo-Wally
- Re: rule morphing, Matt Jonkman
- Re: rule morphing (was: definition), Jack Pepper
- Re: definition, Jason
- Re: definition, Andre Ludwig
- Re: definition, Matt Jonkman
- Re: definition, Andre Ludwig
- Re: definition, Andre Ludwig
- Re: definition, David Glosser
- Re: definition, Matt Jonkman
January 10, 2007
- Re: definition, Matt Jonkman
- Re: Excluding Known IRC Nets from Shadowserver Bot C&C Rules, Matt Jonkman
- Re: Excluding Known IRC Nets from Shadowserver Bot C&C Rules, Frank Knobbe
- Re: definition, Frank Knobbe
- Re: definition, Gentoo-Wally
- Bleeding Edge Threats Daily Signature Changes, bleeding-WwB1pFISwSkm7effSn6vN9HuzzzSOjJt
- VML Sig Updates, Matt Jonkman
- Re: definition, Matt Jonkman
- Re: definition, Matt Jonkman
- Excluding Known IRC Nets from Shadowserver Bot C&C Rules, Matt Jonkman
- Re: definition, Michael Scheidell
- definition, Gentoo-Wally
|
|